Security
Flaree is built and run in the European Union. This page states where your data sits, how it is protected, who can reach it, and who to contact about it.
EU data residency
Flaree runs on Amazon Web Services in the eu-central-1 region, Frankfurt, Germany. Application servers, the production database and its backups are all in that region. Your data does not leave the EU.
EU legal entity
Flaree is operated by Mobile Reality sp. z o.o., registered in Warsaw, Poland. The GDPR is domestic law for us, and your data stays inside the EU, so there is no third-country transfer to cover: no Data Privacy Framework, no Standard Contractual Clauses, no transfer impact assessment.
Encryption
Data at rest is encrypted with AES-256. Data in transit is encrypted with TLS 1.2 or higher — the load balancer and the CDN both reject earlier versions.
Access control
Each account carries a role, and each role carries an explicit set of permissions. A user reaches only their own company's data, and only the parts their role allows. Company administrators assign and revoke roles from the dashboard.
Backups
The production database is backed up daily, in the same region. Backups are retained for 30 days and then deleted.
Sub-processors
We name every third party that processes data on our behalf, and what each one handles.
Retention, deletion and export
Your data is kept while your account is open. Administrators export their employee data from the dashboard at any time, and can request a full machine-readable export by email. When you ask us to delete an account, we remove it from the production database, and the last backup copy expires 30 days later.
Reporting a vulnerability
Report a vulnerability to security@flaree.app. Include the steps to reproduce it and the account or URL affected. The same contact details are published in machine-readable form.