Trust Center

The Vienna Test System (VTS) is designed to be a secure, reliable, and compliant platform for psychological assessment. It is a system used to determine and collect highly sensitive data of individuals. Therefore, the protection and secure handling of such data is of utmost importance and a central driving force in the design of our system and processes. This document gives an overview of the general measures in place at SCHUHFRIED and as part of the VTS. Additionally, it explains SCHUHFRIED's typical role as a data processor and the related, GDPR-compliant contractual relationship with its customers.

Technical and organizational measures

As a basis for the technical and organizational measures in place at SCHUHFRIED and within the VTS, it can be helpful to get a general overview of its capabilities and variants (see Product description). To obtain a comprehensive view of the security framework protecting the VTS, it is essential to look beyond the software's functional capabilities and examine the underlying structures. A detailed overview of how we ensure system integrity and data protection can be found on the page Technical measures. It covers the architectural safeguards and automated defenses integrated into the product, as well as technical implementation details such as cookie usage.

Complementing these digital controls are organizational measures (see Organizational measures), that cover our development processes, operational measures and administrative workflows that govern our internal operations. Together, these two pillars form the basis for our compliance with high-security standards, ensuring that every deployment of the VTS remains resilient, transparent, and legally compliant.

Certifications & reference models

An overview of SCHUHFRIED's certifications and how our technical and organizational measures relate to internationally recognized security frameworks can be found on the page Certifications and reference models.

VTS online – managed by SCHUHFRIED

The following sections apply specifically to VTS online, where SCHUHFRIED hosts and operates the platform on behalf of its customers.

Customer data lifecycle

At SCHUHFRIED, we have established a structured data lifecycle designed to balance legal requirements with the practical needs of our customers. Throughout this entire cycle, all data stored in our systems is protected by industry-leading security measures, including state-of-the-art encryption at rest and in transit, and hosted in highly secure, certified data centers.

Upon the expiration of a system license, the account enters a three-month grace period during which data remains accessible in a read-only mode, allowing users to export data an view test results. After this period, access to the platform is automatically suspended and all client data is scheduled for deletion. SCHUHFRIED guarantees that all personal information is permanently and irretrievably purged from systems no later than six months after the end of the active contract, ensuring the highest level of data integrity and confidentiality from start to finish.

Service level agreement (SLA)

SCHUHFRIED operates VTS online to provide a frictionless, dependable solution for our customers. Our commitment to the reliability of VTS online is formalized in a Service Level Agreement, which defines the guaranteed availability of the platform, planned maintenance windows, and incident response times. SCHUHFRIED guarantees an availability of 99.5% per calendar quarter. Full details, including compensation terms, are set out in the Service level agreement (SLA) – VTS online.

Data Processing Agreement (DPA)

With VTS online, SCHUHFRIED acts as a data processor (Auftragsverarbeiter) under the GDPR on behalf of its customers, who act as data controllers. The terms governing this relationship are set out in SCHUHFRIED's Data Processing Agreement (DPA), which is effective for all current customers of VTS online.

Customers who prefer or require an individually signed copy of the Data Processing Agreement for their internal compliance processes may request one at any time. For this purpose, please use this template:
📄 Data Processing Agreement-20260810.pdf.
Enter your organization's information and get in touch through our contact form or your account manager.

Where an organization requires custom compliance documentation or the completion of individual security questionnaires, please note that such requests are considered additional consulting services and are subject to a fee based on actual time and effort required.

VTS offline - operated by the customer

VTS offline is installed and operated on the customer's own premises and infrastructure. SCHUHFRIED does not host or manage these systems and has no access to the data stored within them. Responsibility for the security and reliability of VTS offline installations therefore rests with the customer.

VTS offline can be operated in a secure and reliable manner when properly installed, configured, and embedded in appropriate organizational processes. SCHUHFRIED supports this through comprehensive technical measures built into the product itself, including encrypted communication, secure authentication, and a robust service architecture, as well as through its rigorous software quality and release processes, which ensure that every version of VTS offline meets the highest development standards.