Heroku
Access description
Heroku is used for hosting our legacy API.They do not have direct access to data in that API unless support is invoked
Access to source systems
Heroku
Data
User
User
Represents an individual account on Heroku with access to apps and services.Pii: Yes
Special Pii: None
Goal Of Data: Management of Legacy API
Retention: For duration of employment
Project
Project
Represents an application or service deployed on Heroku.Pii: No
Special Pii: None
Goal Of Data: Hosting of (Legacy) API
Retention: For the duration of the contract with the supplier
Physical Location
Frankfurt, Germany
✅ All in EER
✅ All in EER
Database System
Supplier cloud
Encryption
✅At Rest
✅In Transit
Automated: AWS Key Management Service
✅In Transit
Automated: AWS Key Management Service
Last review: 16/06/2026. Next review planned for 16/06/2027