Security and operations

Security

Revised7 August 2026 In force from7 August 2026

We hold information about our customers’ customers — amounts, ability to pay and, for private individuals, civil registration numbers. Here is how it is protected, who can see it, and what we do if something goes wrong.

§ 1

The starting point

We hold information about our customers’ customers — amounts, ability to pay and, for private individuals, civil registration numbers. That is data that can do harm if it ends up in the wrong hands. Security is therefore not a feature of the portal; it is a precondition for our being allowed to hold it.

Rieck is an authorised debt-collection firm supervised by Rigspolitiet (the Danish National Police), and we hold professional indemnity insurance and have lodged a guarantee as required. Our processing of personal data is described in the privacy policies; this page sets out the technical and organisational measures behind it.

§ 2

Access to data

Need-based access
Employees have access only to the information their work requires. Access is granted by role and removed once the need ceases — at the latest on the day an employee leaves.
Personal accounts
No shared logins. Every action in the systems can be traced to a named human being.
Two-factor
Administrative access requires two-factor authentication.
Logging
Access to customer data is logged, and the log is kept separately from the systems it concerns.
Separation between customers
Clients’ data is logically separated. One client cannot see another client’s information — not even through an error in a search.

§ 3

Encryption and storage

All traffic to and from the portal and the website is encrypted with TLS. Data is also encrypted at rest, and that includes the backups.

Operations run in data centres within the EU/EEA with physical access control, surveillance and redundant power and network supply. The suppliers that process information on our behalf appear on the list of sub-processors.

We do not use production data in development and test environments.

§ 4

Operations, backup and contingency

Backups are taken regularly, and restoration is tested — a backup that has never been restored is an assumption, not a safeguard.

We monitor operations and have an established procedure for security incidents: who does what, how the scope is established, and when customers and authorities are notified.

If a personal data breach occurs, we notify the affected customers without undue delay, so that they can meet their own 72-hour deadline towards Datatilsynet. The detailed obligations are set out in § 10 of the data processing agreement.

The portal’s current operational status is public at status.rieckflow.com, and the service levels have their own document.

§ 5

People and suppliers

Employees are bound by a duty of confidentiality that continues after the employment ends, and are trained in data protection and in recognising phishing.

We enter into a data processing agreement with every supplier that processes personal data on our behalf, and we hold them to the same requirements we hold ourselves to. New sub-processors are notified to customers before they are put to use.

Where we use artificial intelligence in case handling, it happens within the limits set out in § 19 of the terms of business and § 7 of the privacy policy for debt collection: limited use of data, no training on customers’ data, and never a decision made by a machine alone.

§ 6

What is in your hands

Part of the security sits with you, and we cannot take it off your hands:

  • Give your users the permissions their work requires — and no more.
  • Close access when an employee leaves.
  • Never share logins, and do not reuse the same password elsewhere.
  • Do not send confidential information to us in an ordinary email. Put it in the portal, or call.
  • Tell us immediately if you suspect an account has been compromised.

If you have found a vulnerability in our systems, we would very much like to hear about it — see the page on responsible reporting of vulnerabilities.

Security and operations

Do you need documentation
for a supplier approval?

We are happy to fill in your own security questionnaire and walk your IT department through the setup. Call us, and we will take it from there.

Contact us

Call on any business day or write — we reply within 2 hours on any business day.

35 15 47 65 rieck@rieckflow.com

Operational status

Current status of the portal and website — and the history behind it.

status.rieckflow.com

Found a vulnerability?

Then we would rather hear it from you than from someone exploiting it. The rules are on the page.

Report a vulnerability
  • 30 days free
  • No payment card
  • One day's notice