Background Image

GDPR & Data Security in Fuxam

Education Deserves the Highest Security Standards

Fuxam is operated exclusively in European data centers. Regular automatic backups with verifiable recoverability and ongoing security updates ensure smooth operation. Data is consistently encrypted via HTTPS and TLS, and sensitive data is additionally stored in encrypted form at the database level.

Hosting in Europe

Hosting in Europe

Data That Stays in Europe

Fuxam stores all personal data exclusively in certified EU data centers in Frankfurt am Main and Dublin (ISO 27001, SOC 2, C5/BSI). The data does not leave European storage locations. Where specialized service providers are involved, this is done on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 GDPR and limited to what is technically necessary.

Encryption

Encryption

Encrypted in Transit, Encrypted at Rest

All data transfers are continuously encrypted using established methods (HTTPS, STARTTLS, AES). Data at rest is also encrypted, both at the database and file level, with particularly sensitive information additionally protected using AES-256. Access keys are managed via dedicated secret management and rotated regularly. This ensures that grades, applications, and personnel data remain protected even if someone attempted to intercept them.

Backups & Availability

Backups & Availability

No Data Loss, Even in an Emergency

Databases and files are automatically backed up every two hours and replicated in real time to geographically separate locations. Even in the event of a complete data center failure, the system resumes operation with minimal data loss: recovery within four hours, with a maximum of two hours of data loss. Availability is contractually guaranteed at a minimum of 99.5% per year.

multi-tenancy

multi-tenancy

Your Data, Your Isolated Space

Each educational institution receives a fully isolated tenant in Fuxam. Data from different institutions is not mixed, merged, or made visible to one another. Every query is automatically limited to your own data set. Access to third-party data is architecturally excluded. What happens in your instance stays in your instance.

Authentication & Access Protection

Authentication & Access Protection

Multi-Layer Protection Against Unauthorized Access

Login is secured via a specialized identity service and supplemented with multi-factor authentication. Passwords are subject to clear complexity rules, and trivial passwords are excluded. At the system level, role-based route protection checks every request for authorization before it is processed. Security follows the need-to-know principle. Each person sees exactly what they need for their task.

Granular permission system

Granular permission system

Over 100 Permissions Across Four Levels

Over 100 individual permissions control access to every feature. Permissions can be assigned on four levels, institution-wide, by department, by course, or by individual user. Roles are inherited hierarchically, so higher-level permissions are automatically passed down to lower structural levels. Three standard roles plus any number of custom roles per institution.

Complete logging

Complete logging

Who Changed What and When Can Be Traced at Any Time

All administrative changes are logged in full. Who changed which grade and when? Who set a student to which status? Who approved an application? Every action is documented with a timestamp, responsible person, and before/after values. This protects the educational institution legally and builds trust among students.

GDPR rights for data subjects

GDPR rights for data subjects

Access, Erasure, and Rectification as a Standard Feature

Rights to access, deletion, and correction are technically supported in Fuxam. Data exports for data subjects are a standard feature, not a special case added later. Requests can be handled in a structured way, without anyone having to trawl through databases or export Excel lists.

Tested safety

Tested safety

Security That Is Regularly Put to the Test

The effectiveness of all protective measures is verified through regular penetration tests. Security updates are installed automatically, a Dependabot warns about vulnerable components and initiates fixes. Continuous monitoring automatically detects anomalies, often before users notice anything. All employees receive training on data protection and information security at least once a year.

data lifecycle

data lifecycle

Data That Leaves When It’s Supposed To

Deletion and retention periods are configurable and are enforced automatically. Deleted content can be restored via soft delete for 30 days; after that, it is permanently removed. At the end of the contract, you receive all data back in a machine-readable format or have it deleted, including written proof of deletion. Inactive accounts are automatically cleaned up after four years.

Identity & Single Sign-On

Identity & Single Sign-On

Integration With Your Existing Identity Landscape

Fuxam connects to Active Directory, LDAP and common SSO providers via the standards SAML 2.0, OAuth 2.0 and OIDC. Teachers, students and administrative staff log in with their existing account, one login, one identity provider, and one fewer trail of passwords to manage.

FAQs

Frequently Asked Questions About Data Protection and Data Security

Where is Fuxam’s data hosted?
Is Fuxam GDPR-compliant?
How is the data protected from a technical standpoint?
How does the permission system work in Fuxam?
Which actions are logged to ensure audit compliance?
Are the data of different educational institutions kept separate in Fuxam?
How can we handle GDPR information requests from students?
What happens in the event of a system failure?
What happens to our data at the end of the contract?
How is the safety independently verified?