Guide
Where is your business data? Questions to ask every software vendor
When a company moves to business software, its invoices, customers and entire turnover move into someone else’s software. The fair question that is rarely asked: where exactly? This guide is a checklist of questions for EVERY business software vendor — including us.
Updated:
1. Where is the data physically stored?
The country and region determine which regulations protect your data and whom the vendor answers to. “In the cloud” is not an answer — the cloud is always somebody’s specific data centre in a specific country.
A good answer looks like this: a named country and region, published publicly. For companies from Serbia the most comfortable option is for the data to be in the European Union — the ZZPL (the Serbian Personal Data Protection Act) and the GDPR then line up without additional legal acrobatics around transferring data abroad.
Why the European Union, and not a server in Serbia? For two verifiable reasons. Technical: business software requires a managed database with automatic backups, point-in-time recovery, high availability and independently audited security practice (SOC 2) — a service of that standard does not currently exist in Serbia, and the domestic offer comes down to renting a server on which the vendor would have to build and maintain all those guarantees itself, which in practice lowers reliability instead of raising it. Legal: article 64 of the ZZPL provides for the free transfer of data to the states party to Convention 108 of the Council of Europe, which include all EU member states — storage in the European Union is therefore fully compliant with domestic regulations, without additional measures.
We do not treat this decision as dogma: if a service with equivalent guarantees appears in Serbia, we are ready to reconsider it.
2. Who are the sub-processors — and are they named?
Almost no software keeps everything itself: hosting, the database and sending email are usually with specialised providers. That is normal — but you have the right to know exactly whom your data passes through, and whether those providers have security certifications of their own.
- Ask for the list of sub-processors by name, not “carefully selected partners”.
- Next to every name there should be a public security page (SOC 2, ISO...).
- If there is no list anywhere — ask. The answer “that is an internal matter” is a bad sign.
3. How is the account accessed?
The most common real break-in at small companies is not a hacker from a film but the same password on ten websites — it leaks on one and opens all the others. So ask: does the software even have a password that someone could steal? Does it have two-factor authentication? Does the account lock after failed attempts?
4. Is my data separated from everyone else’s?
In business software many companies run on the same infrastructure. The question is how it is ensured that no one ever sees someone else’s data: is every access to data tied to a specific company, and is that an architectural rule or “we do our best”.
5. Can I export my data — and what does it cost?
The data is yours. The test is simple: can you get it in a usable form, free of charge, without a struggle? Charging for the export of your own data or “export only with a notice period” are forms of lock-in worth seeing before you move.
6. What happens when I stop using the software?
There are two honest answers you must get: how long your data exists after you stop, and how it is deleted when you request it. Accounting regulations require business documents to be kept, so “delete everything immediately” is neither possible nor lawful — but the procedure must be clear and known in advance.
7. Is there a data processing agreement (DPA)?
For your customers’ data you are the controller and the software is the processor — and under article 45 of the ZZPL (and article 28 of the GDPR) that relationship must be governed by a contract. With serious vendors the DPA is a standard part of the terms, not a premium add-on.
8. Can you see who did what?
When several people work in the software, a record of actions is both a security and a practical matter: who issued a document, who sent it, who changed what. Without it every dispute ends in an argument.
9. What exactly is encrypted?
The claim “all data is encrypted” without naming the layers says nothing: encryption in transit (TLS) and at rest (AES-256) is today the standard of every serious cloud infrastructure and goes without saying. A competent answer names what is encrypted, at which layer and what that measure protects against. Ask in particular how the company’s access keys for the state systems (SEF, e-delivery notes) are stored — they allow documents to be issued in the company’s name.
- Why does it matter that the data is in the European Union?
- The Serbian Personal Data Protection Act (ZZPL) and the European GDPR set strict rules for transferring personal data abroad. When the servers are in the EU, the legal framework is clear both for you and for your customers; when the location is not published, you do not even know which rules protect your data.
- What is a data processing agreement (DPA) and do I need one?
- You are the controller of your customers’ data and the software is the processor — article 45 of the ZZPL requires that relationship to be governed by a contract. A serious vendor has a DPA as a standard part of its terms of use, at no extra cost and without separate negotiation.
- How do I verify what the software claims?
- Look for publicly published pages: the data location, a list of sub-processors with links, terms that include the data processing agreement, a description of sign-in and isolation. A claim that is written nowhere — might as well not exist.
- What does the claim “all data is encrypted” mean?
- Without naming the layers — usually just standard encryption in transit and at rest, which every serious cloud infrastructure has. A competent answer names what is encrypted and at which layer; ask in particular how the company’s API keys for SEF and e-delivery notes are stored.
Ask us any of these questions
We keep all the answers public — in the documentation and on the legal pages. And if you want to check for yourself: 30 days free, no card required.