Technical and organizational measures - TOM
Version: 2.1
Date: 4 August 2026
Entity: B2Brouter Global, S.L.
B2Brouter will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing, and the risks to the rights and freedoms of natural persons.
The measures described below may be updated during the term of the services, provided that they do not materially reduce the applicable level of security.
1. Security governance
Section titled “1. Security governance”B2Brouter maintains internal policies, procedures and controls designed to protect the confidentiality, integrity, availability and resilience of the systems and services used to process personal data.
Internal responsibilities for security, data protection, incident management and service continuity are assigned to the relevant B2Brouter teams.
2. Access control
Section titled “2. Access control”B2Brouter applies controls designed to limit access to systems, data and environments to authorised persons only and on the basis of legitimate needs related to the provision of the services.
These measures may include:
- user and permission management;
- privilege control;
- authentication using personal credentials;
- access reviews;
- revocation of access when it is no longer required;
- segregation of duties, where applicable.
3. Personnel confidentiality
Section titled “3. Personnel confidentiality”Personnel authorised to access personal data are subject to appropriate confidentiality obligations.
B2Brouter will take reasonable measures to raise awareness and train personnel involved in providing the services regarding their security and data protection obligations.
4. Communications security and encryption
Section titled “4. Communications security and encryption”B2Brouter uses measures designed to protect communications and data transmissions against unauthorised access, alteration or improper disclosure.
These measures protect communications and data transmissions through secure channels, certificates and protocols appropriate to the nature of the service.
5. Infrastructure and hosting security
Section titled “5. Infrastructure and hosting security”B2Brouter provides its services through its own infrastructure or that of specialised providers located in Germany and France, within the European Union, unless otherwise notified and the safeguards required by applicable law are adopted.
The infrastructure providers used by B2Brouter must be subject to appropriate contractual obligations regarding security, confidentiality and data protection.
The specific location of relevant infrastructure and providers will be identified in the list of sub-processors or applicable technical documentation.
6. Logical segregation
Section titled “6. Logical segregation”B2Brouter applies measures designed to maintain appropriate logical segregation between clients, users, environments, data and services in order to prevent unauthorised access or unauthorised processing.
7. Backups
Section titled “7. Backups”B2Brouter maintains backup procedures designed to preserve the availability and integrity of data and enable recovery following technical or physical incidents.
Backups are managed in accordance with defined internal procedures, with controls designed to protect information against loss, destruction, alteration or unauthorised access.
8. Continuity, recovery and resilience
Section titled “8. Continuity, recovery and resilience”B2Brouter maintains service continuity and incident recovery procedures designed to preserve the availability, integrity and resilience of systems and services.
These measures may include restoration procedures, monitoring, incident management, internal escalation and recovery following technical or physical incidents.
Specific recovery objectives, including RTO and RPO where applicable, will be established in the main agreement, SLA, specific terms or technical documentation applicable to the contracted service, provided that they have been expressly agreed with the Client.
9. Logging, traceability and monitoring
Section titled “9. Logging, traceability and monitoring”B2Brouter maintains technical records, logs, timestamps, activity evidence and monitoring mechanisms intended to ensure the security, traceability, operation, support and technical audit of the services.
Access is limited to authorised personnel, and retention is limited to the periods necessary for those purposes, in accordance with the documented retention periods applicable to each category of record.
10. Incident management
Section titled “10. Incident management”B2Brouter maintains procedures to identify, analyse, escalate, manage and resolve technical or security incidents that may affect the services.
Where an incident constitutes a personal data breach under the GDPR, this DPA will apply.
11. Vulnerability management
Section titled “11. Vulnerability management”B2Brouter implements measures designed to identify, assess and manage technical vulnerabilities that may affect the security of systems and services.
These measures may include technical reviews, updates, patches, monitoring, risk assessments and internal remediation procedures.
12. Secure development
Section titled “12. Secure development”B2Brouter will apply reasonable secure development, deployment and maintenance practices in relation to the services, taking into account the nature and complexity of the platform.
These practices may include change reviews, version control, separation of environments, testing, technical validation and deployment procedures.
13. Provider management
Section titled “13. Provider management”B2Brouter will assess and select providers and sub-processors taking into account reasonable criteria regarding security, confidentiality, availability, regulatory compliance and data protection.
Providers that process personal data on behalf of B2Brouter will be subject to appropriate contractual obligations under Article 28 of the GDPR when acting as sub-processors.
14. Testing, technical audits and penetration testing
Section titled “14. Testing, technical audits and penetration testing”Penetration tests, vulnerability scans, intrusive technical analyses or any testing of B2Brouter systems require B2Brouter’s prior written authorisation.
B2Brouter may establish technical conditions, time windows, scope limitations and coordination measures to prevent impacts on the availability, security, integrity or continuity of the services.
15. Updates to measures
Section titled “15. Updates to measures”B2Brouter may modify, replace or update the technical and organisational measures described in this Annex where necessary to reflect technical, legal, organisational or security changes.
Such updates will not materially reduce the level of protection applicable to the processing of personal data.