• Home
  • Services
  • Portfolio
  • About
  • Contact
SQ EN DE
Home Services Portfolio About Contact

Security & Trust

Last updated: 12 September 2026 Vargu Digital L.L.C. · Pristina, Kosovo

On this page

  1. Where your data lives
  2. Security as standard
  3. How we handle data that belongs to you
  4. Reporting a vulnerability
  5. If something goes wrong
  6. Questions we get asked
GDPR-aligned EU & Swiss infrastructure Zero tracking Encrypted in transit Device-only biometrics

We are a small studio, not an enterprise vendor, and this page is written accordingly. Everything below is something we actually do. Where we do not hold a certification, we say so plainly rather than implying otherwise — see the questions at the bottom, which answer the ones procurement teams ask first.

Where your data lives

Three locations, and the legal basis for each is different. This is usually the first thing a client's legal team asks, so it goes first.

Frankfurt
Germany · Hostinger
Inside the EU

Web hosting, backups and VPS. No third-country transfer arises at all.

Switzerland
Cloudflare · Proton Mail
Adequacy decision

Network layer and email. Covered by a European Commission adequacy decision, so Article 45 applies with no extra safeguard.

Pristina
Kosovo · our own server
Standard Contractual Clauses

Our own infrastructure and our own operations. No adequacy decision for Kosovo, so transfers here run on SCCs under Article 46(2)(c).

Exactly one of the three needs a transfer mechanism. That is a cleaner position than most non-EU suppliers can offer, and it is why we chose these providers.

Security as standard

The measures we apply to systems we build and host. These are the same ones committed to in Annex II of our Data Processing Agreement, where they become contractually auditable.

Encryption in transit

Everything is served over HTTPS/TLS. Plain HTTP is redirected, not accepted.

Database-level authorisation

Row-level security rules are enforced in the database itself, so a bug in application code cannot expose another tenant's rows.

Named access only

Individual accounts, no shared logins, access limited to the people doing the work. Admin interfaces are closed to public sign-up.

Device-only biometrics

Where we build biometric sign-in we use passkeys and WebAuthn. The fingerprint or face never leaves the user's device and never reaches our servers.

Daily backups

Automated daily backups of hosted systems, retained 30 days, with restores tested rather than assumed.

Tenant separation

Client environments are logically separated. We do not commingle one client's data with another's.

Data minimisation

We hold the least personal data a service needs. Server logs are kept 14 days. The marketing site sets no cookies at all.

Patching

Where we maintain a system under agreement, dependencies and platform updates are our responsibility. Where you maintain it, we hand over with that stated.

Incident response

Documented breach assessment, and notification to you within 48 hours so you can meet your own 72-hour regulatory deadline.

How we handle data that belongs to you

When we build or host a system for you, the personal data inside it is yours. In GDPR terms you are the controller and we are the processor: we act only on your documented instructions and never for our own purposes.

  • A Data Processing Agreement under Article 28(3) is signed before processing starts. It is published in full — no request needed.
  • Sub-processors are listed in Annex III, with 30 days' notice and a right to object before any change.
  • At the end of an engagement we return or delete your data at your choice, and confirm deletion in writing.
  • You own what we build. Once paid, you can take the source code and your data and leave — that is in our Terms, not just our marketing.

Reporting a vulnerability

If you have found a security issue, tell us before you tell anyone else. Email legal@vargu.digital with "Security" in the subject line. Our machine-readable contact is at /.well-known/security.txt.

Scope

In scope: vargu.digital and its subdomains, and infrastructure we operate directly.

Report, but do not test: systems we host for a client. Those belong to the client and we cannot give you permission to test someone else's system. Tell us and we will route it and coordinate the fix.

Out of scope without demonstrated impact: missing headers or TLS configuration nitpicks, self-XSS, clickjacking on pages with no sensitive action, missing rate limits on unauthenticated endpoints, raw automated scanner output, social engineering, and anything physical.

What we ask

  • Do not access, alter, exfiltrate or delete anyone's data. If you encounter personal data, stop and tell us what you saw.
  • No denial-of-service testing, no spam, nothing that degrades service for others.
  • Use your own test accounts wherever possible.
  • Give us reasonable time before publishing — we suggest 90 days, and we will tell you if we can fix it sooner.
  • Do not demand payment to withhold a report. That is not research.

What we commit to

  • We acknowledge within two working days.
  • We tell you whether we consider it valid, and why.
  • We update you at least every 14 days until it is closed.
  • We credit you however you prefer, or keep you anonymous.
  • Safe harbour. Act in good faith and follow this policy and we will not report you to the authorities, will not bring a claim against you, and will treat your research as authorised. If a third party comes after you for work that followed this policy, we will state that authorisation plainly.

We do not run a paid bug bounty. We would rather say that than advertise a reward we cannot fund.

If something goes wrong

Where a vulnerability leads to unauthorised access to personal data, our obligations under the GDPR and Kosovo's Law No. 06/L-082 apply in full: assessment without undue delay, notification of the supervisory authority within 72 hours where the risk threshold is met, and notification of affected people where the risk to them is high.

Where the data is yours, you are the controller and the decision to notify is yours. We notify you within 48 hours and give you everything you need to make it, as set out in section 6 of our DPA.

Questions we get asked

Do you hold SOC 2, ISO 27001 or similar certification?

No. Those audits cost tens of thousands of euros a year and are built for organisations with dedicated security teams. We are a small studio and we will not put a badge on this page that we have not earned.

What we offer instead is specificity: every measure on this page is written into Annex II of our DPA, which makes it contractually binding and auditable by you under section 7. If your procurement process requires a certified supplier, tell us early and we will say so rather than waste your time.

Do you run penetration tests?

Not on a scheduled commercial basis. We rely on secure defaults, database-level authorisation, a deliberately small data footprint, and the responsible disclosure process above. If a project warrants an independent test, we will say so during scoping and can work with a tester you appoint.

Will you sign our DPA instead of yours?

Usually yes. Send it over and we will review it. Our own DPA is published in full so you can see our standard position before you decide it matters.

Is our data used to train AI models?

No. We do not train models on client data and we do not pass client data to third-party AI services. Our internal assistant does not process client personal data, which is stated in Annex III. If that ever changed you would be notified 30 days beforehand with a right to object.

Who can access our production systems?

Only people working on your project, under named individual accounts, bound by confidentiality. There are no shared logins. Because we are a small team, that list is short and we can tell you exactly who is on it at any time.

What happens to our data if we stop working with you?

You choose: we return it in a common machine-readable format, or we delete it and confirm in writing. Tell us within 30 days of the end; if you tell us nothing we hold it for 60 days, remind you, then delete. Backups age out on their normal rotation. The full terms are in section 8 of the DPA.

Anything not covered here — email legal@vargu.digital. This page was last updated on 12 September 2026.

Site

  • Home
  • Services
  • Portfolio
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms & Conditions
  • Acceptable Use
  • DPA
  • Security

Contact

  • contact@vargu.digital
  • +383 49 481 641
© Vargu Digital. All rights reserved.