Security and trust, built for children's data

ISO/IEC 27001:2022 - independently certified, publicly verifiable

1

Certified entity

CampOrganizer APP GmbH (Vienna, Austria)

2

Certification body

Baltum Büroo OÜ

3

Certificate No.

AT-ISMS-270526-1

4

Certified scope

Design, development, operation and support of cloud-based web and mobile platforms for camp management and learning, including secure storage, processing, import and export of customer, parent and participant data in standard and white-label deployments

5

Original certification date

27 May 2026

6

Valid

27 May 2026 - 26 May 2027, renewed annually within a 3-year certification cycle subject to surveillance audits

7

Verify independently

https://baltum.io/certificate/

The controls behind the certificate

1

Role-based access

Every role sees only the data and actions its work requires. A counselor is not an administrator; an administrator is not automatically a reviewer of health data. Least privilege is the default, not a configuration you have to remember to set.

2

Sensitive data classified

Health, allergy, medication, and other special-category information is classified and encrypted, and shown only to the roles whose work requires it - not to everyone with a login.

3

Health data revealed with a reason

The most sensitive values are masked by default and revealed one at a time - by an authorized reviewer, with a stated reason, for a short window - and every reveal is recorded. If someone looked, you can see who, when, and why.

4

Contact with children is controlled

Reaching a child through the platform is a deliberate, recorded permission, separate from any staff or session assignment - never open by default.

5

Encrypted in transit and at rest

Data is encrypted in transit and at rest using industry-standard controls.

6

Hosted in the EU

The platform runs on infrastructure in the European Union, and stays there.

When a parent asks, you have an answer

Ownership, portability, and privacy

1

You own your data

Your organization owns its data. We store and process it to provide the service; ownership never transfers to us. No lock-in by design.

2

Export it yourself, safely

Administrators export the camp's data themselves in machine-readable form, and an export that includes sensitive data needs a second, different manager to approve it - so portability never becomes a leak.

3

GDPR practices

Role-based access, encryption, consent and data-rights handling, structured export, and documented data-processing practices support your obligations under the GDPR. CampOrganizer acts as a processor for the personal data your organization controls - the clean legal split institutional clients expect.

Found a security issue? Tell us.

Talk to us about security, privacy, or the certificate

See the platform your data will live on

© 2026 CampOrganizer. All rights reserved.