Technical and organisational measures
Annex 2 to the Data Processing Agreement
Source: https://www.responsly.com/terms-and-policies/data-processing-addendum/security-measures/
Contents
This annex to the Data Processing Agreement describes the technical and organisational measures the Provider applies under Article 32 GDPR to protect personal data that Customers entrust to it. The Provider may change these measures, provided that the change does not reduce the overall level of protection of personal data (Section 4.1 of the Data Processing Agreement).
1. Security organisation
- The Provider maintains information security policies covering access control, information classification, change management, cryptography and key management, network security, secure software development, use of cloud services, incident response and business continuity. The policies are reviewed periodically and made available on request once a non-disclosure agreement has been concluded.
- Persons with access to Personal Data are authorised, bound by confidentiality and trained in data protection principles.
- The Provider has designated a data protection contact: gdpr@responsly.com.
2. Access control
- Access granted on the principle of least privilege and according to role-based needs.
- Individual accounts for each person; multi-factor authentication for key systems and cloud resources.
- Periodic review of permissions; access removed no later than 1 working day after the end of cooperation or a change of role.
- Logging of login attempts and administrative actions.
- In the Service: User roles and permissions, two-factor authentication, and single sign-on (SSO/SAML) on the Enterprise Plan.
3. Encryption and data protection
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest using AES-256, including backups.
- Restricted and logged access to cryptographic keys.
- Logical separation of each customer’s data.
4. Infrastructure and business continuity
- Service data hosted in data centres in the European Union (Amazon Web Services, DigitalOcean). Physical security of the data centres is ensured by those providers under their agreements with the Provider.
- Regular backups, encrypted and rotated in accordance with Section 7 of the Data Processing Agreement.
- Review of backups and business continuity plans, and a data restoration test, at least once a year.
- Monitoring of the availability and operation of the Service.
- Protection against network attacks, including DDoS, at the content delivery network level.
5. Development and changes
- Code changes made through review by a second person and protected repository branches; emergency changes are reviewed after deployment.
- Controlled deployments and dependency updates.
- Periodic security testing, including vulnerability scanning.
6. Incidents
- An incident response procedure covering detection, assessment, containment, eradication and lessons learned.
- Notification of personal data breaches to the Customer in accordance with Section 4.5 of the Data Processing Agreement.
7. Subprocessors
- Subprocessors selected taking into account their security guarantees; a data processing agreement with each subprocessor that processes Personal Data.
