# Contractual Technical and Organisational Measures Last updated: 2026-09-16 This annex forms part of the DPA for savien's standard service. It describes the agreed measures without disclosing credentials or security-critical operational configurations. Individual additional requirements are agreed separately before the affected processing starts. ## 1. Access and Permissions - Individual user accounts with passwords and email verification through Supabase Auth; TOTP is available as an optional second factor. - Automatic application sign-out after 30 minutes of inactivity, with a warning two minutes beforehand. - Role- and organisation-based permissions; server-side user, organisation and permission checks for protected actions. - Database Row Level Security and storage permissions to separate customer organisations. Shared business transactions are accessible to the respective authorised trading partners. - Administrative keys and integration credentials are used server-side and are not delivered as public client configuration. Administrative access is restricted to necessary tasks. ## 2. Transmission and Storage - Encryption in transit for connections to the application and connected services. - Customer documents in private storage with permission checks. Deliberately published product images and logos are handled separately. - Supabase operates the database and file storage; Vercel provides hosting. Processing locations and transfer safeguards are described in the [Subprocessor List](/en/subprocessors). - Infrastructure operators provide physical data centre security and encryption at storage level. savien checks the settings and provider agreements required for its service. ## 3. Traceability and Data Minimisation - Recording of contract acceptances, exports and defined security-relevant actions; evidence is accessible only to authorised persons. - Invitation links are valid for seven days. Unaccepted invitations are scheduled for deletion one day after expiry. - Internal usage statistics contain normalised route patterns instead of object identifiers, no URL query parameters or fragments, and are deleted after 90 days. They fall under savien's own controllership as described in the Privacy Policy. - Public audience measurement loads only after consent. Customer content is not used for model training without a separate agreement. ## 4. Recovery, Deletion and Incidents We maintain backup and recovery procedures for the storage services used and review their effectiveness according to risk and after material changes. Specific recovery times (RTO), maximum data loss periods (RPO) or an availability percentage are not promised in the standard contract. Statutory security and recovery obligations remain unaffected. Binding customer-specific targets must be agreed before contract formation. Return, deletion, restriction of backup copies and their deletion no later than 90 days after the corresponding choice are governed by DPA section 13. Restored data is subject to previously issued deletion instructions again before the system is released. Security reports are received at security@savien.io, assessed and handled according to risk. Personal data breaches affecting customer data are notified to the customer without undue delay under the DPA. Confidentiality commitments, provider oversight, updates and permission reviews form part of the operational process. ## 5. Evidence and Contract Version This annex is stored together with the DPA. Questions about backup configuration, restore evidence, permission reviews and other operational evidence may be submitted to security@savien.io before contract formation. This annex does not promise external certification or a passed penetration test. Audit and information rights under the DPA remain unaffected.