Version 1.0 · effective date to follow

Technical and Organizational Measures (Article 32 GDPR)

Annex 2 to the ALiSiO Data Processing Agreement · Version 1.0 · effective {{EFFECTIVE_DATE}}

This document describes the measures {{PROVIDER_NAME}} ("Provider") takes to protect personal data processed in the ALiSiO service. It describes measures in place at the effective date; measures that are only planned are not listed.

1. Confidentiality

Physical access. The Service runs on servers of a professional hosting provider in data centres in Germany (see the subprocessor list). Physical access control, video surveillance and on-site security are provided by the hosting provider under its certified information security management. The Provider does not operate its own server rooms.

System access.

Data access.

Separation of purposes. Production, test (beta) and development environments are separated. Development and automated tests use generated test data. Emails from the test environment are redirected to an internal mailbox and never reach real guests.

Pseudonymization and minimization.

2. Integrity

Transfer. All connections to the Service are encrypted with TLS (HTTPS). Off-site backups are encrypted before they leave the server.

Stored secrets. Access credentials to third-party services that Customers connect (for example channel or payment integrations) are stored encrypted (AES-256-GCM) per organization and are never stored in the source code.

Input control and traceability.

Change management. Every change to the software goes through version control, automated checks (types, several hundred functional tests, database schema comparison, tenant isolation, route protection) and review before it is deployed to the test environment and then to production. Production receives only versions that have run on the test environment.

3. Availability and resilience

4. Procedures for regular testing and evaluation

5. Organizational measures