Privacy & information security

Transparency without exposing security-sensitive internal details.

Public information about data processing agreements, technical and organisational measures, subprocessors, retention and deletion. Operational security details are intentionally not published.

Public information
PUBLIC-SAFE
PurposeCustomer transparencywithout operational detail
ScopePrinciples & contractual frameworkpublic
DetailsProvided for the engagementwhere required
Last updated: 30 August 2026 · Public information version 1.0
Two levels

Public transparency and confidential contractual detail are kept separate.

The website explains the applicable privacy and security principles. A specific engagement contains only the information and documents required for that service.

Not published

HTS Europa does not publish internal system names, network diagrams, detailed protection configurations, access paths, detailed security mechanisms, supplier inventories, internal review intervals or other information from which operational or security architecture could be inferred.

Contractual reference

The engagement is governed by the specific, versioned contractual documents.

Public pages are provided for advance information. Where processing on behalf of a customer applies, the DPA/TOM version governing the engagement is identified in the contracting process. Customer-specific details are not published here.

Service-specific

Not every IT service automatically constitutes processing on behalf of a customer. The actual processing in the engagement determines the role.

Versioned

Contractual documents are referenced with an identifiable version or effective date.

Engagement-specific

Purpose, data categories, data subject categories and retention periods are documented only where they are relevant.

Questions?

Do you need privacy information for a specific engagement?

Tell us briefly which service is being considered. The required contractual information can then be provided for the actual scope.