Skip to content
ProductsServicesProcessAbout Kais SolutionsContact
DEStart a project
Products Services Process About Kais Solutions Contact Start a project
Home/Terms/SmartShelf

SmartShelf

Technical and Organisational Measures (TOMs)

SmartShelf – annex to the DPA

Version 1.0As of 31 August 2026

Also for SmartShelf:Terms for IT and software servicesService level agreement and supportData processing agreement (DPA)Sub-processors
This is a convenience translation. Only the German original is legally binding; in case of any discrepancy, the German version prevails.
Contents
  1. 1. Organisation and responsibilities
  2. 2. Physical access control
  3. 3. System access control
  4. 4. Data access control and separation of customer data
  5. 5. Transfer and transport control
  6. 6. Logging
  7. 7. Availability and backup
  8. 8. Protection against malware
  9. 9. Application security and development
  10. 10. Privacy by default
  11. 11. Incident response
  12. 12. Sub-processors
  13. 13. Regular review

1. Organisation and responsibilities

  • Need-to-know and least-privilege principle for access rights.
  • Administrative activities only by authorised persons.
  • Confidentiality undertaking for persons with access to personal data.
  • Documented handling of significant security and operational incidents.

2. Physical access control

  • Physical access to data centre and cloud infrastructure is protected by the respective infrastructure providers.
  • No publicly accessible physical operation of production servers by end customers.

3. System access control

  • Individual user accounts and role-based permissions.
  • Strong authentication for administrative access; multi-factor authentication where technically available and appropriate.
  • Key-based or comparably secured administrative access.
  • Secure session and sign-in procedures.
  • No storage of access credentials in publicly accessible source code.

4. Data access control and separation of customer data

  • Logical separation of customer data and production customer environments.
  • Role- and site-based permissions.
  • Server-side authorisation checks.
  • Database and infrastructure components not directly publicly reachable where possible.
  • Administrative rights limited to the necessary minimum.

5. Transfer and transport control

  • TLS/HTTPS for the web application.
  • Protected administrative connections.
  • Network segmentation between public and internal components.
  • Secure or encrypted transfer of backups to external object storage.

6. Logging

  • Logging of security- and operations-relevant events.
  • Traceability of essential business transactions, as far as provided for by SmartShelf.
  • Access to logs only for authorised persons or engaged monitoring service providers.
  • Sensitive content is not written to logs unnecessarily, where possible.

7. Availability and backup

  • Production-relevant data is backed up daily as scheduled, starting at around 03:00.
  • At least 14 daily backups; in addition, weekly and monthly backups in accordance with the Restic retention scheme in force at the time.
  • Backups are encrypted with Restic.
  • Backups are kept in S3-compatible object storage separate from the primary production environment.
  • Access to backups is protected with separate permissions and credentials.
  • Recovery procedures are reviewed to an appropriate extent.
  • Backups do not replace any statutory archiving obligation of the Client.

8. Protection against malware

  • Technical restriction of permitted file types and file sizes, where provided for.
  • Malware/virus scanning of uploads, where provided for in the respective process.
  • Regular security updates and patch management.
  • Reduction of unnecessary publicly reachable services.

9. Application security and development

  • Versioned source code management and controlled deployment processes.
  • Automated quality and security checks, where set up.
  • Separation of development/test and production environments, where operationally provided for.
  • Secrets and security-relevant configuration kept outside publicly accessible source code.
  • Prioritisation of bug fixes and security updates according to risk.

10. Privacy by default

  • Role-based visibility and data minimisation.
  • No general use of production customer data for development purposes.
  • Technical diagnostic and log data limited to the necessary extent.
  • Deletion and export processes after the end of the contract in accordance with the DPA.

11. Incident response

  • Recording, assessment and prioritisation of relevant security events.
  • Containment and technical remediation of identified incidents.
  • Documentation of significant measures and findings.
  • Informing the Client without delay of relevant personal data breaches in accordance with the DPA.

12. Sub-processors

  • Conclusion of the necessary data protection agreements.
  • Review of processing regions and transfer mechanisms.
  • Maintenance of an up-to-date list of sub-processors.
  • Disclosure of personal data only to the extent necessary.

13. Regular review

  • Review of administrative permissions.
  • Review of backup and recovery procedures.
  • Review of monitoring, patch level and security configurations.
  • Adjustment of the TOMs in the event of significant changes to the risk profile or the infrastructure.

Technical and Organisational Measures (TOMs) SmartShelf, Version 1.0, as of 31 August 2026. Provider: Rani Kais, Kais Solutions – see legal notice.

Custom software and digital solutions for businesses in Austria.

office@kaissolutions.at
ProductsSmartShelfQR TableStammioSnippetQuizSmart ContractsBurevo
Kais SolutionsServicesContactTermsLegal noticePrivacy
© 2026 Kais SolutionsOperator: Rani Kais · Vienna, Austria