The world is changing, and the age of digitalization has fundamentally transformed the way companies work today. With the ever-growing dependence on the internet, software and cloud services, an increasingly pressing question arises for many companies: Who actually controls our data, where is it processed and which legal framework does it fall under?
Digital sovereignty has thus long become more than a political buzzword. It is a business reality that affects companies every day. A reality that demands decisions. One of them is the choice of the right software. In this blog post, we look at European digital sovereignty and show how portatour®, as a European SaaS solution based in Vienna, can contribute to it.
Digital sovereignty in Europe: between dependence and self-determination
A large share of the business software used worldwide comes from providers outside Europe. For European companies, this can entail additional legal and organizational review obligations – especially when personal data is transferred to third countries, when providers use corporate structures outside the European Economic Area, or when sub-processors outside Europe are involved.
Under the GDPR, transfers of personal data outside the European Economic Area are only permitted under certain conditions. As a rule, this requires, for example, adequacy decisions, standard data protection clauses or other appropriate safeguards.
This is not just about the physical server location. Equally relevant are the provider’s location, corporate structure, sub-processors, support access, technical protection measures and the applicable legal framework. This is exactly where digital sovereignty comes in: companies should be able to understand where their data is processed, who has access to it and which rules apply to this processing.
The European Union is strengthening this framework through regulations and initiatives such as the Data Act, the AI Act and European data infrastructure projects, among others. However, political work alone is not enough. It also takes companies that translate European requirements into concrete technical, organizational and contractual measures.
How portatour® actively practices digital sovereignty in Europe
portatour® is a SaaS solution for automatic route planning and territory planning for the field sales team. Behind portatour® is impactit GmbH from Vienna, part of the Solvares Group. For companies that value European data processing, transparent commissioned data processing and traceable security measures, portatour® offers a European solution in a privacy-sensitive area. portatour® does not rely on mere promises, but on concrete measures that are relevant for companies when assessing digital sovereignty.
- Data processing in Europe
The productive processing of personal data within portatour® takes place in the European Union and the European Economic Area, respectively. This makes it possible to avoid unnecessary third-country transfers and to reduce the review obligations associated with international data transfers. For companies, this means: data processing remains within a European legal framework. This strengthens transparency, traceability and control – three key prerequisites for digital sovereignty.
- Own servers in Vienna
portatour® is operated on its own servers in Vienna. The servers are located in data centers whose information security management system is certified according to ISO/IEC 27001:2022. portatour® thus does not rely on an anonymous global cloud infrastructure, but on a deliberately European-oriented operating architecture. For companies that include data protection, IT security and digital independence in their supplier assessment, this is a key factor.
- Information security according to recognized standards
impactit has implemented an information security management system in accordance with ISO/IEC 27001. ISO/IEC 27001 is an internationally recognized standard for information security management systems and defines requirements for the systematic management of information security.
In addition, portatour® takes into account requirements from ISO/IEC 27018:2019 for the protection of personal data in cloud environments. The corresponding measures are regularly reviewed and further developed. For customers, this means: data protection and information security at portatour® are not just isolated organizational measures, but part of a structured security management system.
- No data disclosure without documented instructions
Insofar as portatour® processes personal data on behalf of a licensee, this is done on the basis of documented instructions. Within the scope of commissioned data processing, personal data is not disclosed to third parties without corresponding instructions from the licensee.
In addition, impactit takes technical and organizational measures to protect personal data against unauthorized access, loss or misuse. These include, among others, measures for access control, confidentiality, integrity and availability of the processed data.
This is particularly important for companies because with SaaS solutions, it is not only the feature set that counts, but also the question of how transparently providers handle data flows, sub-processors and access options.
- GDPR-compliant data processing agreement
For the processing of personal data on behalf of the controller, portatour® provides a data processing agreement in accordance with Art. 28 GDPR. It regulates the subject matter, duration, nature and purpose of the processing as well as the rights and obligations of both parties. The data processing agreement is therefore not a mere formality, but a central legal instrument for companies that want to use portatour® in compliance with data protection law. It creates clear foundations for responsibilities, instructions, protective measures and accountability obligations.
For companies using portatour® for their field sales team, this specifically means:
- European legal framework: through provider location, operation and data processing in Europe
- Reduced review effort: by avoiding unnecessary third-country transfers
- Verifiable compliance: based on contractual provisions, technical and organizational measures as well as external audits
- More transparency: through clear commissioned data processing and traceable data flows
- Stronger digital sovereignty: through a European SaaS solution for automatic route planning and territory optimization
Conclusion: European digital sovereignty starts with the choice of software
European digital sovereignty does not arise from political decisions alone. It is shaped every day by concrete decisions made by companies. By choosing providers that work transparently, take European data protection requirements seriously and document their technical and organizational measures in a traceable manner.
Those who select software decide not only on features. They also decide where data is processed, which legal framework applies, which dependencies arise and how well compliance requirements can be met in day-to-day business.
Those who choose portatour® choose a European SaaS solution that combines automatic route planning and territory optimization with data protection, information security and digital sovereignty.
