Data Security & Compliance

Built for European data protection — by architecture.

ECI’s infrastructure is built from the ground up for European data protection standards, not adapted to them after the fact.

Servers in Germany

All ECI data is stored and processed exclusively on EU-domiciled servers located in Germany. No data is transferred outside the European Economic Area without consent of the client. GDPR Art. 44–49 compliant by architecture.

GDPR & ARUG II Native

SRD II queries executed under §67d AktG. Data subjects’ rights respected. Retention limits applied. Full audit trail maintained per query. GDPR-compliant data handling framework.

SWIFT Authorised Partner

Authorised SWIFT partner for SRD II shareholder identification. ISO 20022 compliant data transmission. Secure, legally compliant transfer of identification data across the custody chain.

Cybersecurity Standards

ISO 27001-aligned data handling procedures. Encrypted data in transit and at rest. Access controls, role-based permissions and penetration-test regime. Data minimisation by design.

BSFZ-Certified

ECI’s founding technology partner Captrace holds BSFZ certification for research and development excellence

Measurability & Audit

Every ECI engagement includes a baseline report, defined measurement points and a structured outcome metric. Full reporting chain available for board, legal and compliance review.