Security Standards

Security does not tolerate compromise
Contact us now

Security Standards

Security does not tolerate compromise

Contact us now
CommDoo | Security

The PCI Certificate

CommDoo meets all requirements of the Payment Card Industry (PCI) Data Security Standard from Visa and MasterCard.

With the PCI certificate, the security of our technical systems as well as the security of our of our organizational procedures.

As a user of our front-end interfaces (payment windows) or our finished shop integrations our certificate also applies to you. As a user of our backend interfaces (SOAP), we advise and we are happy to support you in obtaining the appropriate certificate. For this purpose, e.g, that we offer intelligent alternatives for the storage of credit card data.
Further information can be found under www.pcisecuritystandards.org

The secured transmission paths (SSL)

CommDoo uses only secure SSL connections for data exchange.

When your customers pay online, they trust that their personal information are protected and used only for their intended purpose. Our SSL Certificates, such as VeriSign Trusted, stand for this security and ensure that your customers can benefit from it. to convince them that the payment process is secure.

Privacy policy

Your data is in safe hands with us

All employees and freelancers have signed a commitment to the Privacy signed. Any access to systems requires the written consent of the CSO as well as of the Business management.

Our Intrusion Detection System (network-based IDS) prevents anyone from committing unauthorized attacks. access to data. In addition, all access is granted by two log servers and evaluated daily.
Information about the Intrusion Detection System can be found at wikipedia.org/Intrusion_Detection_System

The new regulations of the § 11 BDSG

Since the revised version of the Federal Data Protection Act of 1 January 2009, services are subject to which Data may be collected, processed or used for third parties, subject to stricter regulations and require a separate contractual agreement. Such an agreement to CommDoo has developed an "Order Data Agreement" with respect to your services, so that in this We do not have to obtain expensive legal expertise in this field.

Our Procedural Directory

Companies that collect, process or use data as payment service providers, are generally legally obliged to do so pursuant to Section 4 (2) sentence 3 BDSG, to draw up a list of procedures and make it available to you at any time on request. If this directory is missing or if it is not made available to you, then essential ignores any data protection requirements that have been imposed for their protection.

With our process directory we make our internal data processing processes available to you. towards more transparent. You can request this directory from us at any time. Please register for this on the start page and note in the comments field the term "Procedural directory".