Translation. This is a translation provided for convenience. In case of any conflict between language versions, the Swedish version prevails. Swedish version →
Annex C, Appendix 3 — Technical and Organisational Security Measures (TOMs)
Technical and organisational measures that protect data.
Introduction
Appendix to the Data Processing Agreement Human Syntax AB
This Appendix specifies the technical and organisational measures taken by the Supplier in accordance with Article 32 GDPR and §7 of the Data Processing Agreement (Annex C).
1Access control
- Login to the Service is via email with one-time code (OTP) or via federated login (Single Sign-On) with Google, Microsoft or Apple (Apple available in beta). Additional identity providers may be added.
- Passwords are not stored by the Supplier with SSO-based login.
- Access to the Service’s administrative functions and underlying databases is limited to persons at the Supplier who need access for operations, development or support.
2Encryption
- All communication over the network takes place over TLS — both between client and the Service and between the Service and Subprocessors.
3Backup and recovery
- Backup of the Service’s databases and accounts is taken daily.
- Backups are stored on physically separated backup servers in a different server hall than the production servers.
- Daily backups are retained for 30 days, and monthly backups for an additional 60 days — a total recovery window of three months.
4Incident management
- Upon detection of a Personal Data Breach, assessment, documentation and communication take place in accordance with §10 of the Data Processing Agreement.
- Notification to the Customer takes place without undue delay, however no later than 48 hours after the incident became known to the Supplier.
- Where needed, immediate measures are taken to limit the damage, including isolation of affected data, change of access credentials and coordination with Subprocessors.
5Personnel security
- Persons at the Supplier with access are bound by confidentiality undertakings, either through employment contract or separate confidentiality agreement.
6Development and test environment
- Development and test environments are separated from the production environment and do not contain production data.
- Production data is not copied to development or test environments without prior anonymisation or pseudonymisation.
- Where test data is needed, synthetic or anonymised datasets are generated.
- Any AI-based development tools used by the Supplier do not have access to Personal Data in the production environment.
- The Supplier’s development computers have full disk encryption and require authentication at startup.
7Physical security
- The Service’s servers are operated by Oderland AB in a data centre in Sweden. Oderland applies physical security according to industry practice (access control, surveillance, redundant power supply, fire and water protection) and publishes information about their measures at oderland.se.
8Vendor management
- Subprocessors are listed in Appendix 2 to the Data Processing Agreement.
- For changes in service delivery or security posture of Subprocessors, the Supplier takes reasonable measures to assess the impact on the Processing and informs the Customer of relevant changes in accordance with §8 of the Data Processing Agreement (Annex C).