Technical and organisational measures under Art. 32 GDPR (TOM)

As of: 28.04.2026

This English text is a convenience translation. The legally binding version is the German TOM; in case of discrepancies, the German version prevails.

1. General security organisation

Systempilot takes appropriate technical and organisational measures to protect personal data. The measures are based on the nature, scope, circumstances and purposes of the processing as well as the risk to the rights and freedoms of the data subjects.

The measures are reviewed regularly and adjusted as needed. Systempilot is entitled to replace individual measures with equivalent or superior measures, provided the agreed level of protection is not thereby reduced.

2. Physical access control

The goal is to prevent unauthorised physical access to systems, premises and infrastructure where personal data is processed.

Systempilot processes personal data predominantly via cloud-based systems and data centres of the service providers used. Physical access to data centres is secured by the respective hosting and cloud providers.

Systempilot uses in particular the following measures:

MeasureDescription
Data centre operation by professional providersHosting and infrastructure are provided via specialised providers with their own access and security concepts.
No public access to production systemsProduction systems are not publicly physically accessible.
Device protectionWork devices are protected against unauthorised access.
Home office / remote workWork is carried out in principle via individual user accounts and secured end devices.

3. System access control

The goal is to prevent unauthorised access to IT systems.

Systempilot uses in particular the following measures:

MeasureDescription
Personal user accountsAccess to systems is via individual user accounts.
Password protectionSystems are protected by passwords or comparable authentication mechanisms.
Two-factor authenticationWhere available and appropriate, two-factor authentication is used, in particular for central cloud, hosting, communication and administration systems.
Role and permission conceptAccess rights are granted according to area of responsibility and necessity.
Need-to-know principleOnly persons who need it for the provision of services receive access to customer data.
Blocking of no-longer-needed accessUser accounts that are no longer needed are deactivated or deleted.

4. Data access control

The goal is to ensure that authorised users can only access those personal data they need to fulfil their tasks.

Systempilot uses in particular the following measures:

MeasureDescription
Authorisation conceptsAccess is granted per project and system.
Tenant and project separationCustomer data is processed separately organisationally and, where technically provided, on the system side.
Restriction of administrative rightsAdministrative rights are granted only to authorised persons.
Regular review of authorisationsAuthorisations are reviewed on occasion and at appropriate intervals.
LoggingWhere available on the system side, relevant access, changes or administrative activities are logged.

5. Transfer control

The goal is to prevent personal data from being read, copied, altered or removed without authorisation during transmission, storage or transfer.

Systempilot uses in particular the following measures:

MeasureDescription
Encrypted transmissionData transmissions occur, where technically possible, over encrypted connections, in particular TLS/HTTPS.
Secure communication channelsSensitive data is, where possible, transmitted over suitable secured channels.
Restriction of data exportsData exports occur only insofar as they are necessary for the contractual service.
Use of vetted service providersSub-processors are used only if they are contractually committed to complying with appropriate data protection and security requirements.
Third-country transfersTransfers to third countries occur only if the statutory requirements are met.

6. Input control

The goal is to be able to trace whether and by whom personal data has been entered, altered or deleted, insofar as this is technically possible and appropriate.

Systempilot uses in particular the following measures:

MeasureDescription
User-related accessChanges are made in principle via individual user accounts.
System logsIn the systems used, change and access histories are used where available.
Project-related documentationMaterial project decisions, data changes and coordination are appropriately documented.
Traceability of support casesSupport and error-analysis processes are documented in suitable systems.

7. Commission control

The goal is to ensure that personal data is processed only in accordance with the client's instructions.

Systempilot uses in particular the following measures:

MeasureDescription
DPA provisionProcessing takes place on the basis of the DPA and documented instructions of the client.
Project agreements and service descriptionsThe scope and purpose of the processing also result from project agreements, service descriptions and documented coordination.
Confidentiality obligationPersons authorised to process are committed to confidentiality or are subject to an appropriate statutory duty of confidentiality.
Sub-processorsSub-processors are documented in a separate sub-processor list.
Review of instructionsSystempilot informs the client if, in Systempilot's assessment, an instruction violates data protection provisions.

8. Availability control

The goal is to protect personal data against accidental destruction, loss or unavailability.

Systempilot uses in particular the following measures:

MeasureDescription
Use of professional hosting and cloud providersThe availability of production systems is supported by suitable providers and technical infrastructure.
BackupsInsofar as Systempilot operates systems itself, appropriate backup measures are used.
RecoverabilityData and systems are kept recoverable within the scope of the technical possibilities.
Protection against malwareWork devices and systems are appropriately protected against malware and unauthorised access.
Updates and patchesSecurity-relevant updates are applied to an appropriate extent.

9. Separation requirement

The goal is to process personal data that is processed for different purposes or for different clients separately.

Systempilot uses in particular the following measures:

MeasureDescription
Project-related storageCustomer data is stored structured per project or customer.
Tenant separationInsofar as the systems used offer multi-tenancy, this is used.
Role and permission assignmentAccess rights are restricted per customer and project.
Purpose limitationData is processed only within the scope of the contractually agreed purposes.

10. Pseudonymisation and data minimisation

The goal is to process personal data only to the extent necessary for the respective service.

Systempilot uses in particular the following measures:

MeasureDescription
Data minimisationOnly such personal data is processed as is necessary for implementation, support, error analysis, operation or other agreed services.
Test and development dataWhere possible and appropriate, test data is anonymised, pseudonymised or limited to the necessary extent.
Log minimisationCustomer data is, where possible, not transferred to logs, error reports or monitoring systems, or only in minimised form.
Restriction of AI processingAI-supported processing occurs only insofar as it is necessary for the respective purpose or desired or approved by the customer.

11. Encryption

The goal is to appropriately protect personal data during transmission and storage.

Systempilot uses in particular the following measures:

MeasureDescription
Transport encryptionUse of encrypted connections, in particular HTTPS/TLS, where technically possible.
Encryption by providersFor cloud and SaaS services, the encryption mechanisms provided by the respective provider are used.
Access protection on end devicesEnd devices are secured by suitable access protection mechanisms.
Secret protectionCredentials, API keys and comparable secrets are not stored publicly and are appropriately protected in a password vault with restricted access.

12. Integrity and resilience of the systems

The goal is to ensure the ongoing confidentiality, integrity, availability and resilience of the systems and services.

Systempilot uses in particular the following measures:

MeasureDescription
Selection of suitable providersProviders are used that offer appropriate technical and organisational security measures.
Monitoring and error analysisFor its own systems, monitoring, logging and error-analysis tools may be used.
Security updatesSystems are updated to an appropriate extent.
Access restrictionAdministrative access is restricted and protected.
Configuration controlChanges to production systems are made in a controlled and traceable manner.

13. Procedures for regular review, assessment and evaluation

The goal is to regularly review the effectiveness of the technical and organisational measures.

Systempilot uses in particular the following measures:

MeasureDescription
Regular reviewSecurity and data protection measures are reviewed on occasion and at appropriate intervals.
Adjustment upon changesMeasures are adjusted when technical, organisational or legal conditions change.
Review of sub-processorsSub-processors are reviewed for appropriate data protection and security standards before use and on occasion.
DocumentationMaterial data protection and security decisions are documented.

14. Incident management / data breaches

The goal is to appropriately detect, assess and handle security incidents and data breaches.

Systempilot uses in particular the following measures:

MeasureDescription
Internal assessmentSuspicious security incidents are internally reviewed and assessed.
Notification to the clientData breaches in connection with commissioned processing are reported to the client without delay, insofar as Systempilot becomes aware of them and a notification obligation exists.
DocumentationRelevant security incidents are documented.
Remedial measuresNecessary technical and organisational measures for containment and remediation are implemented.

15. Deletion and return

The goal is to properly delete or return personal data after the end of processing according to the client's instructions.

Systempilot uses in particular the following measures:

MeasureDescription
Deletion after end of contractAfter final termination of the relevant services, personal data is deleted or returned in accordance with the DPA.
Statutory retention obligationsStatutory retention obligations remain unaffected.
Deletion of copiesExisting copies are deleted, insofar as there is no legal obligation or legitimate technical reason for further retention.
Backup cyclesData in backups is removed within the scope of the usual backup and deletion cycles.

Questions, violations or other data-protection-relevant reports are to be addressed to the dedicated email address privacy@systempilot.net.