Tecnologia e
Sicurezza

Annex 2: Technical and Organizational Measures

Annex to the Data Processing Agreement:

General technical and organizational measures pursuant to Art. 32(1) GDPR

Company: aisys media GmbH                        

Date of creation: 17.07.2026

1. Confidentiality (Art. 32(1)(b) GDPR)

1.1. Physical Access Control

The following lists all measures taken to prevent unauthorized persons from gaining physical access to the data processing facilities with which personal data is processed or used:

  • Chip cards / transponder systems
  • Doors with a knob on the outside
  • Emergency exit that can only be opened from the inside
  • Dedicated server room
  • Dedicated server cabinet
  • Key policy / key log
  • Dongle allocation policy
  • Logging/record-keeping of visitors/external persons
  • Visitors / external persons accompanied by an employee
  • External maintenance service
  • Measures in the event of loss of key / ID card / dongle / token / chip card

1.2. System Access Control

The following lists all measures taken to prevent unauthorized persons from gaining access to the data processing systems:

  • Login with username + password
  • Anti-virus software on clients
  • Anti-virus software on mobile devices
  • Firewall – server
  • External access by external service providers
  • Encryption of data media
  • Automatic desktop lock
  • Encryption of notebooks / tablets
  • Encryption when using WLAN (WPA2)
  • Creation and management of user profiles and authorizations
  • “Secure password” policy
  • “Clean desk” policy
  • „Home/Mobile Office“ policy
  • General data protection and/or security policy
  • Mobile device policy
  • “Manual desktop lock” instructions

1.3 Data Access Control

The following lists all measures taken to prevent unauthorized reading, copying, modification or deletion within the data processing systems:

  • Document shredder
  • Physical destruction of data media
  • Logging of access to applications in log files
  • Authorization concept(s)
  • Minimal number of administrators
  • Management of user rights by administrator

1.4. Separation Control

The following lists all measures taken to separate personal data collected for different purposes:

  • Separation of production and test environments
  • Physical separation (systems / databases / data media)
  • Multi-tenancy capability of relevant applications
  • Needs-based access authorizations for employees
  • Definition of database rights

1.5. Pseudonymization
(Art. 32(1)(a) & Art. 25(1) GDPR)

The pseudonymization of data records is implemented through the following measures:

No pseudonymization of the data records takes place.

 

2. Integrity (Art. 32(1)(b) GDPR)

2.1. Transfer Control

Personal data must be sufficiently protected during electronic transmission so that it cannot be read, copied, modified or removed without authorization. We have taken the following technical and organizational measures for this purpose:

  • Email encryption
  • Provision of tunnel connections (VPN)
  • Provision of encrypted connections
  • Logging of access and retrievals in log files

2.2. Input Control

To monitor whether and by whom personal data is entered into, modified, blocked or deleted from the data processing system, we use the following measures:

  • Software list of data processing programs
  • Authorization concept with the assignment of needs-based user rights

 

3. Availability and Resilience (Art. 32(1)(b) GDPR)

3.1. Availability Control

To ensure the availability of personal data against accidental or malicious destruction or loss and its rapid restoration, we use the following measures:

  • Fire and smoke detection systems
  • Fire extinguishers
  • Temperature and humidity monitoring
  • Air conditioning
  • UPS (uninterruptible power supply)
  • RAID system / hard disk mirroring
  • Regular archiving / backup of data
  • Recovery concept (formulated in detail)
  • Monitoring of the backup process
  • Storage of the backup media in a secure location outside the server room
  • No sanitary connections in or above the server room
  • Contingency plans

 

4. Procedures for Regular Review, Assessment and Evaluation
(Art. 32(1)(d) GDPR & Art. 25(1) GDPR)

Date of the last external audit for the evaluation of the technical and organizational measures by a data protection auditor (TÜV)

  • 06.2024

 

4.1. Data Protection Management

To ensure data protection within our company, we use the following measures for regular review, assessment and evaluation:

  • Central documentation of all procedures and rules on data protection, with access for employees
  • External data protection officer: SiDIT GmbH, info@sidit.de
  • Employees trained and bound to confidentiality / data secrecy
  • Regular awareness-raising for employees at least annually, and, in particular, on behaviour whilst working from home or in a mobile office
  • The data protection impact assessment (DPIA) is carried out where necessary
  • The organization complies with the information obligations under Art. 13 and 14 GDPR

 

4.2. Incident Response Management
(pursuant to Art. 33 GDPR)

In the event of the detection and reporting of data protection breaches, we use the following measures:

  • Use of a firewall and regular updating
  • Use of a spam filter and regular updating
  • Use of a virus scanner and regular updating
  • Documented process for the detection and reporting of security incidents / data breaches
  • Documented procedure for handling security incidents
  • Involvement of the DPO in security incidents and data breaches
  • Documentation of security incidents and data breaches
  • Formal process and responsibilities for the follow-up of security incidents and data breaches

 

4.3. Data Protection by Default

As part of data protection by default (Art. 25(2) GDPR), we use the following measures:

  • Data minimization and purpose limitation
  • Simple (technical) exercise of the data subject’s right of withdrawal through technical measures

 

4.4. Commissioned Processing Control / Outsourcing

As part of the outsourcing of the processing of personal data by processors, we use the following measures to ensure an adequate level of protection:

  • Prior review of the security measures taken by the processor and their documentation
  • Selection of the processor from the point of view of due diligence (particularly with regard to data protection and data security)
  • Conclusion of the necessary data processing agreement or EU standard contractual clauses
  • Written instructions to the processor
  • Obligation of the processor’s employees to data secrecy
  • Obligation of the processor to appoint a data protection officer where a duty to appoint exists
  • Agreement of effective rights of control vis-à-vis the processor
  • Provision on the engagement of further subcontractors
  • Ensuring the destruction of data after termination of the assignment
  • In the case of longer-term cooperation: ongoing review of the processor and its level of protection

 

Version: 1.0
Valid from: 17.07.2026
These Technical and Organizational Measures apply to the data processing in the context of the use of pollxpress and form part of the Data Processing Agreement. The version published at the time of conclusion of the contract shall apply in each case.

Suona bene? Prova la nostra prova gratuita!

© 2026 pollxpress | con tecnologia TEDME.com

Diventa
pollxpress è un nuovo prodotto sviluppato sulla base della collaudata piattaforma tecnologica TEDME. Le referenze presentate si riferiscono all'utilizzo di questa tecnologia in progetti dei clienti.
Utente Fondatore

Sii tra le prime organizzazioni a utilizzare pollxpress al momento del lancio nell'ottobre 2026.

Sii tra le prime organizzazioni a utilizzare pollxpress al momento del lancio nell'ottobre 2026.

Come Utente Fondatore, riceverai:
✓ Un account Pollxpress gratuito al lancio
✓ Accesso prioritario e notifiche di lancio
✓ 50 crediti di lancio (valore 50 €) per la tua prima prenotazione
✓ Accesso anticipato a funzionalità future selezionate

pollxpress aiuta le organizzazioni a gestire elezioni, votazioni e delibere in modo sicuro e semplice, online, di persona e ibrido.

Come funziona il Credito Fondatore

Dopo aver confermato il tuo indirizzo email, verranno automaticamente riservati per il tuo account 50 Crediti di Lancio (valore 50 €). Una volta che pollxpress sarà attivo, i Crediti potranno essere applicati alla tua prima prenotazione a pagamento e verranno detratti dal prezzo della prenotazione. I Crediti di Lancio rimarranno validi per 12 mesi dopo la disponibilità di pollxpress.

La pre-registrazione è completamente gratuita e non vincolante.

Iscriviti oggi stesso al programma Founding User e assicurati i tuoi vantaggi per il lancio.

Prova gratis