How Saal Digital protects your data in the Photo Portal

Data security and the protection of personal data are becoming increasingly important. As cyberattacks, phishing attempts, account misuse, and other online threats become more sophisticated, photographers and end clients rightly expect a high level of care when image and customer data are processed online. At Saal Digital, we take this responsibility very seriously. We use a combination of technical and organisational measures designed to protect personal data, image data, account access, and system availability in the Photo Portal.

This article provides an overview of the most important measures we take and what you can do yourself to further improve account security.

Our approach to data protection and security

Data protection and data security are of utmost important to us. We continuously work to maintain and improve our security standards and to reduce risks as much as possible.

Our measures are designed to protect:

  • Personal data, such as names, addresses, and customer information
  • Image data, including uploaded photos and gallery content
  • Account access, including photographer logins and administrative access
  • System availability, so data remains recoverable and services remain stable

1. Access security

Protecting access to accounts and internal systems is one of the most important parts of our security concept.

Mandatory multi-factor authentication

Multi-factor authentication (MFA / 2FA) is mandatory for all Saal Digital Employees. We provide Multi-factor authentication (MFA / 2FA) also to all photographers using the Photo Portal. This adds an additional layer of protection beyond the password and helps reduce the risk of unauthorized access. Please make sure that you have activated MFA / 2FA in your account. You can review your settings in your account under Security and Data Protection:

Check your two-factor authentication settings

Role-based access restrictions

Access to sensitive areas is restricted through role-based permissions. This means users and employees only receive the level of access required for their tasks.

Strong password policies

We enforce strong password policies across accounts to support secure authentication.

Session protection

Session management and automatic timeouts are in place to help prevent unauthorized access, for example if a device is left unattended.

2. Infrastructure and data protection

We use protected infrastructure and multiple layers of technical security to safeguard stored and transmitted data.

Hosting in Germany

Our services are hosted in Germany, supporting reliable infrastructure and compliance with European data protection requirements.

Certified data centers

Data is stored in certified BSI C5 and ISO 27001 data centers with high physical and digital security standards.

Firewall protection

Our infrastructure provider uses a multi-layer firewall system across Saal Digital services to protect systems and network traffic.

Encryption in transit

Data transmitted through our services is protected using current SSL/TLS standards.

Multiple encryption layers for stored data

Stored images are protected by multiple encryption layers, including infrastructure-side protection and additional application-level encryption measures implemented by Saal Digital.

3. Backup, availability, and recovery

Protecting data also means ensuring it remains available and recoverable in the event of technical incidents.

Automated backups

We use regular automated backups of gallery and customer data.

Tested restoration

Backup restoration is regularly tested to help ensure that data can be recovered reliably when needed.

Redundant systems

Our infrastructure includes redundant systems to support availability, reliability, and resilience.

Retention for recovery

Defined retention policies help ensure that data remains available for recovery within appropriate timeframes.

4. Monitoring and incident response

Security depends not only on prevention, but also on detecting unusual activity and responding quickly.

Continious monitoring

Our systems and infrastructure are monitored continuously.

Detection of suspicious activity

We use mechanisms to detect unusual access patterns or suspicious activity in real time.

Log review

Access logs and relevant system events are regularly reviewed to support traceability and security analysis.

Defined incident response procedures

We maintain defined incident response procedures, with clear steps from detection and assessment through to resolution and communication.

5. Secure development and regular testing

Security is not only part of system operations, but also part of how our services are built and maintained.

Security by design

Security is integrated into the development process from the beginning, following a security-by-design approach.

Internal security reviews

Code changes are subject to internal security reviews before deployment.

Checks of dependencies and third-party components

Dependencies and third-party components are regularly reviewed for known vulnerabilities.

Penetration testing

We carry out regular penetration testing by external specialists to identify potential weaknesses and improve our protections.

Security awareness in development

Employees involved in development receive regular security awareness training.

6. Data protection and GDPR compliance

Security and privacy go hand in hand. We process data in accordance with applicable data protection requirements.

GDPR-compliant processing

Saal Digital processes personal data in accordance with GDPR and applicable EU data protection requirements.

Data minimization

We follow the principle of data minimization, meaning only data that is necessary for the relevant purpose is collected and stored.

No sale of data for commercial purposes

Photographer and end-customer data is not sold or shared with third parties for commercial purposes.

Rights of data subjects

End customers have rights regarding their personal data, including the right to access, correction, and deletion, in line with applicable legal requirements.

Data Processing Agreement (DPA)

A Data Processing Agreement (DPA / ADV) is available for photographers who require it:

Open the full Data Processing Agreement

Retention and deletion policies

We apply defined retention and deletion policies. Galleries and customer data are deleted after defined periods or on photographer request, where applicable.

Audits and reviews

We carry out regular internal reviews and review relevant compliance and security documentation from our service providers.

7. Vendor and partner security

Where external service providers are involved, their security standards are an important part of the overall protection concept.

  • Service providers are carefully reviewed for security standards before onboarding
  • Contractual obligations require partners to maintain defined security standards
  • Provider compliance and security standards are reviewed on a regular basis

8. What photographers can do themselves

Security is always a shared responsibility. In addition to the protections implemented by Saal Digital, photographers can take important steps themselves.

Check your 2FA settings

Since 2FA is mandatory, please make sure it is correctly set up in your account under Security and Data Protection:

Check your two-factor authentication settings

Use a strong, unique password

Do not reuse passwords from other services.

Keep devices up to date

Install security updates regularly on your computer, browser, smartphone, and any relevant software.

Be alert to phishing

Be cautious with unexpected emails, messages, login prompts, or links asking for account credentials.

Limit access where possible

Only allow access to accounts and data where necessary, and review workflows regularly.

Questions about data protection or security?

If you have further questions about data protection, account security, or the handling of image and customer data in the Photo Portal, our support team will be happy to help.