
GDPR & Data Security in Fuxam
Education Deserves the Highest Security Standards
Fuxam is operated exclusively in European data centers. Regular automatic backups with verifiable recoverability and ongoing security updates ensure smooth operation. Data is consistently encrypted via HTTPS and TLS, and sensitive data is additionally stored in encrypted form at the database level.

Hosting in Europe
Data That Stays in Europe
Fuxam stores all personal data exclusively in certified EU data centers in Frankfurt am Main and Dublin (ISO 27001, SOC 2, C5/BSI). The data does not leave European storage locations. Where specialized service providers are involved, this is done on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 GDPR and limited to what is technically necessary.

Encryption
Encrypted in Transit, Encrypted at Rest
All data transfers are continuously encrypted using established methods (HTTPS, STARTTLS, AES). Data at rest is also encrypted, both at the database and file level, with particularly sensitive information additionally protected using AES-256. Access keys are managed via dedicated secret management and rotated regularly. This ensures that grades, applications, and personnel data remain protected even if someone attempted to intercept them.

Backups & Availability
No Data Loss, Even in an Emergency
Databases and files are automatically backed up every two hours and replicated in real time to geographically separate locations. Even in the event of a complete data center failure, the system resumes operation with minimal data loss: recovery within four hours, with a maximum of two hours of data loss. Availability is contractually guaranteed at a minimum of 99.5% per year.

multi-tenancy
Your Data, Your Isolated Space
Each educational institution receives a fully isolated tenant in Fuxam. Data from different institutions is not mixed, merged, or made visible to one another. Every query is automatically limited to your own data set. Access to third-party data is architecturally excluded. What happens in your instance stays in your instance.

Authentication & Access Protection
Multi-Layer Protection Against Unauthorized Access
Login is secured via a specialized identity service and supplemented with multi-factor authentication. Passwords are subject to clear complexity rules, and trivial passwords are excluded. At the system level, role-based route protection checks every request for authorization before it is processed. Security follows the need-to-know principle. Each person sees exactly what they need for their task.

Granular permission system
Over 100 Permissions Across Four Levels
Over 100 individual permissions control access to every feature. Permissions can be assigned on four levels, institution-wide, by department, by course, or by individual user. Roles are inherited hierarchically, so higher-level permissions are automatically passed down to lower structural levels. Three standard roles plus any number of custom roles per institution.

Complete logging
Who Changed What and When Can Be Traced at Any Time
All administrative changes are logged in full. Who changed which grade and when? Who set a student to which status? Who approved an application? Every action is documented with a timestamp, responsible person, and before/after values. This protects the educational institution legally and builds trust among students.

GDPR rights for data subjects
Access, Erasure, and Rectification as a Standard Feature
Rights to access, deletion, and correction are technically supported in Fuxam. Data exports for data subjects are a standard feature, not a special case added later. Requests can be handled in a structured way, without anyone having to trawl through databases or export Excel lists.

Tested safety
Security That Is Regularly Put to the Test
The effectiveness of all protective measures is verified through regular penetration tests. Security updates are installed automatically, a Dependabot warns about vulnerable components and initiates fixes. Continuous monitoring automatically detects anomalies, often before users notice anything. All employees receive training on data protection and information security at least once a year.

data lifecycle
Data That Leaves When It’s Supposed To
Deletion and retention periods are configurable and are enforced automatically. Deleted content can be restored via soft delete for 30 days; after that, it is permanently removed. At the end of the contract, you receive all data back in a machine-readable format or have it deleted, including written proof of deletion. Inactive accounts are automatically cleaned up after four years.

Identity & Single Sign-On
Integration With Your Existing Identity Landscape
Fuxam connects to Active Directory, LDAP and common SSO providers via the standards SAML 2.0, OAuth 2.0 and OIDC. Teachers, students and administrative staff log in with their existing account, one login, one identity provider, and one fewer trail of passwords to manage.
FAQs
