Operating security & privacy FAQ

We take security seriously at Operating. We're fully GDPR & SOC 2 compliant. Keeping your information safe and respecting your privacy rights matters to us.

Written By Lauri EurΓ©n

Last updated 10 days ago

This article answers to the most common questions about how Operating secures your data and handles your privacy. For the full, always-current posture β€” certifications, the complete subprocessor list, and formal reports β€” the canonical source is trust.operating.app.

What is Operating?

Operating is a professional services automation platform that helps consulting and professional-services firms plan resources, track time, and manage project financials. It is operated by Operating Solutions Oy, in Helsinki Finland and in the US by its subsidiary Operating Solutions Inc. (DBA: Operating Solutions Group).

Where is Operating hosted?

Operating is hosted on AWS in Frankfurt, Germany.

Is customer data encrypted?

Data is encrypted at rest via AWS encryption and in transit via TLS/HTTPS using industry-standard protocols.

How are users authenticated?

Access requires an authenticated User β€” nothing is accessible without one. Permission sets and roles govern what each User sees (keeping costs/margins restricted), and you can require SSO. (Permission sets in Operating; Single-sign on and user management)

Which user/company data is required to operate on Operating.app?

The only required pieces of information to sign up are an first name, last name, email, and company name.

To move from a free trial to a paid plan, either credit card details or invoicing details are needed.

Which third parties process data?

The current subprocessor list is at https://trust.operating.app/subprocessors

Data Processing Agreement (DPA)?

We offer a comprehensive Data Processing Agreement (DPA) that clearly outlines the responsibilities and obligations in data processing, aligning with GDPR standards β€” read it at https://www.operating.app/dpa

Is Operating GDPR compliant?

Yes, Operating is fully GDPR compliant. Keeping your personal information safe and respecting your privacy rights is important to us.

We are deeply committed to the protection of personal data and ensuring compliance with the General Data Protection Regulation (GDPR).

If you want to know more about your data, change something, or ask us to delete it, we're here for you. You can chat with us live via our app’s chat or email us at support@operating.app.

Is Operating SOC 2 certified?

Yes, Operating is officially SOC 2 certified. The full SOC 2 Type II report is available upon request via live chat or support@operating.app.

You can access our Trust Center here β†’

Company details

Parent company:

Operating Solutions Oy, Lapinlahdenkatu 16, 00180 Helsinki, Finland

Subsidiary:

Operating Solutions Inc.

169 Madison Avenue New York, NY, 10016 US