Wise Timetable

Information security

ISO/IEC 27001:2022 certified

Certified since 2019, currently in our third certification cycle, by a UK-based certification body accredited by UKAS. The certificate is published below in full — please check it.

  • Standard: ISO/IEC 27001:2022
  • UKAS-accredited certifier
  • Held continuously since 2019

The certificate, in detail

Everything on this page is taken from the certificate itself, so it can be verified against the copy below or with the certification body directly.

FieldValue
Certified organisationWise Technologies Ltd., Cesta 24. junija 23, 1231 Ljubljana, Slovenia
StandardISO/IEC 27001:2022 — the current revision of the standard
ScopeDesign, Development, Implementation and Maintenance of Software Solutions
Statement of ApplicabilityVersion 3.0, dated 1 December 2024
Certificate number202124/A/0001/UK/En
Certification bodyURS — United Registrar of Systems (Holdings) Ltd., United House, 28 Poole Hill, Bournemouth BH2 5PS, United Kingdom
AccreditationUKAS Management Systems, accreditation number 0043; URS is a member of the IAF Multilateral Recognition Arrangement
Originally issued28 March 2019
Current cycle issued28 March 2025 (issue 3, cycle 3)
Valid until27 March 2028

Why the accreditation matters more than the badge

Anyone can print a certificate. The question a procurement office should ask is who accredited the body that issued it.

Ours was issued by URS, a certification body based in Bournemouth in the United Kingdom, accredited by UKAS — the United Kingdom Accreditation Service, the national accreditation body recognised by the UK government. UKAS accreditation number 0043 appears on the certificate itself.

URS is also a member of the IAF Multilateral Recognition Arrangement, which is what makes the certificate mean the same thing to a university in Riyadh, Kuala Lumpur or Dublin as it does in London. An unaccredited certificate carries none of that.

It is also worth checking which version of the standard a vendor holds. Ours is ISO/IEC 27001:2022, the current revision. Certificates against the superseded 2013 edition are still in circulation.

  • Issued by a UK-based certification body, not an unaccredited registrar
  • UKAS-accredited, accreditation number 0043
  • IAF Multilateral Recognition Arrangement member, so it is recognised internationally
  • Certified against ISO/IEC 27001:2022, not the superseded 2013 edition
  • Held continuously since March 2019, through three certification cycles
  • Scope explicitly covers software design, development, implementation and maintenance — the product itself, not just an office

What the certification actually commits us to

ISO/IEC 27001 is not a product feature and we will not present it as one. It certifies a management system: a structured, risk-based approach to information security covering people, processes and technology, audited by an external body on a recurring cycle rather than claimed once.

In practice, for an institution evaluating us, it means there is a documented Statement of Applicability, that risks are assessed and treated on a defined cycle, that access and change are controlled, and that an independent auditor checks all of it against a published standard.

  • Encryption of sensitive information in storage and in transit
  • Regular backups, with restores tested rather than assumed
  • Strict access controls limiting exposure to what a role requires
  • Documented incident response and change management
  • Annual surveillance audits, with full recertification every three years

Personal data, and the law that governs it

A timetable is not an abstract dataset. It says where a named student is at nine on Tuesday, and which lecturer is with them. That is personal data, and in some combinations it is sensitive.

We are based in Slovenia, inside the European Union, so the General Data Protection Regulation applies to us directly rather than as an export obligation we have chosen to honour. GDPR compliance is included in what you buy; it is not a chargeable module and there is no separate compliance tier.

In the language of the regulation, your institution is the data controller and Wise Technologies is a data processor. That distinction matters: the data remains yours, we process it only on your documented instructions, and we do not repurpose it. We do not sell or rent personal data, we do not use your institution's data to train anything, and we do not mine it for our own analytics.

We also try to hold less of it in the first place. A timetabling system does not need a student's home address, and asking for fields we will never use would be a liability for both of us. Where an institution can send us group identifiers rather than named individuals, we would rather it did.

  • A Data Processing Agreement is available and we will sign yours if you prefer your own wording
  • Personal data is not transferred outside the European Economic Area unless adequate safeguards are in place, such as EU Standard Contractual Clauses
  • Sub-processors are limited, disclosed on request, and bound by equivalent obligations
  • Data-subject rights — access, correction, erasure, restriction, portability, objection — are supported, and we assist you in answering requests as your processor
  • Retention is defined rather than indefinite: account data for the life of the subscription, imported scheduling data for as long as you use the service
  • Breach notification obligations are contractual, not discretionary
  • Full on-premises deployment where policy or national law requires the data never to leave your network

Beyond GDPR

Institutions outside the European Union bring their own obligations, and we would rather discuss them early than discover them late. Gulf institutions increasingly work under national data-protection laws with residency requirements; United States institutions raise FERPA; several of our clients answer to sector regulators as well.

We do not claim blanket certification against every regime, because that claim would not be honest. What we can say is that the on-premises option satisfies residency requirements outright, that our contractual terms can be adapted, and that we will tell you plainly if something you need is outside what we can commit to.

Read the Privacy Policy for how we handle personal data in detail, and the Terms and Conditions for the contractual position.

The certificate

Reproduced in full. The signed PDF is linked above and below.

Where your data lives is still your decision

Certification governs how we work; it does not oblige you to host anything with us. Cloud hosting runs on AWS with daily backups and regionally distributed infrastructure, and full on-premises installation is a supported alternative with identical functionality, support and upgrade terms.

For institutions in jurisdictions with data-residency rules, on-premises keeps every record inside your own network. More on hosting and deployment.

Questions procurement asks

Will you complete our information security questionnaire?

Yes, and we are used to it. Send it with your timescale and we will turn it around; we would rather answer forty questions before a contract than discover a mismatch after one.

If you need the certificate, the Statement of Applicability reference, or confirmation direct from the certification body, ask and we will arrange it.

Can we verify the certificate independently?

Please do. The certificate number is 202124/A/0001/UK/En and the issuing body is URS — United Registrar of Systems (Holdings) Ltd., Bournemouth, United Kingdom. URS publishes contact details for authenticity checks on the certificate itself.

UKAS also maintains a public register of the bodies it accredits, where URS appears under accreditation number 0043.

Is the scope broad enough to cover the software we would be buying?

Yes. The certified scope is 'Design, Development, Implementation and Maintenance of Software Solutions', which covers how Wise Timetable is built, deployed and supported — not merely how our office is run. Narrow scopes limited to a head office are a common thing to check for, and worth checking with every vendor.

What happens if we must keep data inside our country?

We install entirely on your own infrastructure. That is a standard deployment option with the same functionality, support and upgrade terms as cloud hosting, not a reluctant exception.

Running a security review?

Send us the questionnaire and the deadline. We will complete it properly, and tell you plainly about anything we cannot meet.