Section 1
1. Note
1.1 This document contains information available to business partners, customers, and other external parties with legal or other rights of access. For the sake of readability, the text may use the masculine form, but the information applies to individuals of all genders.
2. Preamble
2.1 As a data processor, Lumiform has implemented appropriate technical and organizational measures to ensure the confidentiality, integrity, availability, and resilience of its systems, as well as procedures for their regular review, assessment, and evaluation. The measures described below apply regardless of service, location, or customer.
3. Certifications
3.1 Lumiform holds the following official certifications in the field of information security:
| Certificates | Comment |
|---|---|
| ISO 27001 | via AWS |
| ISO 27017 | via AWS |
| ISO 27018 | via AWS |
| Other / Comments | Our data security standards are designed to comply with the recommended best practices in recognized standards such as ISO 27001. Our goal is to continuously expand our security program and pursue formal certification. Find more information here: https://lumiformapp.com/legal/security-standards |
4. Basic Measures
4.1 Basic measures designed to safeguard the rights of data subjects, ensure an immediate response in emergencies, comply with technical design requirements, and protect data at the employee level:
- (a) We have an organizational data protection management system in place that is systematically monitored and evaluated at least twice a year.
- (b) There is a policy for an immediate and legally compliant response to data breaches, which includes investigation, documentation, and reporting. This includes forms, instructions, and necessary implementation procedures.
- (c) A policy for safeguarding the rights of data subjects (e.g., access, rectification, erasure) within statutory timeframes is in place, including forms, instructions, and implementation procedures.
- (d) Authorizations for employees to process personal data, as well as keys, access cards, or codes, are revoked upon termination of employment or a change in responsibilities in accordance with an authorization policy.
- (e) Service providers for non-core business tasks are carefully selected to ensure the protection of personal data. For service providers involved in core business activities, data protection and the rights and obligations of the client and contractor in data processing arrangements are guaranteed, including in the case of data transfers to third countries.
- (f) Employees receive training in data protection, are bound by confidentiality obligations, and are made aware of the legal consequences of liability. Special regulations apply to activities conducted outside company premises or when using personal devices.
- (g) The protection of personal data is taken into account—considering the state of the art, implementation costs, and processing risks—as early as the development and selection of hardware, software, and procedures, in accordance with the principle of data protection through technology design and privacy-friendly default settings (Art. 25 GDPR).
- (h) The software, virus scanners, and firewalls in use are always kept up to date.
5. Access Control
5.1 All measures suitable for preventing unauthorized access to data processing facilities.
5.2 Measures Implemented:
- (a) Alarm system
- (b) Automated access control system
- (c) Manual locking system
- (d) Security locks
- (e) Securing building shafts
- (f) Doors with a knob on the outside
- (g) Window security
- (h) Staff on duty at all times
- (i) Doorbell system with camera
- (j) Regulation of key issuance
- (k) Visitor log / visitor record
- (l) Visitor access policies
- (m) Visitors must be accompanied by staff
- (n) Careful Selection of Cleaning Services
6. Access Control
6.1 All measures suitable for preventing unauthorized use of data processing systems, as well as all measures that ensure that individuals authorized to use a data processing system can access only the data covered by their access authorization, and that personal data cannot be read, copied, modified, or deleted without authorization during processing, use, and after storage.
6.2 Measures Implemented:
- (a) Login with username + password
- (b) Login using biometric data
- (c) Always up-to-date antivirus protection
- (d) Software versions always kept up to date
- (e) Encrypted data transfer via HTTPS/TLS or comparable security systems
- (f) Network firewall
- (g) Mobile device management
- (h) Encryption of storage media
- (i) Smartphone encryption
- (j) Blocking of external interfaces (USB, etc.)
- (k) Use of Intrusion Detection Systemsl
- (l) Automatic desktop lock
- (m) Encryption of laptops/tablets
- (n) Management of user permissions
- (o) Creating user profiles
- (p) Directory and Policies for Removable Storage Devices
- (q) “Secure Password” Policy
- (r) “Deletion/Destruction” Policy
- (s) “Clean Desk” Policy
- (t) Screen Lock Policy
- (u) General Policy on Data Protection and/or Security
- (v) Mobile Device Policy
- (w) “Manual Desktop Lock” Instructions
- (x) Paper Shredder
- (y) Physical Destruction of Data Storage Media
- (z) Logging of Access to Applications, Specifically When Entering, Modifying, and Deleting Data
- (aa) Use of authorization models
- (bb) Minimum number of administrators
- (cc) Management of User Permissions by Administrators
- (dd) Personal Firewall
- (ee) Policy on the Use of USB Drives
7. Data Disclosure Control
7.1 All measures that ensure that personal data cannot be read, copied, altered, or removed without authorization during electronic transmission, transport, or storage on data carriers, and that it is possible to verify and determine the destinations to which personal data is intended to be transmitted via data transmission systems.
7.2 Measures Implemented:
- (a) Email encryption (S/MIME, PGP, TLS, or equivalent)
- (b) Logging of accesses and retrievals
- (c) Data is disclosed only to authorized third parties
- (d) Pseudonymization
- (e) Encryption of data storage media and connections
- (f) Dedicated sharing permissions
- (g) Provision via encrypted connections such as SFTP, HTTPS
- (h) Use of signature procedures
8. Input control
8.1 All measures that ensure it is possible to subsequently verify and determine whether, and by whom, personal data has been entered into, modified, or removed from data processing systems.
8.2 Measures implemented:
- (a) Logging of data entries, modifications, and deletions
- (b) Manual or automated review of logs
- (c) Overview of which programs can be used to enter, modify, or delete which data
- (d) Traceability of data entry, modification, and deletion through individual usernames (not user groups)
- (e) Assignment of permissions to enter, modify, and delete data based on an authorization model
- (f) Retention of forms from which data has been transferred to automated processing systems
- (g) Clear responsibilities for deletions
- (h) Administrator and deputy concept
9. Order control
9.1 All measures that ensure that personal data processed on behalf of a client can only be processed in accordance with the client’s instructions.
9.2 Measures Implemented:
- (a) Prior review of the security measures implemented by the contractor and their documentation
- (b) Selection of the processor based on due diligence criteria (particularly with regard to data protection and data security)
- (c) Conclusion of the necessary data processing agreement or EU Standard Contractual Clauses
- (d) Written instructions to the processor
- (e) Obligation of the contractor’s employees to maintain data confidentiality
- (f) Requirement that the contractor appoint a data protection officer, if such an appointment is mandatory
- (g) Agreement on effective oversight rights with respect to the contractor
- (h) Provisions regarding the use of additional subcontractors
- (i) Ensuring the destruction of data upon termination of the contract
10. Availability Control / Integrity
10.1 All measures that ensure that personal data is protected against accidental destruction or loss.
10.2 Measures Implemented:
- (a) Fire and smoke detection systems
- (b) UPS (uninterruptible power supply)
- (c) Data protection safe (S60DIS, S120DIS, other suitable standards with source sealing, etc.)
- (d) RAID system / disk mirroring
- (e) Backup & Recovery Plan (fully documented)
- (f) Continuously monitored backup and recovery plan
- (g) Emergency plan implemented by in-house IT and external service providers
- (h) Conducting stress tests
- (i) Technical protection against data loss and unauthorized access through antivirus software, anti-spyware, and spam filters
- (j) Separate surge protection
- (k) Additional backup copies stored in specially secured locations
- (l) Differential and full backups, cloud-based and via NAS system
- (m) Regular data recovery tests and logging of results
- (n) Existence of an emergency plan (e.g., BSI IT Basic Protection 100-4)
- (o) Separate partitions for operating systems and data
11. Ensuring compliance with the principle of purpose limitation and data separation
11.1 All measures that ensure that data collected for different purposes can be processed separately.
11.2 Measures implemented:
- (a) Separation of production and test environments
- (b) Physical separation (systems/databases/data storage media)
- (c) Control via an authorization concept
- (d) Definition of database permissions
- (e) Data records are tagged with purpose attributes
- (f) Installation of a multi-tenant system