Skip to content
poletis

Trust

Security & your data

You're about to put member names, addresses, attendance and payment info into our system. You deserve straight answers about where it goes and who can touch it. Six questions, six plain answers — no enterprise-speak.

Where is my data stored?

Studio OS runs on Vercel for the application and Supabase for the database, authentication and file storage. Both sit in EU regions. Poletis d.o.o. is a Croatian company, so your data stays in the EEA whichever market you signed up through — the US and Canada included. Your uploads — logos, member photos — go to a storage bucket of your own, not a shared folder every studio can reach.

Is my data encrypted?

Yes, in both directions. Every request to the app is TLS 1.2+ (HTTPS everywhere — no HTTP fallback). At rest, the database and file storage are encrypted by Supabase. Your Stripe keys get a second layer on top — AES-256-GCM, with the key held outside the database. Passwords are hashed by Supabase Auth, never stored as plaintext.

How often is it backed up?

Daily. Supabase takes an automated backup of the production database every day and encrypts it at rest. That is the commitment written into our data-processing agreement, and it is what is actually running — we would rather state the guarantee we keep than a recovery window we have not tested. If you delete something by accident, email me and I will go and get it.

Who at Poletis can see my data?

One person: Nino Poletan, the founder. Poletis d.o.o. is a one-person company. No support tier, no contractors, no offshore team. Production credentials live only on my machine. If access changes (a hire, a contractor), this page changes first.

What happens if there's a breach?

You hear from me within 48 hours of confirmation — by email, directly, with what was exposed, what we know, and what to do next. No PR-cleansed statement. If a breach affects EU residents, GDPR's 72-hour authority notification applies and we meet it. Status updates continue until resolved.

Can I export or delete my data?

Always. Full export (CSV of every member, booking, payment, message) on request — fulfilled within 7 days. On request we delete your account from production within 30 days; the encrypted backups it appears in rotate out within 90, and nothing touches them in between except disaster recovery. You own your data. Leaving is a one-email process, not a hostage negotiation.

Still have a security question?

Reach me directly at nino@eupoletis.com. If you need it in writing for procurement or compliance, say so and I'll send a signed PDF.

Last updated: 2026-05-28 · Poletis d.o.o.