Skip to main content

Data security and governance

Are you assessing EASYTM® as a supplier?
Every access leaves an audit trail.

EASYTM® runs on servers in Italy, each user sees only what their role allows, the application logs access and changes and, by choice, there is no function for downloading data in bulk.

Here you will find the principles; at the meeting we go into the details, including with the people in your organisation who assess suppliers: IT, compliance, risk, data protection.

The principles in brieffor those assessing suppliers
Servers in Italyrun by an Italian provider
One-time passwordsent to your own email inbox
Role-based accesseach user sees what their role allows
Access loggedand changes, user by user
No bulk downloada security choice
Continuityautomatic backups and written plans
Further down: what DORA and NIS2 require regarding suppliers.

Access

Who sees tenant and property data in EASYTM®, and what is recorded

In EASYTM® every request is tracked through to closure, and the same goes for everyone who accesses the data.

Everyone sees only what is theirs to see

You can sign in with a one-time password sent to your own email inbox, and each user sees only what their role allows.

A record of who does what

Access is only through the application, which logs each user’s access and changes.

No bulk data download

EASYTM® has no functions for downloading data in bulk: it is a security choice.

Protection, continuity and audits

The principles by which D.P.S. protects data in EASYTM®

Measures are chosen on the basis of a risk analysis, and data protection applies by design and by default.

Servers and support in Italy

EASYTM® is a cloud service hosted on servers in Italy, run by an Italian provider. Support is provided from Italy by Italian staff.

Authorised and trained staff

Only authorised staff access the systems, with personal, named user accounts and permissions limited to what is necessary. Anyone working on the data is bound by confidentiality and trained in data protection.

System administrators appointed by name

System administrators are appointed by name and their access is logged, as required by the Italian Data Protection Authority (Garante per la protezione dei dati personali).

Regular updates and checks

D.P.S. applies security updates regularly and reviews system configurations and user accounts.

Backups and continuity

Backups are made automatically, and they are tested to make sure they can be restored. D.P.S. has written business continuity and disaster recovery plans.

Your audits of D.P.S.

If you choose EASYTM®, you can audit D.P.S., with your own staff or through external auditors.

DORA and NIS2

DORA and NIS2: what they require regarding suppliers and how EASYTM® helps you

Organisations within the scope of DORA, the EU regulation on digital operational resilience for the financial sector, or of the NIS2 Directive must also look after the security of their ICT providers, in proportion to the risks. The principles on this page are the starting point for assessing EASYTM®; the assessment is yours to make.

DORA and ICT providers

DORA requires financial entities, such as fund managers within its scope, to manage the risks of their ICT third-party service providers and to keep a register of information on them. To assess EASYTM®, here you will find the first answers: where the service runs, who accesses the data, backups and continuity, and the audits you can carry out. At the meeting we go into the details, including the agreed service levels.

NIS2 and supply chain security

NIS2 requires the essential and important entities within its scope to look after the security of their suppliers too. The measures it lists include risk analysis, access control, security updates, backups and business continuity: these are also the principles by which D.P.S. protects data in EASYTM®.

Legal references under legal review.

Frequently asked questions

Frequently asked questions about data security in EASYTM®

Is EASYTM® secure?

EASYTM® protects data in these ways: it runs on servers in Italy, each user sees only what their role allows, the application logs access and changes and, by choice, there is no function for downloading data in bulk. D.P.S. applies security updates regularly, makes backups automatically and has written business continuity and disaster recovery plans. At the meeting we go into the details.

Where are the EASYTM® servers located?

In Italy: EASYTM® is a cloud service hosted on servers in Italy, run by an Italian provider. Support is also provided from Italy by Italian staff.

Who can sign in to EASYTM® and what can they see?

You can sign in with a one-time password sent to your own email inbox, and each user sees only what their role allows; the application logs everyone’s access and changes. Only authorised staff access the systems EASYTM® runs on, with personal, named user accounts; system administrators are appointed by name, and their access is logged.

How is personal data processed in EASYTM® under the GDPR?

D.P.S. processes personal data on behalf of the organisations that choose EASYTM®, acting as their processor. Data protection applies by design and by default, and anyone working on the data is bound by confidentiality and trained in data protection.

Can I audit the security of EASYTM®?

Yes. If you choose EASYTM®, you can audit D.P.S., with your own staff or through external auditors.

Does EASYTM® help a fund manager with DORA?

DORA requires financial entities, such as fund managers within its scope, to manage the risks of their ICT third-party service providers and to keep a register of information on them. To assess EASYTM®, a fund manager will find the first answers on this page: where the service runs, who accesses the data, backups and continuity, and the audits it can carry out on D.P.S. The assessment is the fund manager’s to make, and at the meeting we go into the details it needs, including the agreed service levels.

Does EASYTM® help with NIS2?

NIS2 requires the essential and important entities within its scope to look after the security of their suppliers too, in proportion to the risks. The measures it lists include risk analysis, access control, security updates, backups and business continuity: these are also the principles by which D.P.S. protects data in EASYTM®. The assessment is yours to make.

Who makes EASYTM®?

EASYTM® is made in Rome by D.P.S. Soluzioni Informatiche S.r.l., a software house since 2002. It has been in use since 2022, with about 10,000 events handled every year in Italy (an event is a recorded step of a request; data as of 19 May 2026). Support is provided from Italy by Italian staff.

Who is behind EASYTM®

EASYTM® is made in Rome by D.P.S. Soluzioni Informatiche

2002
software house since
2022
EASYTM® in use since
~10,000
events handled every year
Italy
servers and support

Data as of 19 May 2026, based on EASYTM® tickets since 2022.