Skip to content

Technical and Organizational Measures (TOMs)

This document outlines the technical and organizational security measures implemented by On2Air.com to protect Personal Data. It is the detail behind Annex II of our Data Processing Addendum.

  • Access to data centers is restricted to authorized personnel only.
  • 24/7 security monitoring and biometric access controls at data hosting facilities.
  • Secure disposal of hardware and storage media.
  • Use of strong password policies and multi-factor authentication (MFA).
  • Role-based access control (RBAC) to ensure employees only have access to data necessary for their roles.
  • Logging and auditing of all system access and changes.
  • Encryption of data at rest using industry-standard algorithms (e.g., AES-256).
  • Encryption of data in transit using TLS 1.2 or higher.
  • Regular database backups with secure, off-site storage.
  • Use of secure protocols for all data transfers.
  • Monitoring of network traffic for suspicious activity.
  • Logging of data entry, modification, and deletion.
  • Audit trails for sensitive operations.
  • High-availability architecture with redundant systems.
  • Business continuity and disaster recovery plans.
  • Regular testing of backup restoration processes.
  • Logical separation of customer data within the multi-tenant architecture.
  • Development, testing, and production environments are strictly separated.
  • Regular security awareness training for all employees.
  • Internal privacy and security policies.
  • Incident response procedures for managing and reporting security breaches.

See also: Data Security · Data Processing Addendum · Privacy Policy