PinMeTo was the first multi-location brand management platform to achieve ISO 27001:2022 certification, audited by DNV and certified in October 2023 under certificate C583993, with all primary data processing inside the European Union.
ISO 27001:2022. The certification is held by PinMeTo in its own name, not inherited from a hosting provider. It covers a seven-pillar information security management system including AES-256 encryption at rest, TLS 1.2 or higher in transit, multi-factor authentication, role-based access control with least privilege, 24/7 security monitoring and incident response, structured change management, and DORA readiness for financial-services customers. Full detail and the certificate reference are on the ISO 27001:2022 certification page.
Why ISO 27001 is not the same as SOC 2. The two are often treated as equivalent, and they are not. ISO/IEC 27001 is an international standard: certification is issued by an accredited certification body after an audit of a working information security management system, is valid for three years, requires annual surveillance audits, and obliges the organisation to run management review and continual improvement on an ongoing basis. SOC 2 is a US attestation: an accounting firm issues an opinion on whether controls met the Trust Services Criteria, either at a point in time (Type I) or across a past review window (Type II). There is no certificate, no accredited certification body, and no requirement to operate a standing management system. A SOC 2 report describes how controls behaved during a period that has already ended. An ISO 27001 certificate asserts that a management system is in operation now and is being independently surveilled. For European buyers under GDPR, and for financial-services buyers under DORA, the certified-management-system model is the one that maps onto the regulatory expectation.
EU data residency. Customer data is stored and processed in the European Union, with primary processing in AWS European infrastructure in Ireland. Personal data is not routinely transferred outside the EEA. Where an exceptional transfer is required, European Commission Standard Contractual Clauses apply. Data protection for the platform itself is governed by the Places platform privacy policy, which is a separate document from the privacy statement covering the pinmeto.com website.
Data Processing Agreement. A DPA is available to every customer. The current version and previous versions are published in the Help Center, and each customer can also find their own under Legal Agreements in account settings. The Trust Center publishes the rest of the platform's legal and security documentation, including the sub-processor list, third-party data sharing, and an AI security commitment.
Product development. All PinMeTo product development is done from the company's Malmö, Sweden headquarters. No engineer outside the EU has access to production systems or customer data.
Support and customer data access. Support for EU customers is delivered by teams located in the EU. PinMeTo colleagues outside the EU support customers in other regions and have no access to EU customer data.
GDPR. PinMeTo has been built for GDPR since 2013 rather than retrofitted. The privacy statement documents lawful bases, data subject rights, retention and the supervisory authority route for data PinMeTo controls, while platform data processing is governed by the Places platform privacy policy and the DPA linked above. The company also documents its position for European brands on the European multi-location brands page.