You do not choose software on features and price alone. Increasingly, the way a vendor handles data determines whether a solution fits. Especially for organisations that work with confidential or personal data.
These five questions help you have that conversation well. They are deliberately simple: a vendor that answers them clearly usually brings clarity about everything else too.
1. Where is our data stored?
Do not just ask whether data is 'secure', but where it physically resides and under which legislation. Within the European Union, jurisdiction is clear. Vague answers are a warning sign.
2. Who has access and how is that controlled?
Who at the vendor can see your data? How are rights assigned and audited? A good vendor can explain this in detail, including roles, logging and access management.
3. Is our data used for AI or other purposes?
AI is powerful, but only if you know what happens with it. Is your data used to train models? Is it shared with external parties? The answer should be 'no, not without your permission'.
4. What happens to our data if we leave?
A vendor that is confident in its product makes leaving easy. Can you export everything? Is data fully deleted? Ask about the process and the timelines, not just the promise.
5. How are we supported on privacy and GDPR?
Privacy is a shared responsibility. Ask what support you get: a data processing agreement, help with data breaches and someone who takes your questions seriously. That is a sign that compliance is not an afterthought.
At dreebro we build with these principles as a starting point. Want to know how we handle data? Get in touch.