| 1. Data transfer | - Encryption during transfer (TLS 1.2 / 1.3)
- Internal: devices → gateway → EU cloud
- Outside: ixi Pro (SIM and GPS) → mobile network → EU cloud
- Secure push notifications
| Confidentiality and integrity of data during transfer |
| 2. Data storage | - Encryption at rest (AES-256)
- EU-hosted cloud (AWS, with protection against DDoS, SOC 2 / ISO certifications)
- Audit logging with timestamps and tamper resistance
- Separation of access to systems and backups
| Protection of stored data and full traceability |
| 3. Access management and authentication | - Role-based access control (need-to-know, least privilege)
- Multi-factor authentication available for ixicare administrators
- Controlled support access only after a formal request from the controller
| Access restriction, abuse prevention and accountability |
| 4. Data deletion and retention | - Manual deletion by authorised administrators
- Limited backup retention, then overwriting
- Secure wipe and reset at end of device life, including stop-transmit and reset on deprovisioning
| Compliance with the retention policy and secure deletion of personal data |
| 5. Network and device security | - Secure firmware and configuration updates over the air
- Firewalls and segmentation of cloud and application environments
- AWS high availability and DDoS mitigation
| Protection against unauthorised access and cyber threats |
| 6. Availability and continuity | - Redundant servers and failover for 24/7 operation
- Hosting in EU data centres (AWS, high availability)
- Monitoring of platform and devices with incident notifications
- Backup and restore procedures
| Uninterrupted service and recovery in the event of incidents |
| 7. Security monitoring and change management | - External penetration testing
- Regular vulnerability scans
- Intrusion detection on the cloud platform
- Peer review and logging of manual actions (code, server access)
- Controlled development and release process
| Early detection and mitigation of security risks |
| 8. Legal and compliance | - Privacy and security policy
- Data processing agreements with customers and subcontractors
- Privacy risk assessments with a re-evaluation cycle
- Supplier management with audit rights and due diligence (ISO 27001, SOC 2)
- Terms of use and privacy notice
| Governance, compliance and chain responsibility |
| 9. Employees and awareness | - Periodic GDPR and security training
- Confidentiality clauses for staff and contractors
| Awareness and compliance among employees |
| 10. Incident and data breach management | - Procedure in line with the 72-hour GDPR reporting obligation
- Crisis and escalation protocol with communication to customers
- Evaluation and follow-up of incidents
| Rapid response, transparency and recovery after a data breach |
| 11. Rights of data subjects | - Procedure for access, correction, portability and deletion of personal data
- Contact point for GDPR requests from customers and data subjects
- Transparency through the privacy notice
| Strengthening data subject rights and GDPR compliance |
| 12. Data minimisation and R&D | - Location data only during active alarms or necessary monitoring; no continuous tracking as standard
- Use for research and development only with appropriate safeguards (notice, anonymisation)
| Minimising processing and secure use for innovation |