Technologie &
Sécurité

Annex 2: Technical and Organizational Measures

Annex to the Data Processing Agreement:

General technical and organizational measures pursuant to Art. 32(1) GDPR

Company: aisys media GmbH                        

Date of creation: 17.07.2026

1. Confidentiality (Art. 32(1)(b) GDPR)

1.1. Physical Access Control

The following lists all measures taken to prevent unauthorized persons from gaining physical access to the data processing facilities with which personal data is processed or used:

  • Chip cards / transponder systems
  • Doors with a knob on the outside
  • Emergency exit that can only be opened from the inside
  • Dedicated server room
  • Dedicated server cabinet
  • Key policy / key log
  • Dongle allocation policy
  • Logging/record-keeping of visitors/external persons
  • Visitors / external persons accompanied by an employee
  • External maintenance service
  • Measures in the event of loss of key / ID card / dongle / token / chip card

1.2. System Access Control

The following lists all measures taken to prevent unauthorized persons from gaining access to the data processing systems:

  • Login with username + password
  • Anti-virus software on clients
  • Anti-virus software on mobile devices
  • Firewall – server
  • External access by external service providers
  • Encryption of data media
  • Automatic desktop lock
  • Encryption of notebooks / tablets
  • Encryption when using WLAN (WPA2)
  • Creation and management of user profiles and authorizations
  • “Secure password” policy
  • “Clean desk” policy
  • „Home/Mobile Office“ policy
  • General data protection and/or security policy
  • Mobile device policy
  • “Manual desktop lock” instructions

1.3 Data Access Control

The following lists all measures taken to prevent unauthorized reading, copying, modification or deletion within the data processing systems:

  • Document shredder
  • Physical destruction of data media
  • Logging of access to applications in log files
  • Authorization concept(s)
  • Minimal number of administrators
  • Management of user rights by administrator

1.4. Separation Control

The following lists all measures taken to separate personal data collected for different purposes:

  • Separation of production and test environments
  • Physical separation (systems / databases / data media)
  • Multi-tenancy capability of relevant applications
  • Needs-based access authorizations for employees
  • Definition of database rights

1.5. Pseudonymization
(Art. 32(1)(a) & Art. 25(1) GDPR)

The pseudonymization of data records is implemented through the following measures:

No pseudonymization of the data records takes place.

 

2. Integrity (Art. 32(1)(b) GDPR)

2.1. Transfer Control

Personal data must be sufficiently protected during electronic transmission so that it cannot be read, copied, modified or removed without authorization. We have taken the following technical and organizational measures for this purpose:

  • Email encryption
  • Provision of tunnel connections (VPN)
  • Provision of encrypted connections
  • Logging of access and retrievals in log files

2.2. Input Control

To monitor whether and by whom personal data is entered into, modified, blocked or deleted from the data processing system, we use the following measures:

  • Software list of data processing programs
  • Authorization concept with the assignment of needs-based user rights

 

3. Availability and Resilience (Art. 32(1)(b) GDPR)

3.1. Availability Control

To ensure the availability of personal data against accidental or malicious destruction or loss and its rapid restoration, we use the following measures:

  • Fire and smoke detection systems
  • Fire extinguishers
  • Temperature and humidity monitoring
  • Air conditioning
  • UPS (uninterruptible power supply)
  • RAID system / hard disk mirroring
  • Regular archiving / backup of data
  • Recovery concept (formulated in detail)
  • Monitoring of the backup process
  • Storage of the backup media in a secure location outside the server room
  • No sanitary connections in or above the server room
  • Contingency plans

 

4. Procedures for Regular Review, Assessment and Evaluation
(Art. 32(1)(d) GDPR & Art. 25(1) GDPR)

Date of the last external audit for the evaluation of the technical and organizational measures by a data protection auditor (TÜV)

  • 06.2024

 

4.1. Data Protection Management

To ensure data protection within our company, we use the following measures for regular review, assessment and evaluation:

  • Central documentation of all procedures and rules on data protection, with access for employees
  • External data protection officer: SiDIT GmbH, info@sidit.de
  • Employees trained and bound to confidentiality / data secrecy
  • Regular awareness-raising for employees at least annually, and, in particular, on behaviour whilst working from home or in a mobile office
  • The data protection impact assessment (DPIA) is carried out where necessary
  • The organization complies with the information obligations under Art. 13 and 14 GDPR

 

4.2. Incident Response Management
(pursuant to Art. 33 GDPR)

In the event of the detection and reporting of data protection breaches, we use the following measures:

  • Use of a firewall and regular updating
  • Use of a spam filter and regular updating
  • Use of a virus scanner and regular updating
  • Documented process for the detection and reporting of security incidents / data breaches
  • Documented procedure for handling security incidents
  • Involvement of the DPO in security incidents and data breaches
  • Documentation of security incidents and data breaches
  • Formal process and responsibilities for the follow-up of security incidents and data breaches

 

4.3. Data Protection by Default

As part of data protection by default (Art. 25(2) GDPR), we use the following measures:

  • Data minimization and purpose limitation
  • Simple (technical) exercise of the data subject’s right of withdrawal through technical measures

 

4.4. Commissioned Processing Control / Outsourcing

As part of the outsourcing of the processing of personal data by processors, we use the following measures to ensure an adequate level of protection:

  • Prior review of the security measures taken by the processor and their documentation
  • Selection of the processor from the point of view of due diligence (particularly with regard to data protection and data security)
  • Conclusion of the necessary data processing agreement or EU standard contractual clauses
  • Written instructions to the processor
  • Obligation of the processor’s employees to data secrecy
  • Obligation of the processor to appoint a data protection officer where a duty to appoint exists
  • Agreement of effective rights of control vis-à-vis the processor
  • Provision on the engagement of further subcontractors
  • Ensuring the destruction of data after termination of the assignment
  • In the case of longer-term cooperation: ongoing review of the processor and its level of protection

 

Version: 1.0
Valid from: 17.07.2026
These Technical and Organizational Measures apply to the data processing in the context of the use of pollxpress and form part of the Data Processing Agreement. The version published at the time of conclusion of the contract shall apply in each case.

Ça vous dit ? Essayez notre essai gratuit !

© 2026 pollxpress | propulsé par TEDME.com

Deviens un
pollxpress est un nouveau produit développé sur la base de la technologie éprouvée de la plateforme logicielle TEDME. Les références présentées concernent l'utilisation de cette technologie dans des projets clients.
Utilisateur fondateur

Soyez parmi les premières organisations à utiliser PollXpress lors de notre lancement en octobre 2026.

Soyez parmi les premières organisations à utiliser PollXpress lors de notre lancement en octobre 2026.

En tant qu'utilisateur fondateur, vous recevrez :
✓ Un compte pollxpress gratuit au lancement
✓ Accès prioritaire et notifications de lancement
✓ 50 crédits de lancement (valeur de 50 €) pour votre première réservation
✓ Accès anticipé à certaines fonctionnalités à venir

pollxpress aide les organisations à organiser facilement des élections, des votes et des résolutions sécurisés – en ligne, en personne et hybrides.

Comment fonctionne le crédit des utilisateurs fondateurs

Après confirmation de votre adresse e-mail, 50 crédits de lancement (valeur de 50 €) seront automatiquement réservés sur votre compte. Dès le lancement de pollxpress, les crédits pourront être appliqués à votre première réservation payante et seront déduits du prix de la réservation. Les crédits de lancement restent valables pendant 12 mois après la mise à disposition de pollxpress.

La pré-inscription est entièrement gratuite et sans engagement.

Rejoignez le programme des premiers utilisateurs dès aujourd'hui et sécurisez vos avantages de lancement.

Essai gratuit