Security & Compliance

AegisBackup is built for European organisations. Your data stays in Sweden, your rights are protected, and your compliance obligations are supported.

GDPR
General Data Protection Regulation (EU) 2016/679

AegisBackup is fully GDPR-compliant. We act as your data processor and provide a Data Processing Agreement (DPA). All data is processed lawfully, stored within the EU/EEA, and never transferred to third parties without your consent.

Read more
As a GDPR-compliant data processor, AegisBackup adheres to the principles of data minimisation, purpose limitation, and storage limitation. We maintain records of all processing activities and fully support your obligations as a data controller. Key GDPR commitments: • Data Processing Agreement (DPA) available on request • Data stored exclusively within the EU/EEA (Sweden) • Personal data encrypted at rest and in transit • Security breach notification within 72 hours (Article 33) • Support for data subject access requests (DSAR) • Right to erasure (right to be forgotten) supported For GDPR enquiries: info@aegisbackup.com
Data Residency
Stored in Sweden — EU/EEA

All backup data is stored exclusively on servers located in Sweden, within the European Economic Area. Your organisation's data never leaves the EU/EEA at any point in the backup or restore process.

Read more
AegisBackup uses data centres located in Sweden. This ensures: • Full data sovereignty within EU jurisdiction • Compliance with GDPR data transfer restrictions (Chapter V) • No transfers to third countries without adequate safeguards • All metadata, indexes, and backup archives remain within the EEA Data centre location: Sweden (EU/EEA) Applicable regulation: GDPR Articles 44–49
NIS2
EU Network and Information Security Directive 2

Regular, tested backups are a core requirement of the NIS2 Directive. AegisBackup helps your organisation meet its NIS2 obligations with automated backup of critical cloud data and documented, on-demand restore capabilities.

Read more
The NIS2 Directive (EU) 2022/2555, in force since October 2024, requires medium and large organisations in critical sectors to implement appropriate cybersecurity measures — including backup management and business continuity planning. How AegisBackup supports NIS2: • Automated daily backups of Microsoft 365 and Google Workspace data • Documented and testable restore procedures • Incident logging and full audit trails • Point-in-time restore capability • RPO (Recovery Point Objective) of 24 hours or less NIS2 applies to organisations in sectors including energy, transport, healthcare, digital infrastructure, and public administration. Consult your legal adviser to determine your organisation's specific obligations.
ISO 27001
Information Security Management

AegisBackup is built around ISO/IEC 27001 principles for information security management — covering risk assessment, access control, encryption at rest and in transit, and documented incident response procedures.

Read more
ISO/IEC 27001 is the international standard for information security management systems (ISMS). Our security practices are built around its core requirements: • Risk assessment and treatment processes • Access control and least-privilege principle • Encryption at rest and in transit (AES-256 / TLS 1.3) • Asset management and data classification • Supplier security assessments • Security incident management and response procedures • Business continuity and disaster recovery planning • Regular security reviews and vulnerability assessments
Questions about compliance or data processing?
Contact us at info@aegisbackup.com — we are happy to provide a Data Processing Agreement (DPA) or answer any security questions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.