Technical and Organizational Measures (Article 32 GDPR)
Annex 2 to the ALiSiO Data Processing Agreement · Version 1.0 · effective {{EFFECTIVE_DATE}}
This document describes the measures {{PROVIDER_NAME}} ("Provider") takes to protect personal data processed in the ALiSiO service. It describes measures in place at the effective date; measures that are only planned are not listed.
1. Confidentiality
Physical access. The Service runs on servers of a professional hosting provider in data centres in Germany (see the subprocessor list). Physical access control, video surveillance and on-site security are provided by the hosting provider under its certified information security management. The Provider does not operate its own server rooms.
System access.
- Users log in with an email address and a password. The Service supports an individual account for every person; the Customer is responsible for not sharing logins. Passwords are stored only as salted hashes (bcrypt).
- Repeated failed login attempts are rate-limited.
- Sessions of Customer Users expire; support sessions of Provider staff expire after at most 24 hours.
- Administrative access to servers is restricted to named persons of the Provider.
Data access.
- Separation of customers (multi-tenancy). Every record carries the organization it belongs to. In the production database (PostgreSQL) row-level security policies enforce that an organization can read and change only its own data, even if application code were to omit a filter. The application connects with a database role without superuser rights and without the right to bypass these policies.
- The separation is tested automatically before every release with two real organizations on a real database; a failed test blocks the release.
- A request for an object of another organization is answered as "not found", so the existence of foreign data cannot be probed.
- Role-based access inside an organization: seven roles and individually adjustable permissions; menus and server routes both enforce the permissions. The finance area has an additional lock that requires re-entering credentials.
- Files (for example uploaded documents) are delivered only to authenticated Users of the owning organization and are not cached publicly.
- Support access by Provider staff uses a separate account type, is limited to one organization at a time, is shown on every screen, and every login and logout is written to the audit log of that organization.
Separation of purposes. Production, test (beta) and development environments are separated. Development and automated tests use generated test data. Emails from the test environment are redirected to an internal mailbox and never reach real guests.
Pseudonymization and minimization.
- Retention periods can be set per organization; guest registration data is anonymized automatically after the retention period by a scheduled job.
- The content of emails stored in the Service is kept only for a configurable period (default 90 days).
- Images of identity documents are not stored permanently. Automatic document recognition by an external service is used only if the Customer switches it on (opt-in).
2. Integrity
Transfer. All connections to the Service are encrypted with TLS (HTTPS). Off-site backups are encrypted before they leave the server.
Stored secrets. Access credentials to third-party services that Customers connect (for example channel or payment integrations) are stored encrypted (AES-256-GCM) per organization and are never stored in the source code.
Input control and traceability.
- Changes to reservations are recorded in an audit trail with user and time.
- Financial records follow the principle "correct, never delete": an issued invoice is not changed but cancelled by a cancellation invoice; a payment is not deleted but reversed by a counter-entry.
- Actions of Provider support staff inside an organization are marked as support actions.
Change management. Every change to the software goes through version control, automated checks (types, several hundred functional tests, database schema comparison, tenant isolation, route protection) and review before it is deployed to the test environment and then to production. Production receives only versions that have run on the test environment.
3. Availability and resilience
- Daily database backups, encrypted with a public key; the private key is held offline by the Provider's management and not stored on the servers.
- An encrypted copy is stored off-site with a second provider in the European Union; stored copies expire automatically after 30 days.
- Restoration is tested with a scripted procedure that restores a copy into a separate database and verifies it.
- Monitoring alerts the Provider if a backup is missing or too old, if disk space or memory runs low, and on application errors (error monitoring in the EU region).
- Resource limits prevent one component from exhausting the server.
4. Procedures for regular testing and evaluation
- Automated tests run on every change; security-relevant findings are recorded in an internal register together with the root cause and the preventive check added.
- Personal data breaches are handled according to an internal incident procedure; Customers are notified as set out in the DPA (at the latest within 48 hours).
- These measures are reviewed at least once a year and whenever the Service changes significantly.
5. Organizational measures
- Persons with access to personal data are bound to confidentiality.
- Access rights are granted on a need-to-know basis and withdrawn when no longer needed.
- Subprocessors are selected with regard to their data protection guarantees, bound by data processing agreements and listed publicly (Annex 3).
- Personal data of Customers is not used to develop or test the software. AI tools used for development work with test data. Where Customer data has to be analysed at the Customer's request (for example to migrate data from a previous system or to resolve a support case), this is done only with services listed as subprocessors, under terms that exclude the use of the data for training.