Fluëntry
  • Tests
    Browse all testsFor funFor workCompliance prepHow tests are scored
  • Academy
    Academy homeBrowse coursesFor organisationsFAQHow courses are built
  • Pricing
    For individualsFor teamsFor organisations
Sign in
Fluëntryfluentry.be / Trust

Legal / Trust

How we handle trust

Where Fluëntry runs, how we keep it secure, who we share data with, and how to report a security concern. Plain language. No vague claims.

Effective 30 May 2026

1Where we host

All primary infrastructure for fluentry.be runs inside the European Union, with Frankfurt, Germany as the dominant region for database, analytics, and application hosting:

  • Application hosting and edge runtime: Vercel (EU regions).
  • Database, authentication, and file storage: Supabase, Frankfurt.
  • Product analytics and session replay: PostHog EU Cloud, Frankfurt.
  • Transactional email: Resend, EU (Ireland).

Other subprocessors (Lemon Squeezy as merchant of record, Sentry for error tracking, OpenRouter as an AI model gateway for content-authoring only) are listed at /subprocessors with role, jurisdiction, and data-residency detail. Where personal data is transferred outside the European Economic Area in the course of these vendor relationships, transfers are governed by Standard Contractual Clauses under Article 46 of the GDPR.

2How we protect it

Our architecture is built around a single trust boundary at the application server, not at the database. In practice:

  • Privileged database access (service-role credentials) lives only on the Vercel-side application server. Browsers never receive service-role credentials.
  • Anonymous PostgREST access is revoked. Public access to the database is not possible.
  • Row-level security is applied as defence-in-depth on four sensitive tables (responses, scores, purchases, entitlements) so that even a compromised application path cannot cross-read another user's data.
  • Input validation at the service layer uses Zod schemas; database constraints back this up with check constraints and generated columns where appropriate.
  • Anti-gaming protections include rate-limiting, fingerprint clustering for suspect-pattern detection, and a suspect flag that throttles or blocks repeated abusive behaviour.
  • Secrets are managed in a dedicated secret store, never in source control, and rotated on a defined cadence.
  • Production deploys require a passing CI pipeline including type-checks, linting, unit tests, item-bank validation, and an axe-core accessibility gate on P0 routes.

The technical detail is summarised in our internal architecture and operations specifications. We do not publish those documents, but we will share an architecture overview deck on request with prospective B2B customers and security reviewers under NDA.

3Subprocessors

A live list of every subprocessor that handles personal data on our behalf is published at /subprocessors, including role, jurisdiction, and data-residency information. Each subprocessor is bound by a data processing agreement consistent with Article 28 of the GDPR. We disclose new subprocessors at least 30 days before they go live for processing identifiable personal data, where reasonably practicable.

4Report a security concern

Found something? Tell us privately and we will work with you to fix it.

  • Email: security@fluentry.be
  • Discoverable metadata: /.well-known/security.txt (RFC 9116)
  • Acknowledgement: within 3 working days.
  • Disclosure: please give us a reasonable opportunity to investigate and remediate before public disclosure. We commit to a 90-day default disclosure window, extensible by mutual agreement for complex or coordinated issues.
  • Good-faith research: we will not pursue legal action against you for good-faith security research conducted within reasonable scope (no exfiltration of other users' data, no degradation of service, no social engineering of staff).

We do not currently operate a paid bug-bounty programme. Reporters who provide materially useful findings will be acknowledged publicly (with consent) and may receive a goodwill subscription credit.

5Incident notification

In the event of a personal-data breach as defined by Article 4(12) of the GDPR, we will notify the lead supervisory authority (the IDPC in Malta) within 72 hours of becoming aware of the breach, as required by Article 33. Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will also notify those individuals without undue delay, as required by Article 34.

6Compliance posture

  • GDPR: full compliance with EU 2016/679, including access, erasure, portability, restriction, and objection rights. Access, erasure, and consent management are self-serviceable at /account/data; all other rights are exercisable via privacy@fluentry.be.
  • UK GDPR: equivalent rights honoured for UK residents.
  • EU AI Act: Fluëntry's product is positioned to help organisations evidence team literacy under Article 4 of the EU AI Act (literacy obligation, effective 2 February 2025). Our own use of AI in content authoring is disclosed on the item-health page.
  • e-Privacy: consent obtained for non-strictly-necessary cookies via /cookie-preferences.
  • Accessibility: targeting WCAG 2.2 AA on consumer-facing P0 routes, self-assessed against an axe-core CI gate in the deployment pipeline (external audit deferred to pre-first-B2B).

7For B2B and procurement reviewers

If you are reviewing Fluëntry for a B2B literacy benchmark, security questionnaire, or Article 4 compliance arrangement, please contact hello@fluentry.be. We can provide, under NDA:

  • An architecture overview deck.
  • Our internal compliance specification.
  • Standard SCC-based DPAs and our processor sub-contracts.
  • A DPIA aligned to the data flows you intend to enrol.
  • Stock-answer responses to common security questionnaires (CAIQ-style).
Fluëntry

AI literacy, measured and trained.

Explore

  • Tests
  • Academy
  • Pricing

Company

  • Methodology
  • Mission
  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Trust
  • Subprocessors
  • Cookie preferences
© 2026 Fluentry. Hosted in the EU.Frankfurt-hosted. GDPR by default.