ixicare

Technical and organisational measures

Last updated 10 September 2026

This is an overview of the technical and organisational measures (TOM) that ixicare has implemented to protect personal data in accordance with the GDPR.

DomainMeasuresPurpose
1. Data transfer
  • Encryption during transfer (TLS 1.2 / 1.3)
  • Internal: devices → gateway → EU cloud
  • Outside: ixi Pro (SIM and GPS) → mobile network → EU cloud
  • Secure push notifications
Confidentiality and integrity of data during transfer
2. Data storage
  • Encryption at rest (AES-256)
  • EU-hosted cloud (AWS, with protection against DDoS, SOC 2 / ISO certifications)
  • Audit logging with timestamps and tamper resistance
  • Separation of access to systems and backups
Protection of stored data and full traceability
3. Access management and authentication
  • Role-based access control (need-to-know, least privilege)
  • Multi-factor authentication available for ixicare administrators
  • Controlled support access only after a formal request from the controller
Access restriction, abuse prevention and accountability
4. Data deletion and retention
  • Manual deletion by authorised administrators
  • Limited backup retention, then overwriting
  • Secure wipe and reset at end of device life, including stop-transmit and reset on deprovisioning
Compliance with the retention policy and secure deletion of personal data
5. Network and device security
  • Secure firmware and configuration updates over the air
  • Firewalls and segmentation of cloud and application environments
  • AWS high availability and DDoS mitigation
Protection against unauthorised access and cyber threats
6. Availability and continuity
  • Redundant servers and failover for 24/7 operation
  • Hosting in EU data centres (AWS, high availability)
  • Monitoring of platform and devices with incident notifications
  • Backup and restore procedures
Uninterrupted service and recovery in the event of incidents
7. Security monitoring and change management
  • External penetration testing
  • Regular vulnerability scans
  • Intrusion detection on the cloud platform
  • Peer review and logging of manual actions (code, server access)
  • Controlled development and release process
Early detection and mitigation of security risks
8. Legal and compliance
  • Privacy and security policy
  • Data processing agreements with customers and subcontractors
  • Privacy risk assessments with a re-evaluation cycle
  • Supplier management with audit rights and due diligence (ISO 27001, SOC 2)
  • Terms of use and privacy notice
Governance, compliance and chain responsibility
9. Employees and awareness
  • Periodic GDPR and security training
  • Confidentiality clauses for staff and contractors
Awareness and compliance among employees
10. Incident and data breach management
  • Procedure in line with the 72-hour GDPR reporting obligation
  • Crisis and escalation protocol with communication to customers
  • Evaluation and follow-up of incidents
Rapid response, transparency and recovery after a data breach
11. Rights of data subjects
  • Procedure for access, correction, portability and deletion of personal data
  • Contact point for GDPR requests from customers and data subjects
  • Transparency through the privacy notice
Strengthening data subject rights and GDPR compliance
12. Data minimisation and R&D
  • Location data only during active alarms or necessary monitoring; no continuous tracking as standard
  • Use for research and development only with appropriate safeguards (notice, anonymisation)
Minimising processing and secure use for innovation

ISO 27001 and SOC 2 above refer to certifications held by our suppliers, as part of supplier due diligence. Questions go to info@ixicare.com.