PROdb Security and Privacy

Details about Security and Privacy in the eSolia PROdb Cloud Database

Security and Privacy Policy

Updated: October 29, 2025

The privacy of your data is very important to us. This document explains how your data is stored, where it is stored and whether it is stored securely.

PROdb” is our brand name for the applications eSolia develops and hosts via the PaaS “dbFLEX”, owned and operated by ForeSoft. This document’s use of the brand name “PROdb” refers to the PaaS service.

Security

Infrastructure

Customer Data is stored and processed in the following data centers with appropriate physical, technological, and administrative controls enacted to ensure appropriate access of Customer Data.

Data Centers

  • Steadfast Networks Data Center Colocation, Chicago, IL, United States
  • Biometric authentication locks and 24/7 surveillance systems
  • Dual diesel-powered emergency generators
  • Advanced fire suppression systems
  • Security and Certifications

Data Encryption

Communication Encryption

  • 256-bit (SHA2) TLS certificate encryption
  • Support for TLS 1.0, 1.1 and 1.2
  • All data communications protected by SSL

Storage Encryption

  • Databases encrypted via AES256
  • File attachments also encrypted via AES256
  • Backup data stored in encrypted format

Data Backups and Disaster Recovery

Backup System

  • Hourly automated data backups
  • Encrypted backup files
  • Secure disaster recovery facility replication
  • 6-month retention period before permanent deletion
  • No removable media used for backup storage

Recovery Infrastructure

  • Rapid disaster recovery capabilities
  • Secure server backup storage
  • Special recovery procedures for natural disasters and security breaches

Personnel Access Control

Administrative Access

  • Small operations team with infrastructure access
  • Read-only access to database metadata for troubleshooting
  • No customer database access without invitation or authorization

Security Measures

  • All employees sign confidentiality agreements
  • Security training and best practices education
  • VPN-only remote server access for authorized personnel
  • All access events logged by IP address

Incident Response

Response Protocol

  • Email notification to all affected customers within 72 hours of suspected or confirmed data breach
  • Rapid investigation and response measures
  • Transparent reporting and improvement strategies

Privacy

Personally Identifiable Information (PII)

Information We Collect

  • First and last name - for personalized user experience
  • Email address - for unique user identification and communication
  • Password - for account security
  • Locale and time zone - for appropriate data formatting

Data Handling

  • User accounts cannot be deleted due to data integrity constraints
  • Personally identifiable information can be cleared upon request
  • Secure encryption protects all information

Sharing Personally Identifiable Information

Third-Party Disclosure

  • We will never pass your personal information to third parties
  • We won’t use your name in marketing statements without your permission

Internal System Usage

  • Secure copying into customer database, support system, billing system
  • All systems covered by eSolia’s Security and Privacy Policies

Purpose

  • User authentication
  • Keeping user preferences
  • Tracking user movements around the site

Security

  • No cookies contain personally identifiable information
  • Secure implementation and access controls

Law Enforcement

Policy

  • We reject requests to supply data to law enforcement unless by official court order
  • We reject data disclosure requests without legal mandate
  • We will always inform customers when we receive such requests (unless legally prevented)

Data Retention and Deletion

Customer Responsibilities

Data Management

  • Customers are responsible for understanding and implementing their data retention and deletion requirements
  • Customers may delete their data at any time
  • Immediate erasure from production systems

Complete Purge Timeline

  • Up to 6 months for complete purge from PROdb backup systems
  • Security and recovery backup retention period

Deletion Processes

Deleted Records

  • Moved to database “Recycle Bin” for 30 days
  • Automatic purge after 30 days
  • Manual purge available by database administrator

Expired Databases

  • Databases become ‘expired’ when trial period ends or subscription is cancelled
  • PROdb system blocks access to expired databases
  • Paid databases: securely kept in locked state until deletion
  • Trial databases: automatically deleted within 90 days after expiration

Deleted Databases

  • Immediate disappearance from user access
  • Physical deletion from system within 30 days
  • 6-month residence in system backups

Additional Important Information

Business Continuity

Stable Operations

  • ForeSoft (dbFLEX operator) maintains strong financial stability
  • 100% debt-free operations without reliance on financing
  • No intention to cease operations
  • Commitment to serving customers throughout database subscription life

Data Portability

  • Export tools provided for local data storage
  • Customer data portability guaranteed

Intellectual Property

Customer Rights

  • Database structure and workflow configuration are customer intellectual property
  • PROdb protects customer intellectual property
  • No sharing with other customers

Changes to This Document

We reserve the right to modify this document at any time. We will announce changes on this website in the news section.

Contact Information

If you have any questions or concerns regarding this statement, please contact eSolia Inc.:

eSolia Inc.
Shiodome City Center 5F (Work Styling), 1-5-2 Higashi-Shimbashi,
Minato-ku, Tokyo, Japan, 105-7105
Main: +813-4577-3380
Urgent Support: +813-4577-3389

Website: esolia.com | esolia.co.jp