Security and data protection
Somebody has sent you a security questionnaire, and one section is about us
This page is written for the person who has to fill that in: where the data lives, who touches it, how it is protected, what we are not certified for, and what happens if you decide to leave. No sales copy between you and the answer.
Email the section that concerns us and we will complete it and send it back, usually the same day. You do not need to be a customer, and there is no follow up sequence afterwards.
The short answers
Fourteen questions, answered before you ask them
These are the ones that appear, in some wording, on every supplier assurance form we have been sent. They are short on purpose — short enough to read before you go back to the form, and to paste into it.
| The question | The answer |
|---|---|
| Where is our data stored? | The European Union — eu-west-1, Ireland — on ISO 27001 certified infrastructure. Transfers from the UK rely on the UK adequacy regulations for the EEA, so there are no standard contractual clauses to review and no transfer risk assessment to do. |
| Is it encrypted? | In transit, TLS on every connection. At rest, by the hosting and database providers. |
| Who is the controller? | You are. Noon Elite Ltd is the processor. You decide what is collected, how long it is kept and who can see it, and those decisions are written into the Data Processing Agreement rather than left to us. |
| Is there a DPA? | Yes, provided as standard with every contract rather than on request. Ask for it before you sign anything and we will send it. |
| How long is data kept? | For the retention period you set, per site, within the range in the DPA. Records are automatically and permanently deleted when it expires. The badge audit trail runs on its own period because it records who was admitted to a building. |
| Can our data be separated from other customers’? | Every record is bound to its client organisation, enforced in application code and by row level security in the database. |
| Do you use multi factor authentication? | Our administrative accounts require it and cannot be used without it. |
| Is any of it processed outside the UK or EU? | One exception, and only if you licence Permit to Work: Resend dispatches its email from the EU but stores account data, email metadata and delivery logs in the United States, under its certification to the UK Extension to the EU-US Data Privacy Framework. Without that module, nothing belonging to your visitors, contractors, couriers or staff is stored in the United States. |
| Do you use biometrics or facial recognition? | No. No facial recognition, no biometric matching and no automated decision making at any point. A visitor photograph is captured only if you turn it on, and it is used to identify somebody on a badge. |
| Do you process special category data? | Not by design. Where a site has a health declaration, the kiosk shows it and records that the visitor accepted it, with the wording and the time. It does not ask for or store an account of somebody’s symptoms. |
| Do you store card details? | No. Card payments are handled entirely by the merchant of record and we never see the number. |
| What is your breach notification time? | We notify the affected client within 48 hours of becoming aware of a personal data breach in kiosk data. You are the controller, so the decision to report to the ICO is yours. |
| Will you tell us before you change a sub-processor? | Thirty days’ written notice, with a right to object. |
| What is the uptime commitment? | We target 99.9% software uptime and aim to respond to support requests within 24 hours during UK business hours. Where your signed agreement states different figures, those apply. |
Every one of these is also in the privacy policy, which is the document that governs. This table is the same thing arranged for somebody with a form open rather than for the ICO.
How it is protected
Six controls worth being specific about
“Industry standard security” is what a supplier writes when they would rather not be pinned down. These are the measures in place, named so that a reviewer can tell whether they are the right ones.
Nothing sensitive lives on the kiosk
Database credentials are never held in a browser or on a kiosk device. Every read and write is mediated by server side code. An iPad taken off a stand and walked out of the building is an iPad, not a copy of your visitor log.
Your records are separated from everyone else’s
Tenant separation is enforced twice: in application code, and by row level security in the database itself. The second one is the one that matters, because it holds even if the first is wrong.
Credentials that cannot be read back
Approver PINs are stored as salted scrypt digests and are not recoverable by anyone, us included. Contractor access links are cryptographically signed, expiring, and single use where appropriate.
Brute force gets nowhere
Rate limiting and brute force protection on the kiosk endpoints, on PIN entry and on contractor authentication codes. A four digit PIN is only weak if you are allowed to try ten thousand of them.
Photographs are not on the open web
Where a site captures them, they sit in a private object store, are not publicly addressable, and are reachable only through short lived signed links. No guessable URL, no directory to crawl.
Access on a need to know basis
Only people with a business need can reach client data, and our own administrative accounts require multi factor authentication to exist at all. There is no shared login and no standing access for a support tier, because there is no support tier.
No system is perfectly secure and we do not claim otherwise. Where a personal data breach occurs in kiosk data we notify the affected client within 48 hours of becoming aware of it, and it is you, as the controller, who decides on any report to the ICO.
Who else touches it
The whole sub-processor list, on a page you did not have to ask for
Five, and this is all of them. Changes require thirty days’ written notice to you, with a right to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | EU — eu-west-1, Ireland |
| Vercel | Application hosting and compute | EU — eu-west-1, Ireland |
| PostHog | Product usage analytics | European Union |
| Sentry | Application error monitoring, with request URLs, credentials and session cookies redacted before transmission | European Union |
| Resend | Transactional email, Permit to Work module only | Dispatched from the EU. Account data, email metadata and delivery logs stored in the United States |
Two things people expect to find on that list, and why they are not
- Your own Teams or Slack workspace. Where arrival notifications are enabled, that workspace is under your control and you are the controller in respect of it. We are not putting your visitor data somewhere you cannot see.
- The platform we use to manage the hardware. The iPads are ours, so we run mobile device management on them. It holds device identifier, serial number, operating system version and configuration for our own equipment. It has no access to any personal data inside the kiosk application.
For your IT department
There is nothing here for them to own
The reason a visitor kiosk stalls in procurement is rarely the security answers. It is that somebody in IT reads the words “new system” and correctly works out who ends up maintaining it. This is the part of the answer that gets the project moving again.
- Nothing to install and no server to run. There is no agent on your network, no appliance in a comms cabinet and no directory integration to build. The kiosk needs a WiFi connection and a mains socket where it is going.
- No inbound firewall rules. The iPad makes outbound connections over TLS to the application, the way any other tablet on your guest network would. It does not need to be reachable from outside.
- Hardware is our problem, not yours. The iPad and stand are ours, included in the monthly price and managed by us. If a unit fails we ship a configured replacement in three to five working days. Your asset register does not change.
- You are not being asked to own a new system. Hosting, backups, monitoring and updates run in the background and are part of the fee. Nobody on your side gets paged about this, and nobody has to patch it.
The website you are on
Worth knowing, since you are checking
- No trackingnoonelite.com sets no analytics, advertising or profiling cookies. There is no tag manager, no chat widget, no consent banner, and no third party request on any page.
- The videoEvery demonstration video on the site is a still image and a play button. Nothing is requested from YouTube or Google until you press it.
- CompanyNoon Elite Ltd, registered in England and Wales, company number 17223153. Registered with the Information Commissioner’s Office, ICO number 00014127862.
Being straight with you
What we cannot tick
- Noon Elite Ltd does not hold ISO 27001, SOC 2 or Cyber Essentials Plus certification of its own. The infrastructure your data sits on is ISO 27001 certified; the company operating it is a one person business and has not been through an audit of its own. If your procurement policy requires a certificated supplier, that is a real answer and it is no.
- There is no third party penetration test report to send you. If your questionnaire has a field for one, put “none held” in it rather than leaving it blank, and bring it to the call.
- There is one of us. No 24/7 on-call rota, no status page and no second engineer. The comparison page says the same thing in the same words, because it is the trade you are making and it should be made with your eyes open.
- We are the processor. Your lawful basis, your privacy notice wording and the retention period you choose are yours to decide, ideally with someone qualified. We are not data protection lawyers.
- A visitor kiosk evidences physical entry to a building. It says nothing about your network, your access reviews, your suppliers or your backups, and a security reviewer who treats it as though it did has misread it.
If any of those is a hard stop in your procurement policy, say so on the first call and we will not waste your afternoon. If they are not, the rest of this page is what you have to work with, and all of it is checkable against the documents linked from it.
Before you ask
The six that come in by email
Where is Noon Elite visitor data hosted?
In the European Union — eu-west-1, Ireland — on ISO 27001 certified infrastructure, through Supabase for the database, authentication and file storage and Vercel for application hosting. Transfers from the UK rely on the UK adequacy regulations for the EEA, so no standard contractual clauses or transfer risk assessment are required. The one exception is the Permit to Work module, where Resend stores email account data and delivery logs in the United States under the UK Extension to the EU-US Data Privacy Framework.
Is Noon Elite ISO 27001 certified?
No. The infrastructure the data sits on is ISO 27001 certified, and that distinction matters, so it is worth stating plainly: Noon Elite Ltd has not itself been through a certification audit. It is a one person business. If your procurement policy requires a certificated supplier, we are not one, and it is cheaper for both of us to know that on the first call.
Does the kiosk need access to our network?
No. There is nothing to install, no server to run, no agent on your network and no directory integration. The iPad makes outbound TLS connections to the application over a WiFi connection — a guest network is fine — and needs a mains socket. It does not need to be reachable from outside, so there are no inbound firewall rules to open.
Who can see our visitor records?
People at your site with a login you have granted, and people here with a business need. Every record is bound to your organisation in application code and by row level security in the database. Our administrative accounts require multi factor authentication and cannot be used without it. Database credentials are never held in a browser or on a kiosk device — every read and write goes through server side code.
Will you sign our data processing agreement?
We provide one as standard with every contract, and you can have a copy before you sign anything. If your legal team would rather paper it on your own template, send it over and we will read it. Changes to our sub-processor list require thirty days’ written notice to you, with a right to object.
What happens to our data if we stop being a customer?
You export your records at any time from the dashboard, in a format that opens without our software, and that includes on the way out. Send the hardware back within fourteen days of termination and that is the end of it. Retention and deletion of what remains run as set out in the Data Processing Agreement.
ISO 27001 visitor access controlThe paper book and UK GDPRCMMC physical security
Next step
Send the questionnaire, not a meeting invite
Forward the section that concerns your suppliers and we will fill it in and send it back, usually the same day. If it turns out we cannot satisfy it, we will tell you that instead of writing around it.
Email the questionnaireYou do not need to be a customer to ask, and nothing automated happens afterwards.
Would rather talk it through? Book a 15 minute call