How we protect your data and our infrastructure
Effective Date: 1 February 2026Bennovate takes the security of your data seriously. This page describes the technical and organisational measures we employ to protect the Avantwerk platform, partner data, and client information. Security is foundational to everything we build.
The Avantwerk platform is hosted on enterprise-grade cloud infrastructure provided by our technology partners. Our infrastructure security measures include:
Hosted on Google Cloud Platform (GCP) and Amazon Web Services (AWS) with SOC 2, ISO 27001, and GDPR-compliant data centres.
Data is replicated across multiple availability zones to ensure high availability and disaster recovery.
All data centres employ 24/7 security personnel, biometric access controls, CCTV surveillance, and environmental controls.
Cloudflare enterprise-grade DDoS mitigation and Web Application Firewall (WAF) protect all endpoints.
All data is encrypted both in transit and at rest using industry-standard encryption protocols.
We implement strict access control policies based on the principle of least privilege.
Security is integrated into every stage of our software development lifecycle.
Our network architecture is designed with defence in depth to protect against unauthorised access and threats.
Bennovate uses a limited number of vetted sub-processors to deliver the Avantwerk platform. Each sub-processor is contractually bound to maintain appropriate security standards.
| Sub-Processor | Purpose | Location |
|---|---|---|
| HighLevel (GoHighLevel) | Core platform infrastructure — CRM, automations, websites, funnels | United States |
| Google Cloud Platform | Cloud hosting, data storage, computing | EU / US |
| Amazon Web Services | Cloud hosting, data storage, computing | EU / US |
| Mailgun (Sinch AB) | Transactional and marketing email delivery | EU / US |
| Twilio | SMS and voice communications | United States |
| Stripe | Payment processing | United States |
| Cloudflare | CDN, DDoS protection, DNS, WAF | Global |
Data transfer safeguards: Where personal data is transferred outside the EEA/UK, appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) and adequacy decisions where available. All sub-processors maintain SOC 2 compliance or equivalent certifications.
Bennovate maintains a formal incident response plan to handle security events promptly and effectively.
Our business continuity and disaster recovery plans ensure service availability and data integrity.
Bennovate and our infrastructure partners maintain compliance with major security and data protection standards.
Full compliance with the General Data Protection Regulation for EU data subjects.
Compliance with UK data protection legislation, including the Data Protection Act 2018.
Our core infrastructure providers (GCP, AWS, Stripe) maintain SOC 2 Type II certification.
Our hosting providers are ISO 27001 certified for information security management.
Payment processing through Stripe is PCI DSS Level 1 compliant. Bennovate does not store card details.
Cookie and electronic communications compliance under the Privacy and Electronic Communications Regulations.
All Bennovate team members and contractors undergo security awareness training and are bound by confidentiality obligations.
We proactively identify and remediate security vulnerabilities across our systems.
Security is a shared responsibility. To help keep your account and data secure, we recommend:
If you have questions about our security practices, wish to report a vulnerability, or need further information, please get in touch.
Our team is available to discuss security questions and concerns.
Bennovate sp. z o.o.
KRS: 0000597272 | NIP: 7272799328 | REGON: 363700466
Registered in Poland — District Court for Łódź-Śródmieście, XX Commercial Division of the National Court Register