This Schedule forms Annex II of the DPA. Detailed evidence may be requested at legal@advigator.com under confidentiality. Measures may evolve without materially reducing the overall level of protection.
| Area | Measures |
|---|---|
| Encryption | HTTPS/TLS for service connections; encryption of production data storage and backups; passwords stored as salted hashes rather than recoverable plaintext. |
| Access | Individual access for authorised personnel, least-privilege permissions and revocation when access is no longer authorised. Customer access is restricted by account and permissions. |
| Confidentiality | Personnel with access to Customer Personal Data are bound by confidentiality duties. |
| Segregation | Logical separation of customer accounts and access controls to restrict cross-customer access. |
| Maintenance | Application security protections and dependency maintenance; changes are tested before release. |
| Monitoring | Application error and availability monitoring to support incident detection and investigation. |
| Recovery | Daily database backups to separate storage. Deletion and backup expiry follow the retention policy. No contractual RTO or RPO is included without a signed agreement. |
| Accountability | Service change history and authentication/session records; this is not a comprehensive audit log of every dashboard action. |
| Incidents | A reporting and response process and customer notification without undue delay, no later than the DPA deadline. |
| Suppliers | Written data protection obligations, the DPA authorisation/objection process and safeguards for restricted transfers. |
Scope and limitations
No independent certification, penetration test, scheduled access-review programme, automated dependency-scanning programme or formal recurring security-training programme is represented as completed by this Schedule. Review evidence distinguishes implemented controls from planned work. Customers must assess whether the standard service meets their requirements before purchase.
Nothing here limits mandatory security obligations or the DPA audit rights. Additional agreed controls must be recorded in writing; a template or roadmap is not such an agreement.