Hopp Solutions

Cloud and infrastructure engineering for business-critical environments.

Case StudiesInsightsAboutContact
ENDE
Book an Infrastructure Review

Security, Privacy & Compliance

Security and privacy are part of the operating model.

Hopp Solutions works with business-critical infrastructure and treats access, data handling, documentation and recoverability as operational responsibilities. We apply documented technical and organizational measures, limit access to what is required and support clients with contractual and compliance requirements relevant to the engagement.

How we work with client data

  • DPA Available
  • Named Accounts & MFA
  • Least-Privilege Access
  • Controlled Remote Administration

Data-protection commitment

Personal data is processed for a defined purpose, with defined access and retention.

Hopp Solutions processes personal data in accordance with applicable data-protection requirements, including the EU General Data Protection Regulation where it applies to our activities, the North Macedonian Law on Personal Data Protection and the Swiss Federal Act on Data Protection where relevant to a client engagement.
We use data minimization, purpose limitation, access control, confidentiality, documented retention and secure deletion as part of our data-handling model. Where Hopp acts as a processor, we work under the client's documented instructions and an applicable Data Processing Agreement.
iamgeshadow

How we access client environments

Access is attributable, limited and removable.

icon

Named identities

Administrative work should use individual, attributable accounts rather than shared credentials wherever the platform permits.

icon

Multi-factor authentication

MFA is required for privileged and remote access where supported.

icon

Least privilege

Access is limited to the roles, systems and time period required for the agreed task.

icon

Controlled remote administration

Sensitive administration is performed through approved client or controlled remote environments. Client information is not intentionally stored on unmanaged endpoints.

icon

Access removal

Access is reviewed during the engagement and removed when it is no longer required or when the service ends.

icon

Change evidence

Material changes, decisions, exceptions and validation results are recorded according to the project or service process.

When Hopp acts as a processor

The agreement defines the processing, not the assumption.

Where Hopp Solutions processes personal data on behalf of a client, the agreement should define the subject matter, duration, nature and purpose of processing, data categories, data subjects, documented instructions, confidentiality, security, subprocessors, incident notification, assistance, deletion or return and audit information.
A Data Processing Agreement and a summary of relevant technical and organizational measures are available for qualifying engagements.
iamgeshadow

International data transfers

Data location is reviewed during onboarding.

Data location and transfer requirements are reviewed during onboarding. Where personal data is transferred to a country without an applicable adequacy basis, the contract and operating model must use an appropriate transfer mechanism and supplementary safeguards where required.
iamgeshadow

Incident and breach handling

Material events are contained, documented and communicated.

Hopp Solutions maintains an escalation process for security events affecting client environments or personal data within our control. Material events are contained, documented and communicated to the client according to contractual and legal requirements so the client can meet its own assessment and notification obligations.
iamgeshadow

Security and privacy information available

  • Data Processing Agreement template.
  • Technical and organizational measures summary.
  • Subprocessor and data-location summary, where applicable.
  • Secure-access and offboarding overview.
  • Incident and breach-notification overview.
  • Business-continuity and backup overview for Hopp-operated services.
  • Relevant certifications or partner statuses, only where current and verifiable.

What we do not claim

We do not present GDPR compliance as a government-issued certification.

We do not claim ISO 27001, SOC 2 or other certification unless formally obtained and current.

We do not promise that any technology or process eliminates all security risk.

We do not publish client security details, credentials or architecture without authorization.

Procurement, security and legal teams can request the relevant privacy and security documentation for a planned engagement.

Hopp Solutions

Cloud and infrastructure engineering for business-critical environments.

Based in Ohrid, North Macedonia. Supporting organizations and technology teams across Europe.

Copyright 2026 Hopp Solutions Dooel. All rights reserved.