Skip to content

Security Measures Schedule

Technical and organisational measures incorporated into the DPA.

Version
1.0
Last updated
22 September 2026

This Schedule forms Annex II of the DPA. Detailed evidence may be requested at legal@advigator.com under confidentiality. Measures may evolve without materially reducing the overall level of protection.

Area Measures
Encryption HTTPS/TLS for service connections; encryption of production data storage and backups; passwords stored as salted hashes rather than recoverable plaintext.
Access Individual access for authorised personnel, least-privilege permissions and revocation when access is no longer authorised. Customer access is restricted by account and permissions.
Confidentiality Personnel with access to Customer Personal Data are bound by confidentiality duties.
Segregation Logical separation of customer accounts and access controls to restrict cross-customer access.
Maintenance Application security protections and dependency maintenance; changes are tested before release.
Monitoring Application error and availability monitoring to support incident detection and investigation.
Recovery Daily database backups to separate storage. Deletion and backup expiry follow the retention policy. No contractual RTO or RPO is included without a signed agreement.
Accountability Service change history and authentication/session records; this is not a comprehensive audit log of every dashboard action.
Incidents A reporting and response process and customer notification without undue delay, no later than the DPA deadline.
Suppliers Written data protection obligations, the DPA authorisation/objection process and safeguards for restricted transfers.

Scope and limitations

No independent certification, penetration test, scheduled access-review programme, automated dependency-scanning programme or formal recurring security-training programme is represented as completed by this Schedule. Review evidence distinguishes implemented controls from planned work. Customers must assess whether the standard service meets their requirements before purchase.

Nothing here limits mandatory security obligations or the DPA audit rights. Additional agreed controls must be recorded in writing; a template or roadmap is not such an agreement.

Questions about this document: legal@advigator.com. All Advigator legal documents are listed at advigator.com/legal.