Trust & Security
Last updated: August 2026
HermanWa holds your compliance evidence, audit findings, tenant records and energy data. Before you put that in our hands, you deserve straight answers about where it lives, who touches it, and how it is protected. This page states exactly what we do — and is equally plain about what we do not yet claim.
Summary: Your data is hosted on our own server in Manchester, United Kingdom, and stays there apart from the sub-processors listed below. You contract with a UK company under UK data protection law. We hold no security certifications yet and say so plainly, rather than implying otherwise. Our Data Processing Agreement is published in full.
1. Who you contract with
HermanWa is a trading name of Danai Data UK Ltd, a company registered in England and Wales. All customers — including those in Singapore and the UAE — contract with the UK entity. We do not currently have a Singapore entity or UEN, or a UAE establishment; we state that here because it is one of the first questions a procurement panel asks, and you should not have to dig for it.
Security and privacy contact (including data protection enquiries): hi@hermanwa.com.
2. Where your data lives
HermanWa runs on a single production environment: a dedicated virtual server located in Manchester, United Kingdom, provided by Hostinger International Ltd. Your account data, compliance registers, audit responses, uploaded evidence and generated reports are stored on that server. There is no multi-region replication; your data does not move outside the UK except for the specific sub-processors listed in section 6 and the off-site backups described in section 5.
3. International transfers
Singapore customers: storing data with HermanWa transfers it outside Singapore, which engages the transfer limitation obligation in section 26 of the PDPA. The receiving jurisdiction is the United Kingdom, where our processing is governed by UK GDPR — a regime whose protections are comparable to the PDPA — and we commit contractually, through our Data Processing Agreement, to protect transferred personal data to a standard comparable to the PDPA. For PDPA purposes, HermanWa acts as a data intermediary processing personal data on your behalf and on your instructions.
UAE customers: data is transferred to and processed in the United Kingdom under UK GDPR. We will support your assessment of the cross-border transfer provisions of Federal Decree-Law No. 45 of 2021 (PDPL) and its forthcoming Executive Regulations.
UK and EU customers: your data is hosted in the UK. Onward transfers are limited to the sub-processors in section 6.
4. How your data is protected
4.1 Encryption and transport
- All connections use HTTPS/TLS (certificates from Let's Encrypt), with HTTP Strict Transport Security enforced across the domain and subdomains.
- Passwords are stored as bcrypt hashes — never in plain text.
- Payment card details never touch our servers: checkout and billing run on PayPal's hosted infrastructure.
4.2 Access control and application security
- Separate, role-scoped portals for administrators, clients, tenants and contractors — each authenticates independently and sees only its own scope.
- Time-based one-time-password (TOTP) two-factor authentication on administrative access, enabled by default.
- Session cookies are Secure, HttpOnly and SameSite=Strict, and expire after 4 hours.
- CSRF tokens on state-changing requests, input sanitisation, login and registration rate-limiting, and a Content-Security-Policy restricting scripts to known origins.
- A security event log with automated alerting on suspicious activity.
5. Backups and resilience
The application and its databases are backed up automatically every day. Backup archives are compressed and stored off-site with Dropbox, with a 14-day retention window — so deleted data also leaves the backup set within 14 days. Application processes run under supervision and restart automatically on failure.
6. Sub-processors
These are the third parties that process data on our behalf, what they receive, and where they are. We keep this list current; if it changes, this page changes.
| Provider | Purpose | What they receive | Location |
|---|---|---|---|
| Hostinger International Ltd | Production hosting and transactional email (SMTP) | All service data (hosted); email addresses and message content of notifications we send | Hosting in Manchester, UK |
| Dropbox, Inc. | Off-site backup storage | Compressed backup archives of the application and databases | United States |
| PayPal | Subscription billing | Billing name, email and payment details (held by PayPal; never on our servers) | Global (US-headquartered) |
| OpenAI | Herman AI assistant | Your chat messages and the building/facility data extracts needed to answer them | United States |
| DeepSeek | Internal website-analytics assistant (admin-only) | Aggregated, anonymised page-view statistics for our public website — no customer account data, no portal data | China |
| Google (Tag Manager, Analytics, Ads) | Marketing-site analytics and advertising | Anonymised usage data on the public marketing site only — the client portal carries no Google tags | United States |
| OpenWeatherMap / Open-Meteo | Weather data for energy analytics | Building coordinates only — no personal data | UK / EU |
Your browser also calls two services directly from our public pricing page: PayPal (checkout) and frankfurter.app (indicative currency conversion). Neither receives your account data.
7. Certifications — what we hold and what we don't
We currently hold no security certifications. HermanWa is not ISO/IEC 27001 or ISO/IEC 42001 certified, has no SOC 2 attestation, and holds neither Cyber Essentials (UK) nor CSA Cyber Essentials/Cyber Trust or DPTM (Singapore). We build the product against those frameworks — our audit methodology follows ISO 19011 and certification-body practice — but a vendor that sells compliance tooling owes you the same honesty it recommends: no implied badges. UK Cyber Essentials is the first certification on our roadmap.
8. If something goes wrong
If we confirm a personal-data breach affecting your data, we will notify you without undue delay, and in any case within 72 hours of confirming it — with what we know, the likely impact, and what we are doing about it. We will assist you with your own notification obligations to your regulator (PDPC, ICO, or the UAE Data Office) with the information you need from our side.
9. Your role and ours
For the content you put into HermanWa — tenant records, evidence, registers, findings — you are the controller (in Singapore: the organisation) and we are the processor (in Singapore: your data intermediary), acting on your instructions. For your account and billing data, we are the controller, as described in our Privacy Policy.
Our standard Data Processing Agreement — UK GDPR Article 28 terms with Singapore PDPA and UAE PDPL modules, including the PDPA section 26 transfer commitment — is published in full. For a countersigned copy, email hi@hermanwa.com.
10. Data deletion
When you close your account, or on request, we delete your data from the production environment; backup archives containing it age out within the 14-day backup retention window. AI assistant conversation history can be deleted on request, as set out in the Privacy Policy.
11. Questions
Procurement questionnaire? Vendor onboarding form? Send it to hi@hermanwa.com — answering it is our job, not an imposition.