redirect.pizza is built and operated in the Netherlands by a European company. Protecting your data and the data of your visitors is part of how we work, and we back that up with independent certification. This page summarizes our security and compliance posture. For reports, certificates and policies, visit our trust center.
Certifications
ISO 27001

redirect.pizza is ISO 27001:2022 certified. Our information security management system is audited by an independent certification body, covering how we protect customer data, manage risk and keep improving our controls.
Request our ISO 27001 certificate
SOC 2 Type 2

redirect.pizza completed its SOC 2 Type 2 audit in April 2024. The report describes our security and operational controls and confirms that they worked as designed over the audit period.
Request our SOC 2 Type 2 report
How we handle your data
- European data storage. Your data is processed and stored within Europe, in data centers that are ISO 27001 and NEN 7510 certified.
- No data selling. We never sell your data or use it for anything other than providing the service.
- Encryption. Data is encrypted in transit and at rest.
- Access control. Only authorized staff can access customer data, and only when their work requires it.
- Regular audits. Our systems are assessed frequently to detect and address risks.
- Data retention. We delete data when it's no longer needed, or on your request.
- Incident communication. We inform you promptly of any data breach or security incident that affects you.
- Data protection officer. A dedicated DPO oversees our privacy and data protection practices.
- Privacy by default. Tracking can be disabled per redirect. Without tracking, we only store the date and URL of a request to count hits.
Our privacy policy describes in detail what we collect, why, and how long we keep it.
GDPR
As a European company, we're subject to the General Data Protection Regulation (GDPR) and process personal data accordingly: we collect no more than we need, keep it accurate and secure, and delete it when it's no longer required. We act as a data processor for the data in your account; our data processing addendum covers that relationship, and our subprocessors are listed publicly.
HIPAA
redirect.pizza is not subject to HIPAA. Our service doesn't let customers store, process or transmit protected health information (PHI), so the regulatory requirements of HIPAA don't apply to it.
Security questionnaires and procurement
Larger organizations often need to complete a security review before adopting a new vendor. We're glad to help. Our ISO 27001 certificate and SOC 2 Type 2 report answer most questions, and the trust center has our policies. Custom security questionnaires and procurement processes are available for customers on the Enterprise plan. Contact sales to get started.
Questions?
Get in touch. We're happy to walk you through how we keep your data secure.