maesn

Data Processing Agreement (DPA)

1. General remarks

(1) This Data Processing Agreement ("DPA") forms part of and is incorporated by reference into the Terms of Service available at maesn.com/terms-of-service ("Main Agreement").

(2) The Processor will process personal data on behalf of the Controller in the meaning of Article 4 (8) and Article 28 of Regulation (EU) 2016/679. This Data Processing Agreement governs the rights and obligations of the parties in connection with the processing of personal data.

(3) Insofar as the term "data processing" or "processing" (of data) is used in this Agreement, it is taken as that defined in Article 4 (2) GDPR.

2. Subject matter of the Agreement

The subject matter, nature and purpose of the processing, the nature of personal data and the categories of data subjects are set out in Annex 1 to this Agreement.

3. Rights and duties of the Controller

(1) The Controller is the responsible body within the meaning of Article 4 (7) GDPR for the processing of data on behalf of the Controller. Pursuant to section 4 (5) of this Agreement, the Processor has the right to inform the Controller if the Processor is of the opinion that the data processing is in breach of applicable statutory data protection law in this Agreement and/or an instruction.

(2) The Controller shall be the person responsible for safeguarding the data subject's rights. The Processor shall promptly inform the Controller if data subjects claim their data subject's rights against the Processor.

(3) The Controller shall be entitled to issue supplementary instructions concerning the nature, scope and procedure of data processing to the Processor at any time. Instructions must be given in text form (e.g. email).

(4) Regulations concerning a possible remuneration of additional expenses incurred through supplementary instructions by the Controller for the Processor remain unaffected.

(5) The Controller shall promptly inform the Processor if he finds errors or irregularities in connection with the processing of personal data by the Processor.

(6) In the event of the obligation to provide information to Third Parties pursuant to Articles 33, 34 GDPR or any other statutory reporting obligation applicable to the Controller, the Controller shall be responsible for the fulfillment of those obligations.

4. General obligations of the Processor

(1) The Processor shall process personal data only within the framework of this Agreement and/or in compliance with possible additional instructions given by the Controller. Excluded from this are legal provisions, which potentially oblige the Processor to a different processing of data. In such a case, the Processor shall inform the Controller of these legal requirements before the processing, unless the law in question prohibits such notification on account of an important public interest. Purpose, nature and scope of data processing shall be governed exclusively by this Agreement and/or the instructions of the Controller. Data processing deviating from this Agreement shall be forbidden, unless the Controller has given its written consent.

(2) The Processor shall generally carry out the data processing on behalf in member states of the European Union (EU) or the European Economic Area (EEA). The Processor is also permitted to process data outside the EU or EEA if appropriate subprocessors are used in the third country in compliance with the requirements of Section 9 and the requirements of Art. 44-48 GDPR are met or an exception within the meaning of Art. 49 GDPR exists.

(3) The Processor shall inform the Controller if the Processor is of the opinion that a Controller's instruction is in breach of statutory data protection laws. The Processor shall be entitled to suspend the implementation of the relevant instruction until it has been confirmed or amended by the Controller. Insofar as the Processor can demonstrate that processing according to the instructions of the Controller can lead to liability of the Processor according to Article 82 GDPR, the Processor is free to suspend further processing in this respect until the liability between the parties has been clarified.

5. Data Protection Officer of the Processor

The Processor confirms that it has appointed a data protection officer in accordance with Art. 37 GDPR. The Processor shall ensure that the data protection officer has the necessary qualifications and expertise.

6. Notification obligations of the Processor

(1) The Processor shall inform the Controller immediately of each breach of statutory data protection laws or contractual agreements and/or the Controller's instructions which has occurred during the processing of the data by him or other persons involved in processing the data. The same shall apply to any violation of the protection of personal data which the Processor processes on behalf of the Controller.

(2) Furthermore, the Processor shall inform the Controller immediately if a data protection authority pursuant to Art. 58 GDPR is operating against the Processor and this operation may also affect controlling of the processing which the Processor makes on behalf of the Controller.

(3) The Processor is aware that the Controller may be subject to a notification obligation pursuant to Articles 33–34 GDPR, which provides that notification must be made to the supervisory authority within 72 hours after detection. The Processor shall assist the Controller in implementing the notification obligations. The Processor shall notify the Controller, in particular, of any unauthorized access to personal data processed on behalf of the Controller, without delay, but at the latest within 48 hours of knowledge of such access. In particular, the notification of the Processor to the Controller shall include the following information:

  • a description of the nature of the breach of the protection of personal data, indicating, as far as possible, the categories and approximate number of data subjects concerned, the categories concerned and the approximate number of personal data sets concerned;
  • a description of the measures taken or proposed by the Processor to remedy the breach of the protection of personal data and, where appropriate, to mitigate its potential adverse effects.

7. Processor's obligation of cooperation

(1) The Processor shall assist the Controller in fulfilling his duty to respond to requests for the exercise of rights of the data subjects in accordance with Art. 12-23 GDPR. The provisions of section 12 of this Agreement shall apply.

(2) The Processor assists the Controller in compiling the lists of processing activities. The Processor must provide the Controller with the required particulars by suitable means.

(3) Taking into account the type of processing and the information available to him, the Processor shall assist the Controller in complying with the obligations set out in Articles 32-36 GDPR.

8. Regulation on mobile workstation

(1) The Processor may allow its employees who are commissioned to process personal data for the Controller to process personal data at mobile workstations outside the Processor's business premises.

(2) The Processor shall ensure that compliance with the contractually agreed technical and organizational measures is also guaranteed when using mobile workstations of the Processor's employees. Deviations from individual contractually agreed technical and organizational measures must be agreed with the Controller in advance and approved by the Controller in text form.

(3) In particular, the Processor shall ensure that when processing personal data at mobile workstations, the storage locations are configured in such a way that local storage of data on IT systems is excluded. If this is not possible, the Processor shall ensure that local storage is exclusively encrypted and that other persons at the location of the respective mobile workstation do not have access to this data.

(4) The Processor is obliged to ensure that effective control of the processing of personal data on behalf of the Controller at mobile workstations is possible.

(5) If employees are also to be deployed at mobile workstations by subprocessors, the provisions of paragraphs 1 to 4 shall apply accordingly.

9. Supervisory powers

(1) The Controller has the right to monitor compliance with statutory laws regarding data protection and/or compliance of the regulations agreed between the Parties and/or compliance with the instructions of the Controller by the Processor at any time to the extent necessary.

(2) The Processor shall be obliged to provide the Controller with information to the extent necessary to carry out an inspection in the meaning of paragraph 1.

(3) The Controller may carry out the inspection within the meaning of paragraph 1 at the Processor's business premises during normal business hours after prior notification with reasonable notice. The Controller shall ensure that the inspections are only carried out to the extent necessary in order not to disproportionately disrupt the Processor's business operations as a result of the inspections. The parties assume that an inspection is required no more than once a year. Further inspections must be justified by the Controller, stating the reason. In the event of on-site inspections, the Controller shall reimburse the Processor for the expenses incurred, including the personnel costs for the supervision and support of the inspectors on site to an appropriate extent. The basis of the cost calculation shall be communicated to the Controller by the Processor before the inspection is carried out.

(4) At the Processor's discretion, proof of compliance with the technical and organizational measures may also be provided instead of an on-site inspection by submitting a suitable, current certificate, reports or report extracts from independent bodies (e.g. auditors, internal audit, data protection officer, IT security department, data protection auditors or quality auditors) or a suitable certification, if the audit report enables the Controller to reasonably satisfy itself of compliance with the technical and organizational measures in accordance with Annex 3 to this Agreement. If the Controller has reasonable doubts about the suitability of the test document within the meaning of sentence 1, an on-site inspection may be carried out by the Controller. The Controller is aware that an on-site inspection in data centers is not possible or only possible in justified exceptional cases.

(5) The Processor shall be obliged to provide necessary information to the Controller in case of measures of a supervisory body against the Controller according to Art. 58 GDPR, especially regarding obligations of information and monitoring and to grant the competent supervisory body on-site inspections. The Processor shall inform the Controller about such relevant intended measures.

(6) The Parties agree that the control measures for the processing of personal data at mobile workplaces to protect the personal rights of other persons at these mobile workplaces shall primarily be carried out by monitoring the measures to be taken by the Processor in accordance with Section 8 (2) and (3). The Controller must also be given the opportunity to monitor the mobile workplaces of employees by the Processor on an ad hoc basis.

10. Subprocessing

(1) The Processor shall be entitled to use the subprocessors listed at maesn.com/subprocessors for the processing of data on behalf of the Controller. The change of subprocessors or the commissioning of further subprocessors is permitted under the conditions specified in paragraph 2.

(2) The Processor shall carefully select the coprocessors and check before commissioning that the subprocessor can comply with the agreements made between the Controller and the Processor. In particular, the Processor shall check in advance and regularly during the term of the contract that the subprocessor has taken the technical and organizational measures required under Art. 32 GDPR to protect personal data. In the event of a planned change of subprocessors or the planned commissioning of a new subprocessor, the Processor shall inform the Controller in text form in good time, but no later than 2 weeks before the change or new commissioning ("Information"). The Controller shall have the right to object to the change or new assignment of the subprocessor in text form within 2 weeks of receipt of the "Information", stating the reasons. The objection may be withdrawn by the Controller in text form at any time. In the event of an objection, the Processor may terminate the contractual relationship with the Controller with a notice period of at least 14 days to the end of a calendar month. The Processor shall give reasonable consideration to the interests of the Controller in the notice period. If no objection is made by the Controller within two weeks of receipt of the "Information", this shall be deemed to constitute the Controller's consent to the change or reassignment of the subprocessor concerned.

(4) The Processor shall ensure that the provisions agreed in this contract and any supplementary instructions of the Controller also apply to the subprocessor.

(5) The Processor shall conclude a data processing agreement with the subprocessor that meets the requirements of Art. 28 GDPR. In addition, the Processor shall impose the same obligations on the subprocessor to protect personal data as are stipulated between the Controller and the Processor. The Controller shall be provided with a copy of the data processing agreement upon request.

(6) In particular, the Processor shall be obliged to ensure by means of contractual provisions that the supervisory powers (Section 9 of this contract) of the Controller and supervisory authorities also apply to the subprocessor and that corresponding supervisory rights of the Controller and supervisory authorities are agreed. It must also be contractually stipulated that the subprocessor must tolerate these control measures and any on-site inspections.

(7) Services which the Processor uses from third parties as a purely ancillary service in order to carry out the business activity are not to be regarded as subprocessing relationships within the meaning of paragraphs 1 to 6. These include, for example, cleaning services, pure telecommunication services with no specific connection to services that the Processor provides for the Controller, postal and courier services, transportation services, security services. The Processor is nevertheless obliged to ensure that appropriate precautions and technical and organizational measures have been taken to ensure the protection of personal data, even in the case of ancillary services provided by third parties. The maintenance and servicing of IT systems or applications constitutes a subprocessing relationship requiring consent and processing within the meaning of Art. 28 GDPR if the maintenance and testing concerns IT systems that are also used in connection with the provision of services for the Controller and personal data processed on behalf of the Controller can be accessed during maintenance.

11. Obligation of confidentiality

(1) When processing data on behalf of the Controller, the Processor shall be obliged to maintain confidentiality of data which he receives or obtains in connection with the data processing agreement.

(2) The Processor also warrants that the employees working on the data have been made known to applicable regulations of data protection and that they are bound to maintain data confidentiality.

(3) Proof for such an obligation for the employees pursuant to paragraph 2 must be presented to the Controller on request.

12. Protection of Data Subjects' rights

(1) The Controller is solely responsible for safeguarding data subjects' rights. The Processor is obliged to support the Controller in his duty to process requests from data subjects in accordance with Articles 12-23 GDPR. The Processor shall in particular ensure that the information required in this respect is provided to the Controller without delay so that the Controller is able to fulfil his obligations under section 12 (3) GDPR in particular.

(2) As far as a participation of the Processor for the protection of data subjects' rights by the Controller is necessary – especially regarding access, rectification, blocking or deleting –, the Processor will undertake the necessary measures on instruction by the Controller. Where possible, the Processor shall assist the Controller with appropriate technical and organizational measures to fulfil his obligation to respond to requests for the exercise of the data subjects' rights.

(3) Provisions concerning remuneration of additional expenses incurred through participation of the Processor in connection with assertion of data subjects' rights against the Controller remain unaffected.

13. Confidentiality obligations

(1) Both Parties hereby undertake to treat all information received in connection with the processing of this Agreement indefinitely confidential and to use the information only for carrying out the Agreement. No Party has the right to use the information in part or as a whole for other than those mentioned purposes or to make this information available to Third Parties.

(2) The foregoing obligation shall not apply for information that one Party received demonstrably from Third Parties, without being bound by secrecy or which are publicly known.

14. Remuneration

The Processor's remuneration is provided for by way of a separate agreement.

15. Technical and organizational measures for data security

(1) The Processor shall pledge against the Controller to comply with all technical and organizational measures that are required for compliance with applicable data protection regulations. This includes, in particular the dispositions in Art. 32 GDPR.

(2) The technical and organizational measures as of the time at which this Agreement is made are attached as Annex 3 to this contract. The Parties agree that changes to technical and organizational measures may be required to adapt to technical and legal requirements. The Processor will inform the Controller in advance and within a reasonable period of any material changes affecting the integrity, confidentiality or availability of personal data. The Processor may implement without consulting with the Controller measures that entail only slight technical or organizational changes and that do not negatively affect the integrity, confidentiality or availability of the personal data. The Controller may at any time request an up-to-date version of the technical and organizational measures taken by the Processor.

16. Term of the Agreement

(1) The Agreement begins with the ordering of the Processor's services and runs for the duration of the main contract existing between the Contracting Parties.

(2) The Controller may terminate the Agreement at any time without notice if the Processor has committed a serious violation of the applicable data protection provisions or a breach of duties under this Agreement; the Processor is unable or unwilling to carry out an instruction of the Controller or denies access to the Controller or the competent supervisory authority in breach of the Agreement.

17. Termination

(1) After the Agreement has ended, the Processor shall, at the Controller's discretion, return to the Controller all documents and data in its possession that relate to the contractual relationship, or shall delete them. The deletion shall be documented in a suitable manner.

(2) The Processor may store personal data that has been processed in connection with the processing relationship beyond the termination of the Agreement if and to the extent that the Processor has a legal obligation to store it. In these cases, the data may only be processed for the purpose of implementing the respective legal storage obligations. After the storage obligation has expired, the data must be deleted immediately.

18. Final Provisions

(1) Should the property of the Controller be at risk at the Processor through measures of Third Parties (especially confiscation or seizure of property), by insolvency proceedings or other events, the Processor must inform the Controller immediately. The Processor will inform creditors immediately about the fact that the data are processed on behalf of the Controller.

(2) Written form is compulsory for ancillary agreements.

(3) Should individual parts of this Agreement be invalid, the validity of the Agreement's other provisions will not be affected thereby.

  • * *

Annex 1 – Subject matter of the Agreement

Subject matter and purpose of processing

The subject matter and purpose of the processing is the provision and operation of the Processor's unified API platform, which serves as technical middleware between the Controller's software application and the ERP and accounting systems of the Controller's end customers. The processing comprises the receipt, normalisation and routing of API requests, authentication and token management, webhook and synchronisation services, as well as real-time passthrough of API calls.

The purpose is to enable automated, standardised data integration between the aforementioned systems, in particular the synchronisation of financial and transactional data.

Type(s) of personal data

The following types of data are subject to this contract:

  • Account data (username, email address)
  • Technical data (logs, API calls, timestamps)
  • Financial and transactional data routed through the API in real time without storage (e.g. contact data, invoice data, payment information as contained in the connected ERP and accounting systems)
  • Support and service data (support tickets, correspondence, details for problem resolution)

Special categories of personal data within the meaning of Art. 9 GDPR are not intended to be processed. To the extent such data is transmitted by the controller or its end customers via the API, the controller is solely responsible for ensuring a valid legal basis.

Categories of data subjects

Data subjects whose personal data is contained in the financial and transactional data transmitted via the API, such as customers, suppliers, contact persons and employees of the Controller's end customers, as well as the controller's own authorised users of the platform.

  • * *

Annex 2 – Subprocessors

For the processing of data on behalf of the Controller, the Processor uses the services of third parties who process data on behalf of the Processor ("subprocessors"). The current list of subprocessors is maintained and regularly updated at: maesn.com/subprocessors.

  • * *

Annex 3 – Technical and organizational measures of the Processor

The Processor shall undertake the following technical and organizational measures for data security in accordance with Art. 32 GDPR.

Access Control (Physical)

Measures to prevent unauthorized persons from gaining physical access to data processing facilities

Data center (Microsoft Azure):

All data is stored and processed exclusively in Microsoft Azure data centers in Frankfurt (Germany) and Amsterdam (the Netherlands). Physical security of these facilities is managed entirely by Microsoft, including perimeter fencing, security personnel, CCTV surveillance, and access control systems. Microsoft is ISO 27001 and SOC 2 certified and contractually bound via a Data Processing Agreement (DPA) and Standard Contractual Clauses (SCCs).

Office premises (startup hub):

The organization does not own or lease dedicated office space. Employees work from a shared startup hub, where physical security is the responsibility of the hub operator.

  • Building access is controlled by keycard systems, managed through a formal onboarding/offboarding process with structured checklists at each stage.
  • A reception desk with a designated employee is stationed at the building entrance.
  • Video surveillance monitors the building and its entry points.
  • An alarm system is in place that automatically alerts a professional security company in the event of an intrusion.
  • Visitors cannot enter the building without being actively admitted by a member of staff; unaccompanied or unannounced access is not possible.

Workplace measures:

  • No data is stored locally on office hardware; organizational data resides exclusively in company-approved cloud services.
  • A clean desk policy is enforced at all times.
  • Automatic screen lock is configured after 5 minutes of inactivity; employees must additionally lock screens manually when stepping away.
  • Employees are required to secure company-owned devices when unattended and report lost, stolen, or compromised equipment immediately.

Access Control (Logical)

Measures to prevent unauthorized use of data processing systems

Authentication:

  • Multi-factor authentication (MFA) is mandatory for all access to company systems and applications.
  • The organization relies on MFA combined with Azure's native breach and anomaly detection rather than traditional password rotation policies.
  • Anonymous, default, and shared accounts are explicitly prohibited.
  • All access attempts and anomalous activity — including access from unfamiliar locations, multiple failed login attempts, and unusual hours — are monitored and reported to the Information Security Officer (ISO).

Device security:

  • All employees are provided with company-managed laptops as their primary work device.
  • Full disk encryption is enforced on all devices (BitLocker on Windows, FileVault on Mac).
  • Windows devices are protected by Microsoft Defender; Mac devices by Apple's XProtect and Gatekeeper.
  • Personal devices are not permitted for accessing production systems, development work, or confidential data.

Network security:

  • Access to company systems requires encrypted connections (HTTPS/SSH) at all times.
  • Remote employees must use WPA2/WPA3-secured WiFi networks.
  • Access to production environments over public WiFi is explicitly prohibited.
  • Security is enforced at the identity and application layer through Azure's built-in capabilities; no VPN is deployed.

Removable media:

  • The use of removable storage media is actively discouraged and minimized.
  • Where removable media must exceptionally be used, AES-256 encryption or equivalent is required.
  • All removable media must be sanitized prior to disposal or release, with sanitization activities documented.
  • USB ports are not technically blocked but usage is governed by the Removable Storage Media Policy.

Authorization Control

Measures to ensure that persons authorized to use a data processing system can only access the data within the scope of their authorization

Authorization concept:

  • Access rights are granted exclusively based on the principle of least privilege and role-based access control (RBAC), implemented through Microsoft Azure.
  • Access is provisioned only after formal approval by the Information Security Officer (ISO) and upon completion of onboarding.

Account lifecycle:

  • Accounts are created upon authorized request, modified when roles change, and disabled without undue delay upon termination or role change.
  • Account managers are notified within 24 hours of any relevant change in employment status.
  • Shared or group accounts are prohibited except in testing environments or emergency situations.

Review and monitoring:

  • Access rights are reviewed quarterly and additionally upon significant changes such as role changes or termination.
  • Administrator access is limited to the CTO, with one secured backup administrator account.
  • All access activity is logged through Azure's native audit logging capabilities.
  • Anomalous access patterns are monitored and flagged through Microsoft Cloud Defender.

Transfer Control

Measures to ensure that personal data cannot be read, copied, altered, or removed without authorization during electronic transfer or transport

Encryption in transit:

  • All data in transit is encrypted using HTTPS/TLS.
  • No plaintext communication is permitted anywhere in the infrastructure.
  • Internal API communication is likewise encrypted.

Data handling architecture:

  • The organization operates a no-storage architecture: personal data of the Controller and its end users is processed in memory only and delivered directly to the Controller's system.
  • No shadow copies, caches, or secondary databases are maintained.

Third-party transfers:

  • Data transfers to third parties occur only on a contractual basis (DPA) and are documented.
  • The only third-party provider with access to personal data is Microsoft.
  • All infrastructure is hosted exclusively within the EU.

Input Control

Measures to ensure that it is possible to retrospectively verify and establish whether and by whom personal data have been entered into, modified, or removed from data processing systems

  • All access to systems and data is logged through Microsoft Azure's native audit logging capabilities.
  • Logs capture the granting, modification, and revocation of access rights as well as access activity across systems.
  • Automated alerting for anomalous data access patterns is implemented through Microsoft Cloud Defender.
  • Logs are accessible to the CTO and authorized administrators.

Commissioned Processing Control

Measures to ensure that personal data processed on behalf of the Controller is processed solely in accordance with the Controller's instructions

Sub-processors:

  • A Data Processing Agreement and applicable Standard Contractual Clauses are in place with Microsoft as the sole sub-processor.
  • Prior to onboarding, Microsoft's compliance with ISO 27001, SOC 2, and GDPR was verified.
  • The same verification process applies to any future sub-processors.

Employee obligations:

  • All employees are contractually bound to confidentiality.
  • Data protection training is provided during onboarding and on an ongoing basis through the Kertos platform.

Internal governance:

  • A comprehensive suite of internal policies governs data handling, including the Information Handling Policy, Access Control Policy, Remote Work Policy, and Removable Storage Media Policy.

Availability Control

Measures to ensure that personal data is protected against accidental destruction or loss

Infrastructure:

  • All data is hosted in Microsoft Azure data centers, which provide redundant infrastructure, automated backups, and high availability by design.
  • The organization relies on Azure's native availability and disaster recovery capabilities.

Monitoring and incident response:

  • System availability is monitored through Azure Monitor.
  • A formal Security Incident Management Policy establishes structured processes for detecting, reporting, and responding to security incidents, including defined escalation paths.

Device-level measures:

  • All company devices must maintain up-to-date security patches.
  • Full disk encryption protects against data loss in case of device theft or loss.
  • Lost, stolen, or compromised equipment must be reported immediately.

Separation Control

Measures to ensure that data collected for different purposes is processed separately

Logical separation:

  • Separation of data is enforced through RBAC and the principle of least privilege within the Azure environment.
  • Customer data is logically separated through Azure's native access controls, security groups, and IAM policies.
  • All access is traceable to individually identified and authenticated users; shared accounts are prohibited.

Environment separation:

  • Development, test, and production environments are logically separated within Azure using resource groups, security groups, and private networks.
  • Production data must not be used in development or test environments; exclusively synthetic test data is used.
  • All production deployments follow a controlled change management process and are executed through automated CI/CD pipelines.

Pseudonymization and Encryption

Measures pursuant to Art. 32(1)(a) GDPR

Pseudonymization:

  • The organization operates a no-storage architecture: personal data of the Controller and its end users is never persistently stored.
  • Within the application, tenants and end users are represented exclusively by internal identifiers rather than directly identifying personal data.
  • Data masking is applied to remove specific PII elements (names, email addresses, IP addresses, dates of birth, biometric records) when data is no longer necessary or before sharing externally.

Encryption at rest:

  • All company laptops are protected by full disk encryption (BitLocker/FileVault).
  • All data stored within the Microsoft Azure infrastructure is encrypted at rest using AES-256, stored exclusively within the EU.
  • Removable media, where exceptionally used, must be encrypted with AES-256 or equivalent.

Encryption in transit:

  • All data in transit is encrypted using HTTPS/TLS 1.2 or higher.
  • No plaintext communication is permitted.

Resilience of Systems

Measures to ensure resilience of processing systems and services pursuant to Art. 32(1)(b) GDPR

  • The organization's infrastructure is hosted on Microsoft Azure, which provides scalable cloud infrastructure with built-in redundancy and resilience capabilities.
  • System availability and performance are monitored through Azure Monitor with automatic notifications in the event of disruptions.
  • Protection against attacks at the infrastructure level is provided by Azure's native security capabilities, supplemented by Microsoft Cloud Defender for threat detection and alerting.

Recoverability

Measures for rapid restoration of availability and access to personal data following a physical or technical incident pursuant to Art. 32(1)(c) GDPR

Incident management:

  • A formal Security Incident Management Policy defines a structured process for detecting, escalating, and responding to incidents.
  • Employees can report incidents through the Kertos platform, email, or Slack; anonymous reporting is available.
  • Internal escalation paths and responsibilities are clearly defined.

Breach notification:

  • In the event of a personal data breach affecting Controller data, the Controller is notified promptly with full details of the breach, affected data, estimated scope, potential consequences, and remediation measures.
  • Where the organization acts as controller, the supervisory authority is notified within 72 hours.
  • All breaches are documented in the Data Breach Register.

Data recovery:

  • Recovery of infrastructure and data relies on Microsoft Azure's native backup and disaster recovery capabilities.

Procedures for Regular Review, Assessment, and Evaluation

Measures pursuant to Art. 32(1)(d) GDPR

Governance:

  • Company management has formally assumed responsibility for information security through the Information Security Policy.
  • An Information Security Officer (ISO) is appointed with defined authority and responsibilities.
  • The organization maintains an ISO 27001-certified Information Security Management System (ISMS).

Audits and reviews:

  • Internal audits are conducted regularly to assess compliance with all information security policies.
  • External audits are performed as part of the ISO 27001 certification cycle.
  • Technical and organizational measures are reviewed and updated at least annually or upon significant changes.

Training and awareness:

  • All employees receive data protection and information security training during onboarding.
  • Ongoing training and policy updates are delivered through the Kertos platform.
  • Compliance is monitored through management reviews, internal and external audits, and ongoing feedback mechanisms.

Sub-processor oversight:

  • Sub-processors are regularly reviewed for continued compliance with data protection requirements.
  • Vendor security documentation and compliance reports are evaluated as part of the ongoing oversight process.