Technical and Organizational Measures (TOM)
Annex 1 to the DPA – octoja GmbH
octoja GmbH — As of: July 2026
Pursuant to Art. 32 GDPR
The German version of this document is the sole legally binding version.
These TOMs describe the catalogue of measures implemented as of July 2026 for the protection of personal data in connection with the operation of the octoja RMM platform. octoja reviews and updates these measures regularly in accordance with the state of the art.
1. Physical Access Control
Measures to prevent unauthorized physical access to data processing facilities
- Data Center (Hetzner): The platform's physical infrastructure is operated in certified data centers of Hetzner Online GmbH in Germany (Nuremberg, Falkenstein). Hetzner ensures physical access security through access control systems, security personnel, video surveillance, and multi-factor access authentication. octoja employees have no direct physical access to the server locations.
- octoja Office Premises: Access to octoja office premises is restricted to authorized employees; visitor access only when accompanied.
2. System Access Control
Measures to prevent unauthorized use of data processing systems
- Secure password policy for all internal systems: minimum length 12 characters, combination of upper/lowercase letters, digits, and special characters
- Mandatory multi-factor authentication (MFA) for all administrative access to the platform infrastructure
- Automatic session timeouts after inactivity
- Encrypted transmission of all access credentials (TLS 1.2 or higher)
- Password hashing with modern algorithms (bcrypt/Argon2); no plaintext storage of passwords
- Use of a centralized password management system for internal access credentials
3. Data Access Control
Measures to ensure that only authorized persons can access the data
- Role-based access control (RBAC) at platform level: separation of administrators, technicians, and read-only access
- Tenant isolation at database level: data of different resellers/MSPs is strictly logically separated
- Principle of least privilege: employees receive only the permissions required for their specific tasks
- Regular review and revocation of no longer needed access rights (at least semi-annually)
- Complete logging of all administrative access to production systems (audit logs)
- Separation of development, test, and production environments; no access to production data in test environments without anonymization
4. Separation Control
Measures for separate processing of data collected for different purposes
- Logical tenant separation at database and application level: data of different clients (distributors/MSPs) cannot be viewed by each other
- Separate database schemas or tenant IDs as separation mechanism
- Separate processing of production and test data
- Log and protocol data are stored separately from operational user data
5. Pseudonymization and Encryption
Measures pursuant to Art. 32(1)(a) GDPR
- Transport Encryption: All data transmissions between client and platform take place exclusively via TLS 1.2 or higher (HTTPS). HTTP requests are automatically redirected to HTTPS.
- Encryption of Stored Data: Sensitive database fields (e.g., authentication tokens, API keys) are stored in encrypted form.
- Backup Encryption: Database backups are encrypted with AES-256 before being transferred to an S3-compatible object storage located in Germany. The encryption key remains exclusively with octoja.
- Pseudonymization: Where technically possible and appropriate, pseudonymized identifiers are used in logs and evaluations instead of direct personal identifiers.
6. Availability Control
Measures to protect against accidental or intentional destruction or loss
- High Availability: The central database is operated as a redundant cluster with automatic failover; if individual systems fail, a replacement system takes over without manual intervention.
- Backups: Regular full and incremental database backups as well as continuous archiving of transaction logs enable point-in-time recovery. All backups are stored encrypted and geographically separated from the primary site.
- Restore Tests: The recoverability of backups is verified quarterly by documented restore tests.
- Monitoring: Continuous 24/7 monitoring of platform availability and critical system components with automatic alerting mechanisms
- Incident Response: Defined internal process for responding to system outages with clearly defined responsibilities
- Updates and Patches: Regular application of security patches for operating systems, dependencies, and platform components
- Emergency Plan: Documented business continuity plan for critical failure scenarios
7. System Resilience
Measures for permanent resilience pursuant to Art. 32(1)(b) GDPR
- Scalable cloud infrastructure at Hetzner enables adaptation to peak loads
- Load balancing for critical platform components
- Regular load tests and capacity planning
- Automatic restart management for failed services
8. Transfer Control
Measures to ensure that data cannot be read, copied, or altered without authorization during electronic transmission
- Exclusively encrypted transmission channels (TLS 1.2+) for all external data communications
- No unencrypted transmission of personal data via email; sensitive communication takes place via encrypted channels
- API communication with third-party services (e.g., ThreatDown, Lywand, Microsoft 365) exclusively via secured, authenticated connections (HTTPS/TLS, API key authentication)
- Delivery of static platform content via Bunny CDN exclusively via HTTPS/TLS; no personal user data is cached in the CDN; Bunny CDN is GDPR-compliant as an EU-based provider (Slovenia)
- Logging of data transfers to sub-processors
- No transfer of personal data to third parties outside the DPA without instruction from the data controller
9. Input Control
Measures to log whether data has been entered, modified, or deleted
- Complete audit logs for all security-relevant actions on the platform (logins, permission changes, configuration changes, script executions)
- Logging of administrative actions with timestamp and user ID
- Immutable log storage (logs cannot be deleted by the user)
- Retention of audit logs for at least 90 days
10. Order Control
Measures to ensure that data is processed only in accordance with the instructions of the data controller
- Written DPA with all sub-processors pursuant to Art. 28 GDPR
- Regular review of sub-processors for compliance with data protection requirements
- Internal training of octoja employees on data protection and obligation to follow instructions
- Documented instruction from the data controller as a prerequisite for any data processing outside regular platform operations
11. Organizational Measures
- Data Protection Officer: octoja is currently not subject to the obligation to appoint a Data Protection Officer pursuant to Art. 37 GDPR in conjunction with § 38 BDSG. The obligation to appoint is reviewed regularly, in particular in the event of personnel growth. Contact for all data protection enquiries: datenschutz@octoja.de
- Employee Training: All employees with access to personal data are trained in data protection and information security upon commencement of their role and at least annually
- Confidentiality Commitment: All employees are committed to confidentiality in writing
- Data Protection Policy: Internal data protection policy governs the handling of personal data within the company
- Incident Management: Documented process for detecting, reporting, and handling data protection breaches
12. Review of the Effectiveness of Measures
Procedures for regular review, assessment and evaluation pursuant to Art. 32(1)(d) GDPR
- The effectiveness of the technical and organizational measures is reviewed regularly, inter alia through quarterly restore tests pursuant to Section 6 and at least annual penetration tests.
- Results of the reviews are documented; identified vulnerabilities are remediated based on priority.
- These TOMs are reviewed and updated at least annually and on an ad-hoc basis in the event of material changes to the infrastructure.
13. Measures for the Use of Third-Party Services
The following third-party services are integrated into the Platform or used for its operation. The respective providers' own TOM and data protection documentation apply to these services and are reviewed by octoja for adequacy:
| Service | Provider | Data Protection Evidence |
|---|---|---|
| Hosting / Data Centre | Hetzner Online GmbH (DE) | ISO 27001, GDPR-compliant, DPA in place |
| Database backup storage | Hetzner Online GmbH – Object Storage (DE) | ISO 27001, GDPR-compliant, DPA in place |
| Domain / DNS | Hetzner Online GmbH (DE) | ISO 27001, GDPR-compliant, DPA in place |
| Customer management database | Supabase Pte. Ltd. (Singapore; data processing in EU/Frankfurt) | SOC 2 Type 2, EU Standard Contractual Clauses, DPA in place |
| Ticket system / Support | CORDNET OÜ (d/b/a Featurebase, EE/EU) | GDPR-compliant, DPA in place |
| Email communication (Support) | Microsoft 365 (Microsoft Ireland, EU) | ISO 27001, EU Standard Contractual Clauses, DPA in place |
| Email notifications | Brevo (Sendinblue GmbH, DE) | GDPR-compliant, DPA in place, data processing in the EU |
| CDN / Content delivery | BunnyWay d.o.o. – Bunny CDN (SI/EU) | GDPR-compliant, ISO 27001, DPA in place |
| Alerting (call, SMS, WhatsApp) | seven communications GmbH & Co. KG (DE) | GDPR-compliant, DPA in place, data processing in the EU |
octoja GmbH – As of July 2026
These TOMs are reviewed and updated at least annually and on an ad-hoc basis when significant changes to the infrastructure occur.