Security of the Work Instruction App: data, access and backups
Last updated:
The Work Instruction App is not available offline. To have the latest work instructions available anytime, anywhere, an online connection is required. Fortunately, it's almost always possible to be online these days using Wi-Fi or mobile networks. Because the app is available online, you always have the latest work instructions, and all completed SOPs are immediately saved and available to your colleagues.
The Work Instruction App is very safe. We will make every effort to take appropriate infrastructural and procedural measures to protect your data against loss or unlawful processing. The servers from Industrial IT are located in Europe and are subject to Dutch law. The Work Instruction App only communicates via HTTPS. The safest protocol on the internet. The databases containing customer data are backed up every hour to limit any possible data loss.
All data is stored on servers in Europe, operated by Industrial IT and subject to Dutch law. Every customer gets a separate database, created when the account is made, so your work instructions and recorded results are never mixed with another company's data. Those databases are backed up every hour.
Only the users you invite to your company. Access is set per user through roles, so you decide who may read, create, approve or publish work instructions. Because every customer has a separate database, users of another company cannot reach your data at all. You can also connect Microsoft Entra ID, so someone who leaves loses access the moment their Microsoft account is disabled.
Your data stays available for as long as your subscription runs. If you stop using the service we delete your data 30 days after the subscription end date, or earlier on request. Invoicing data such as contact details and invoices is kept for the statutory period of seven years. On request we show you which data is stored and you can have it corrected.
The app is only reachable over HTTPS: plain HTTP is redirected to the encrypted connection, and HSTS is enabled for a year including subdomains so browsers keep using it. Responses also carry a Content-Security-Policy, X-Frame-Options, X-Content-Type-Options and a strict Referrer-Policy, which limit what a browser may load or pass on. Found a weakness? Report it through our responsible disclosure policy.
Related pages
Questions? Talk to us
We are happy to show you how digital SOPs and work instructions fit your process.
Contact