Trust Center

Trust, Security & Privacy

This page is maintained by the IMS Suite team to answer common security and privacy questions about the product. It describes app-visible controls and current practices — it is editable project content, not an independent certification or audit report.

EU data residency
Hosted in EU regions
Row-level isolation
Per-organization RLS
Audit logging
Who · what · when
GDPR-aligned
DSR-ready workflows
SSO-ready
OIDC / SAML on request
RBAC
Role-based access control

Access & authentication

Sign-in is handled through Supabase Auth. Sessions are scoped per user and per organization. Role-based access control restricts what each user can see and do inside their organization; platform administration is reserved to designated staff. Single sign-on (OIDC / SAML) is available on request.

Platform & hosting

IMS Suite is built on Lovable's TanStack Start stack and uses Supabase (Postgres, Auth, Storage) for data services. Application traffic is served over HTTPS and database access is gated by per-table Row Level Security policies. EU-region hosting is available for customers with data-residency requirements.

Data collection & use

We process the information you and your organization enter into the platform — documents, processes, audits, risks, training records and related metadata — to operate the service you have subscribed to. We do not sell personal data. AI Copilot calls are scoped to your organization's content; we do not use customer content to train third-party models.

Subprocessors & integrations

Core subprocessors include Supabase (database, authentication, storage) and Lovable (application hosting). The AI Copilot uses the Lovable AI Gateway. Additional integrations (e.g. email delivery, calendar booking) are activated only when your organization enables them. Contact us for the current list.

Cookies & analytics

We use the cookies strictly necessary to keep you signed in. Any product- analytics or marketing cookies, if enabled, are disclosed in the in-app cookie notice and require your consent before being set.

Retention & deletion

Customer data is retained for the duration of your subscription. On termination, your organization may request export or deletion of customer- controlled data; backups age out on the platform's standard schedule. Audit logs are kept for the retention period configured by your organization.

Privacy requests

Data-subject requests (access, correction, deletion) can be submitted to your organization administrator, who is the controller of the data inside the workspace. We will assist administrators in fulfilling verified requests within the timeframes required by applicable law.

Incident & security contact

To report a suspected security issue or incident, email security@computech.gr. Please include steps to reproduce and any supporting details. We acknowledge reports and coordinate remediation with the relevant teams.

Compliance

IMS Suite helps organizations operate ISO-aligned management systems (e.g. ISO 9001, 14001, 27001, 37001, 42001 and others). Use of the product does not by itself constitute certification of your organization, and this page does not assert that IMS Suite is independently certified. Contact us for current attestations and the shared-responsibility model.

Have a security or DPA question?

Procurement and security teams can request our DPA, subprocessor list and current attestations.

Last updated: 8 August 2026