Your case files do not sit alongside anyone else's

Noctua does not run as one environment shared by all clients. Your organisation gets its own environment with its own database. There is no shared layer where data from different clients comes together, and therefore no partition that has to hold between those clients.

With this kind of data that is not optional. What ends up in an integrity investigation carries a duty of confidentiality, and that reaches further than the report: your own findings and the documents the subject supplies fall under it as well.

Inside your own environment, who could reach what stays on record. The log also registers the opening of a case file and cannot be switched off, so years later it can still be established who opened what.

Your environment on a separate serverNoctua and your database run together inside one shielded server that belongs to your organisation alone.Own serverNoctuaDatabase

Data protection officer

5 questions

Access
A person's role determines what they may view, edit or finalise. You grant access to sources separately. Case files belonging to one team are not visible to another unless you explicitly configure that. On our side, access is limited to staff we have designated for that purpose, and it is logged.
Who queries the sources
For sources that require a specific authorisation, your organisation queries them itself using its PKIoverheid certificate (the Dutch government's public-key certificate scheme). For commercial registers and open sources, access runs through us, or we keep the data up to date.
Recording
Every query and every finding is recorded with a source, a timestamp and a user, together with the search that preceded it. This lets you trace, for every piece of data, where it came from and what search produced it. The audit log also records who views a case file, and it cannot be switched off.
Archiving
When an investigation is finalised, we archive the report and fix the underlying material in place, so that years later you can still reconstruct it exactly as it was at the time.
Who administers the system
Your organisation. You set up users, roles, permissions and retention periods yourself, and you can retrieve everything held in the system yourself. If a data subject submits an access request, you do not need us for that.

ICT

2 questions

Where the data is held
Every organisation gets its own environment with its own database. There is no shared storage, and no data belonging to other organisations sits in the same database. The environment runs in the Netherlands, and we do not transfer data outside the EEA. If your organisation prefers to work on its own infrastructure, that is possible. A number of customers do this; in that case, your own organisation manages the server.
What your ICT department needs to do
Nothing, for day-to-day use. You work in the browser, in an environment that we set up and maintain. Your ICT organisation becomes involved when you choose single sign-on or hosting on your own infrastructure.

Procurement

3 questions

Certification
Our information security management system is ISO 27001 certified for the development and hosting of Noctua, periodically assessed by an accredited body.
Role as processor
Your organisation is the controller and determines the legal basis, the retention period and who has access. Noctua is the processor. We work with the standard data processing agreement issued by the VNG (the Association of Dutch Municipalities). Documentation for your DPIA is ready. Working with the template your own organisation provides is also an option.
If you stop
If your organisation ends its use, we delete the environment. You decide what happens to the data: transfer in a form of your choosing, or destruction.

We prefer to discuss the rest in person

Authentication, network configuration, backup and recovery, the sub-processor chain and the procedure in the event of a data breach differ by organisation. We prefer to go through those points with you rather than set them out here. The documentation is ready and we have this conversation often.

If a procurement process or a DPIA is under way, we will liaise with your data protection officer. Your ICT organisation only needs to get involved if you choose single sign-on or hosting on your own infrastructure, not for everyday use of the platform: you work in the browser, in an environment that we set up.