Technical and Organizational Measures (TOMs)
This document outlines the technical and organizational security measures implemented by On2Air.com to protect Personal Data. It is the detail behind Annex II of our Data Processing Addendum.
1. Physical Access Control
Section titled “1. Physical Access Control”- Access to data centers is restricted to authorized personnel only.
- 24/7 security monitoring and biometric access controls at data hosting facilities.
- Secure disposal of hardware and storage media.
2. System Access Control
Section titled “2. System Access Control”- Use of strong password policies and multi-factor authentication (MFA).
- Role-based access control (RBAC) to ensure employees only have access to data necessary for their roles.
- Logging and auditing of all system access and changes.
3. Data Access Control
Section titled “3. Data Access Control”- Encryption of data at rest using industry-standard algorithms (e.g., AES-256).
- Encryption of data in transit using TLS 1.2 or higher.
- Regular database backups with secure, off-site storage.
4. Transmission Control
Section titled “4. Transmission Control”- Use of secure protocols for all data transfers.
- Monitoring of network traffic for suspicious activity.
5. Input Control
Section titled “5. Input Control”- Logging of data entry, modification, and deletion.
- Audit trails for sensitive operations.
6. Availability Control
Section titled “6. Availability Control”- High-availability architecture with redundant systems.
- Business continuity and disaster recovery plans.
- Regular testing of backup restoration processes.
7. Separation Control
Section titled “7. Separation Control”- Logical separation of customer data within the multi-tenant architecture.
- Development, testing, and production environments are strictly separated.
8. Organizational Measures
Section titled “8. Organizational Measures”- Regular security awareness training for all employees.
- Internal privacy and security policies.
- Incident response procedures for managing and reporting security breaches.
See also: Data Security · Data Processing Addendum · Privacy Policy