How Solace Care protects your data | Solace Care

End-of-Life Care

How Solace Care protects your data

The moments you share with Solace Care are private and protected. Learn how ISO 27001, encryption, and EU-first hosting keep your information safe.

Solace - Compliance

Solace Care protects your data with an ISO 27001-certified security programme, end-to-end encryption, and EU-based hosting — so the sensitive moments you share with us stay yours.

When a loved one dies, you share some of the most personal information of your life: bank details, insurance policies, medical paperwork, family relationships. You deserve to know exactly how that information is cared for. This article explains, in plain language, how Solace Care protects your data.

What does ISO 27001 certification mean?

ISO 27001 is the international standard for information security management. Fewer than one in ten European technology companies hold this certification because the audit process is rigorous and ongoing.

Solace Care is certified against ISO 27001:2022, the most recent version of the standard. In practice, this means an independent auditor has reviewed how we handle data, who has access to it, how we respond to incidents, and how we manage the people and suppliers who work with us. We re-certify every year.

How is your data encrypted?

Your data is encrypted in two places: while it travels between your device and our servers, and while it sits in our databases.

We use TLS 1.2 or higher for data in transit — the same standard that protects online banking. Data at rest is encrypted with AES-256, which is the encryption standard used by governments to protect classified information. If someone ever got physical access to our storage, the files would be unreadable without the keys we control.

Where is your data stored?

All personal data is stored within the European Union, in AWS data centres in Frankfurt, Germany. This matters for two reasons.

First, your data falls fully under the protections of GDPR — the strongest data protection law in the world. Second, we do not send personal data to servers outside the EU by default. When we do need to use non-EU tools (for example, some AI providers), we apply strict safeguards including data redaction, EU-hosted instances where available, and Standard Contractual Clauses aligned with the Schrems II ruling.

Who can see your information?

Only the people who need to. Our platform has four separate access layers: you, the loved ones you explicitly invite, a small number of Solace Care staff with role-based permissions, and our insurance partners — who only ever see aggregated, de-identified reporting, never individual cases.

Every Solace Care employee signs a Code of Conduct, passes background checks, and uses multi-factor authentication to access internal systems. Access is reviewed every quarter, and no one has more permissions than their role requires.

What happens if something goes wrong?

No security programme is perfect, and we plan for the days things go wrong. We have a documented incident response plan, run regular recovery drills against our backups, and conduct independent penetration tests to find weaknesses before anyone else can.

If a data breach ever affected you, we would notify you and the relevant supervisory authority within the 72-hour window required by GDPR. You can contact our Data Protection Officer at privacy@solace.care at any time.

Can you request your data or ask us to delete it?

Yes. Under GDPR, you have the right to access, correct, export, and delete your personal data. You can reach our privacy team at privacy@solace.care. We respond to every request within 30 days, usually much sooner.

If you choose to stop using Solace Care, your data is removed from active systems. We keep a minimum set of records for legal and regulatory purposes, and inactive accounts are fully deleted after three years.

What else should you know?

Security is a living practice, not a checkbox. Our team reviews new threats weekly, updates systems continuously, and treats every piece of customer information as if it were our own family's. If you ever want to understand more, our Security White Paper is available on request, and we are preparing a public Trust Center that will put more of this detail in one place.

Losing someone is hard enough. You should not also have to worry about whether the tools you trust are worthy of that trust. Solace Care is here to help you navigate this moment, and we take the responsibility that comes with it seriously.

Questions about security or privacy? Write to us at privacy@solace.care.

Related reading