Technical and organisational measures under Art. 32 GDPR (TOM)
As of: 28.04.2026
This English text is a convenience translation. The legally binding version is the German TOM; in case of discrepancies, the German version prevails.
1. General security organisation
Systempilot takes appropriate technical and organisational measures to protect personal data. The measures are based on the nature, scope, circumstances and purposes of the processing as well as the risk to the rights and freedoms of the data subjects.
The measures are reviewed regularly and adjusted as needed. Systempilot is entitled to replace individual measures with equivalent or superior measures, provided the agreed level of protection is not thereby reduced.
2. Physical access control
The goal is to prevent unauthorised physical access to systems, premises and infrastructure where personal data is processed.
Systempilot processes personal data predominantly via cloud-based systems and data centres of the service providers used. Physical access to data centres is secured by the respective hosting and cloud providers.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Data centre operation by professional providers | Hosting and infrastructure are provided via specialised providers with their own access and security concepts. |
| No public access to production systems | Production systems are not publicly physically accessible. |
| Device protection | Work devices are protected against unauthorised access. |
| Home office / remote work | Work is carried out in principle via individual user accounts and secured end devices. |
3. System access control
The goal is to prevent unauthorised access to IT systems.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Personal user accounts | Access to systems is via individual user accounts. |
| Password protection | Systems are protected by passwords or comparable authentication mechanisms. |
| Two-factor authentication | Where available and appropriate, two-factor authentication is used, in particular for central cloud, hosting, communication and administration systems. |
| Role and permission concept | Access rights are granted according to area of responsibility and necessity. |
| Need-to-know principle | Only persons who need it for the provision of services receive access to customer data. |
| Blocking of no-longer-needed access | User accounts that are no longer needed are deactivated or deleted. |
4. Data access control
The goal is to ensure that authorised users can only access those personal data they need to fulfil their tasks.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Authorisation concepts | Access is granted per project and system. |
| Tenant and project separation | Customer data is processed separately organisationally and, where technically provided, on the system side. |
| Restriction of administrative rights | Administrative rights are granted only to authorised persons. |
| Regular review of authorisations | Authorisations are reviewed on occasion and at appropriate intervals. |
| Logging | Where available on the system side, relevant access, changes or administrative activities are logged. |
5. Transfer control
The goal is to prevent personal data from being read, copied, altered or removed without authorisation during transmission, storage or transfer.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Encrypted transmission | Data transmissions occur, where technically possible, over encrypted connections, in particular TLS/HTTPS. |
| Secure communication channels | Sensitive data is, where possible, transmitted over suitable secured channels. |
| Restriction of data exports | Data exports occur only insofar as they are necessary for the contractual service. |
| Use of vetted service providers | Sub-processors are used only if they are contractually committed to complying with appropriate data protection and security requirements. |
| Third-country transfers | Transfers to third countries occur only if the statutory requirements are met. |
6. Input control
The goal is to be able to trace whether and by whom personal data has been entered, altered or deleted, insofar as this is technically possible and appropriate.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| User-related access | Changes are made in principle via individual user accounts. |
| System logs | In the systems used, change and access histories are used where available. |
| Project-related documentation | Material project decisions, data changes and coordination are appropriately documented. |
| Traceability of support cases | Support and error-analysis processes are documented in suitable systems. |
7. Commission control
The goal is to ensure that personal data is processed only in accordance with the client's instructions.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| DPA provision | Processing takes place on the basis of the DPA and documented instructions of the client. |
| Project agreements and service descriptions | The scope and purpose of the processing also result from project agreements, service descriptions and documented coordination. |
| Confidentiality obligation | Persons authorised to process are committed to confidentiality or are subject to an appropriate statutory duty of confidentiality. |
| Sub-processors | Sub-processors are documented in a separate sub-processor list. |
| Review of instructions | Systempilot informs the client if, in Systempilot's assessment, an instruction violates data protection provisions. |
8. Availability control
The goal is to protect personal data against accidental destruction, loss or unavailability.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Use of professional hosting and cloud providers | The availability of production systems is supported by suitable providers and technical infrastructure. |
| Backups | Insofar as Systempilot operates systems itself, appropriate backup measures are used. |
| Recoverability | Data and systems are kept recoverable within the scope of the technical possibilities. |
| Protection against malware | Work devices and systems are appropriately protected against malware and unauthorised access. |
| Updates and patches | Security-relevant updates are applied to an appropriate extent. |
9. Separation requirement
The goal is to process personal data that is processed for different purposes or for different clients separately.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Project-related storage | Customer data is stored structured per project or customer. |
| Tenant separation | Insofar as the systems used offer multi-tenancy, this is used. |
| Role and permission assignment | Access rights are restricted per customer and project. |
| Purpose limitation | Data is processed only within the scope of the contractually agreed purposes. |
10. Pseudonymisation and data minimisation
The goal is to process personal data only to the extent necessary for the respective service.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Data minimisation | Only such personal data is processed as is necessary for implementation, support, error analysis, operation or other agreed services. |
| Test and development data | Where possible and appropriate, test data is anonymised, pseudonymised or limited to the necessary extent. |
| Log minimisation | Customer data is, where possible, not transferred to logs, error reports or monitoring systems, or only in minimised form. |
| Restriction of AI processing | AI-supported processing occurs only insofar as it is necessary for the respective purpose or desired or approved by the customer. |
11. Encryption
The goal is to appropriately protect personal data during transmission and storage.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Transport encryption | Use of encrypted connections, in particular HTTPS/TLS, where technically possible. |
| Encryption by providers | For cloud and SaaS services, the encryption mechanisms provided by the respective provider are used. |
| Access protection on end devices | End devices are secured by suitable access protection mechanisms. |
| Secret protection | Credentials, API keys and comparable secrets are not stored publicly and are appropriately protected in a password vault with restricted access. |
12. Integrity and resilience of the systems
The goal is to ensure the ongoing confidentiality, integrity, availability and resilience of the systems and services.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Selection of suitable providers | Providers are used that offer appropriate technical and organisational security measures. |
| Monitoring and error analysis | For its own systems, monitoring, logging and error-analysis tools may be used. |
| Security updates | Systems are updated to an appropriate extent. |
| Access restriction | Administrative access is restricted and protected. |
| Configuration control | Changes to production systems are made in a controlled and traceable manner. |
13. Procedures for regular review, assessment and evaluation
The goal is to regularly review the effectiveness of the technical and organisational measures.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Regular review | Security and data protection measures are reviewed on occasion and at appropriate intervals. |
| Adjustment upon changes | Measures are adjusted when technical, organisational or legal conditions change. |
| Review of sub-processors | Sub-processors are reviewed for appropriate data protection and security standards before use and on occasion. |
| Documentation | Material data protection and security decisions are documented. |
14. Incident management / data breaches
The goal is to appropriately detect, assess and handle security incidents and data breaches.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Internal assessment | Suspicious security incidents are internally reviewed and assessed. |
| Notification to the client | Data breaches in connection with commissioned processing are reported to the client without delay, insofar as Systempilot becomes aware of them and a notification obligation exists. |
| Documentation | Relevant security incidents are documented. |
| Remedial measures | Necessary technical and organisational measures for containment and remediation are implemented. |
15. Deletion and return
The goal is to properly delete or return personal data after the end of processing according to the client's instructions.
Systempilot uses in particular the following measures:
| Measure | Description |
|---|---|
| Deletion after end of contract | After final termination of the relevant services, personal data is deleted or returned in accordance with the DPA. |
| Statutory retention obligations | Statutory retention obligations remain unaffected. |
| Deletion of copies | Existing copies are deleted, insofar as there is no legal obligation or legitimate technical reason for further retention. |
| Backup cycles | Data in backups is removed within the scope of the usual backup and deletion cycles. |
Questions, violations or other data-protection-relevant reports are to be addressed to the dedicated email address privacy@systempilot.net.