
Data management at Touchify

Summarise this article
On the occasion of World Backup Day, I wanted to share a few thoughts on the way data is managed at Touchify.
Since the OVH incident, I have been asked about the subject several times by customers, but also by some of our own colleagues — proof that the information does not always travel as well as it should, internally included!
Processing and storing data
Clear explanation and transparency matter here, and they matter at every level: whether you use a service or an application, or whether you are a developer, a project manager, or anyone else, technical or not, involved in a project that relies on hosting services or SaaS solutions.
We each have a personal duty to ask how data is processed and how it is backed up. The answer is usually available in the terms of use or in the contract that binds us to a provider. But it can depend on the service level subscribed to.
My data, for instance, may be backed up on the same server as my application — hardly a best practice, we can all agree — or in the same geographical location. If so, it is more likely to be lost in a major incident, with varying degrees of impact, be it a fire, an industrial accident or an earthquake.
To put your mind at ease, know that the various players in the industry pay very close attention to backing up data and to the continuity of their applications and infrastructure. But, as noted above, the terms can depend on the service subscribed to, which is why the customer consuming those services has to pay attention too.
Data management at Touchify
Coming back to these considerations as they apply to Touchify, we would like to shed some light on how we manage data, how we secure it and how we back it up.
1. Data storage and backup
Several types of data can be distinguished, each calling for different storage and backup arrangements depending on the need and on how sensitive the data is:
- user data, used for administration features, authentication and technical support;
- data tied to the use of Touchify: the content created in Studio, the information Publisher needs to operate, the statistical data used by Analytics;
- the files uploaded to the application, which account for the largest volume and benefit from storage and backup arrangements suited to that;
- anonymised data, used to improve the application and the user experience.
To guarantee that data remains available and persistent, Touchify relies on two Cloud service providers: Scaleway and Microsoft Azure.
The solution is built on a distributed infrastructure designed to guarantee service continuity. Some data is replicated in real time, so that it is available at any moment. Backups are taken at set intervals and stored securely in different geographical locations.
2. Data security
Here again, securing data and the exchanges between a user and the application happens on several levels.
First, every exchange is encrypted using the HTTPS protocol.
Next, service providers such as Scaleway and Azure meet very high security standards, both for access to the servers and for the protection of their data centres against intrusion and accidents. The backup systems use secure storage across several sites for optimal resilience.
Finally, the Touchify solution implements its own security management and a strong separation of user data. We also have internal processes in place to limit the risk of malicious acts, or of unintentional ones that could affect the service or the data.
One important point remains: user awareness. Today, the leading cause of intrusions and data loss is compromised user accounts. To counter this kind of attack, a service provider can put measures in place such as two-factor authentication or IP and device validation.
Part of the responsibility sits with the customer company and its users. Choose long, unique passwords. And above all, never share your credentials, whatever the reason!
3. The use of personal data
Touchify makes very limited use of personal data. It is used mainly for administration and support tasks, but also to send out communications such as newsletters or promotional offers.
The data in the content created in the application is strictly private, and our teams can only view it for support purposes and with explicit authorisation.
Some data is anonymised and used for statistical analysis, in order to improve the application and the user experience.
Conclusion
How data is processed and backed up concerns every one of us. Service providers work hard to deliver reliable, secure solutions. But it remains our own responsibility to check what they make available and what their terms of service say. Beyond that, everyone involved owes their customers and users clear explanations and transparency. That is what this piece is about.
Feel free to reach out on Linkedin if you would like to discuss the subject.
Take care of yourself… and of your data!
Recommended articles


Adok & Touchify: collaboration at your fingertips
