Annex 2: Technical and Organizational Measures
Annex to the Data Processing Agreement:
General technical and organizational measures pursuant to Art. 32(1) GDPR
Company: aisys media GmbH
Date of creation: 17.07.2026
1. Confidentiality (Art. 32(1)(b) GDPR)
1.1. Physical Access Control
The following lists all measures taken to prevent unauthorized persons from gaining physical access to the data processing facilities with which personal data is processed or used:
- Chip cards / transponder systems
- Doors with a knob on the outside
- Emergency exit that can only be opened from the inside
- Dedicated server room
- Dedicated server cabinet
- Key policy / key log
- Dongle allocation policy
- Logging/record-keeping of visitors/external persons
- Visitors / external persons accompanied by an employee
- External maintenance service
- Measures in the event of loss of key / ID card / dongle / token / chip card
1.2. System Access Control
The following lists all measures taken to prevent unauthorized persons from gaining access to the data processing systems:
- Login with username + password
- Anti-virus software on clients
- Anti-virus software on mobile devices
- Firewall – server
- External access by external service providers
- Encryption of data media
- Automatic desktop lock
- Encryption of notebooks / tablets
- Encryption when using WLAN (WPA2)
- Creation and management of user profiles and authorizations
- “Secure password” policy
- “Clean desk” policy
- „Home/Mobile Office“ policy
- General data protection and/or security policy
- Mobile device policy
- “Manual desktop lock” instructions
1.3 Data Access Control
The following lists all measures taken to prevent unauthorized reading, copying, modification or deletion within the data processing systems:
- Document shredder
- Physical destruction of data media
- Logging of access to applications in log files
- Authorization concept(s)
- Minimal number of administrators
- Management of user rights by administrator
1.4. Separation Control
The following lists all measures taken to separate personal data collected for different purposes:
- Separation of production and test environments
- Physical separation (systems / databases / data media)
- Multi-tenancy capability of relevant applications
- Needs-based access authorizations for employees
- Definition of database rights
1.5. Pseudonymization
(Art. 32(1)(a) & Art. 25(1) GDPR)
The pseudonymization of data records is implemented through the following measures:
No pseudonymization of the data records takes place.
2. Integrity (Art. 32(1)(b) GDPR)
2.1. Transfer Control
Personal data must be sufficiently protected during electronic transmission so that it cannot be read, copied, modified or removed without authorization. We have taken the following technical and organizational measures for this purpose:
- Email encryption
- Provision of tunnel connections (VPN)
- Provision of encrypted connections
- Logging of access and retrievals in log files
2.2. Input Control
To monitor whether and by whom personal data is entered into, modified, blocked or deleted from the data processing system, we use the following measures:
- Software list of data processing programs
- Authorization concept with the assignment of needs-based user rights
3. Availability and Resilience (Art. 32(1)(b) GDPR)
3.1. Availability Control
To ensure the availability of personal data against accidental or malicious destruction or loss and its rapid restoration, we use the following measures:
- Fire and smoke detection systems
- Fire extinguishers
- Temperature and humidity monitoring
- Air conditioning
- UPS (uninterruptible power supply)
- RAID system / hard disk mirroring
- Regular archiving / backup of data
- Recovery concept (formulated in detail)
- Monitoring of the backup process
- Storage of the backup media in a secure location outside the server room
- No sanitary connections in or above the server room
- Contingency plans
4. Procedures for Regular Review, Assessment and Evaluation
(Art. 32(1)(d) GDPR & Art. 25(1) GDPR)
Date of the last external audit for the evaluation of the technical and organizational measures by a data protection auditor (TÜV)
- 06.2024
4.1. Data Protection Management
To ensure data protection within our company, we use the following measures for regular review, assessment and evaluation:
- Central documentation of all procedures and rules on data protection, with access for employees
- External data protection officer: SiDIT GmbH, info@sidit.de
- Employees trained and bound to confidentiality / data secrecy
- Regular awareness-raising for employees at least annually, and, in particular, on behaviour whilst working from home or in a mobile office
- The data protection impact assessment (DPIA) is carried out where necessary
- The organization complies with the information obligations under Art. 13 and 14 GDPR
4.2. Incident Response Management
(pursuant to Art. 33 GDPR)
In the event of the detection and reporting of data protection breaches, we use the following measures:
- Use of a firewall and regular updating
- Use of a spam filter and regular updating
- Use of a virus scanner and regular updating
- Documented process for the detection and reporting of security incidents / data breaches
- Documented procedure for handling security incidents
- Involvement of the DPO in security incidents and data breaches
- Documentation of security incidents and data breaches
- Formal process and responsibilities for the follow-up of security incidents and data breaches
4.3. Data Protection by Default
As part of data protection by default (Art. 25(2) GDPR), we use the following measures:
- Data minimization and purpose limitation
- Simple (technical) exercise of the data subject’s right of withdrawal through technical measures
4.4. Commissioned Processing Control / Outsourcing
As part of the outsourcing of the processing of personal data by processors, we use the following measures to ensure an adequate level of protection:
- Prior review of the security measures taken by the processor and their documentation
- Selection of the processor from the point of view of due diligence (particularly with regard to data protection and data security)
- Conclusion of the necessary data processing agreement or EU standard contractual clauses
- Written instructions to the processor
- Obligation of the processor’s employees to data secrecy
- Obligation of the processor to appoint a data protection officer where a duty to appoint exists
- Agreement of effective rights of control vis-à-vis the processor
- Provision on the engagement of further subcontractors
- Ensuring the destruction of data after termination of the assignment
- In the case of longer-term cooperation: ongoing review of the processor and its level of protection
Version: 1.0
Valid from: 17.07.2026
These Technical and Organizational Measures apply to the data processing in the context of the use of pollxpress and form part of the Data Processing Agreement. The version published at the time of conclusion of the contract shall apply in each case.