• Über Nashua® B.V.
  • Kontakt
  • Nashua 360 Enterprise
  • Digital Transformation
  • Enterprise Architecture
  • Information Technology
Menü
Nashua® B.V.

Main menu

Skip to primary content
Skip to secondary content
  • Nashua 360
    Enterprise
  • Digital
    Transformation
  • Enterprise
    Architecture
  • Information
    Technology

Trust Center

Last updated: 31 July 2026

Security, privacy and regulatory compliance are foundational to how Nashua builds and operates the Nashua 360 Enterprise Platform and our managed services. This Trust Center summarises the regulations we work under, the standards our security programme is built to, the measures that protect your data, and where to find our legal documents.

Regulatory compliance

As a Dutch company, we operate under the laws of the Netherlands and the European Union. We process Personal Data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Dutch GDPR Implementation Act (UAVG). Where they apply to our services and our clients, we also take account of the Digital Operational Resilience Act (DORA) and the NIS2 Directive as implemented in Dutch law, and we design our platform and operations so that our clients can meet their own obligations under these regimes.

Certifications and assurance

Our information-security programme is built to the requirements of ISO/IEC 27001 and the SOC 2 Trust Services Criteria. We are actively working toward formal ISO/IEC 27001 certification and SOC 2 attestation (Type I and Type II), and in the meantime we operate the controls, policies and evidence practices these frameworks require. We do not yet hold these certifications; this page will be updated as they are achieved.

Because there is not yet a certification or attestation report to bridge, we can provide a letter of intent, a formal statement of our commitment to and progress toward ISO/IEC 27001 certification and SOC 2 attestation, to clients and prospective clients who need assurance during procurement. This serves the same purpose as a bridge letter, which we will issue in the usual way once our reports are available. Our current status, letters of intent and any available reports can be shared with clients and prospective clients on request, under NDA.

Security measures

We maintain technical and organisational measures appropriate to the risk, including: role-based access control and least privilege with multi-factor authentication; encryption of data in transit and at rest; network segmentation and perimeter controls; centralised logging, monitoring and alerting; secure software development, code review and change management; vulnerability management and penetration testing; backup and tested disaster recovery; supplier and sub-processor risk management; personnel screening, confidentiality obligations and security-awareness training; and a documented incident-management and breach-notification process. These measures are described more fully in Annex B of our Data Processing Agreement.

Data residency and sub-processors

By default, Personal Data is hosted within the Netherlands and the European Economic Area. We do not transfer Personal Data outside the EEA without an adequacy decision or appropriate safeguards under Chapter V GDPR. We engage a limited set of sub-processors, principally for hosting and infrastructure within the Netherlands and the EEA; a current list, with each sub-processor's role and location, is available to clients on request, and we notify clients of intended changes as set out in our Data Processing Agreement.

Data protection and legal documents

We process Personal Data only as needed to provide our services and on our clients' documented instructions. Our Privacy Policy explains what we collect and why; our Data Processing Agreement governs how we process Personal Data on a client's behalf, giving effect to Article 28 GDPR; and our Terms and Conditions set out the contractual basis for our services.

Contact

For security, privacy or compliance enquiries, or to request our current certification status, sub-processor list or security documentation, reach us via our contact page or by email at info@nashua.nl.

Nashua® B.V.
Nashua® B.V.
Nashua® Cloud B.V.
Lichttoren 32
5611 BJ Eindhoven
Niederlande

info@nashua.nl
+31 (0)40­ - 304­ 1468
AGB|Datenschutzerklärung|Trust Center
Nashua® ist eine eingetragene Marke von RM.
Copyright © 1999-2026 Nashua® B.V. and Subsidiaries