Draft. This document is a working draft and is pending review by qualified counsel. It is not yet legal advice.
Annex 2 — Technical and organisational measures
Version 1.0 · 27 July 2026 (draft)
This page is part of our Data Processing Agreement. It describes the measures we implement to protect personal data processed on behalf of our customers, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. We may update them over time, provided the level of protection is not reduced.
Every measure listed here is one we apply today. Where a control is on our roadmap but not yet in place, it is absent from this page rather than described in the future tense.
1. Where we process, and encryption
- Your data is hosted in European Union regions. Our application, database, object storage and authentication all run in the EU.
- Some of the companies operating that infrastructure are established in the United States. Their parent company may therefore be subject to US law regardless of where the servers are. We say this plainly rather than imply otherwise: your data is hosted in the EU, and our infrastructure is not yet sovereign. Moving to a European-owned provider is on our roadmap. The transfer safeguards that apply are set out in our sub-processor list.
- All data in transit is encrypted using TLS.
- Data at rest is encrypted by our infrastructure provider using industry-standard algorithms.
- Secrets, API keys and credentials are held in a dedicated secret manager, never in source code, configuration files, logs, or any artefact a user can download, export or share.
2. Confidentiality of processing systems
- Access to production systems is restricted to authorised personnel who need it, and is protected by strong authentication.
- Every access decision is evaluated server-side against the resource owner. Authorisation is deny-by-default: a request that cannot be positively authorised is refused.
- Customer environments are isolated by organisation. Content, storage and usage records are keyed by organisation identifier, and cross-organisation access is structurally prevented rather than filtered after the fact.
- Requests for a resource the requester may not read return the same response as a resource that does not exist, so that identifiers cannot be enumerated.
- Personnel authorised to process personal data are bound by confidentiality obligations.
3. Integrity of processing systems
- Changes to the platform follow a documented change management process: every change is tracked, reviewed against our internal rules, and tested before deployment.
- Sensitive actions — access to or modification of secrets, changes to authorisation, deletion of data, deployments — produce attributable structured logs recording who did what and when. Logs never contain secrets.
- Input from users and from external services is validated server-side before processing.
4. Availability
- The platform runs on managed infrastructure with automatic scaling and health monitoring.
5. Testing and evaluation
- Dependencies are monitored for known vulnerabilities.
- Code is reviewed against a documented security checklist before being merged, covering injection, cross-site scripting, authentication, authorisation and cryptography.
6. Data minimisation and deletion
- We collect only the personal data required for the feature being used.
- You can delete your account and your content directly from the Service.
- On termination, data is deleted as described in section 11 of theData Processing Agreement.
7. Sub-processor management
- Our current sub-processors arepublished, with the country of processing and the transfer safeguard for each, and we give at least 30 days' notice before adding or replacing one.
- Each sub-processor is bound by a data processing agreement imposing obligations no less protective than those we owe you, except where the sub-processor list states otherwise on that provider's row.
8. Incident management
- We maintain a documented procedure for assessing and responding to personal data breaches, and we notify affected customerswithout undue delay of becoming aware of one, so that they can meet their own obligations towards their supervisory authority.
- Our notification states the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken, and a contact point — so that you can notify your authority without having to come back to us.
- Security incidents can be reported to contact@geonova.be.
9. Certifications
We build against the control frameworks of ISO/IEC 27001 and SOC 2. We do not currently hold either certification; obtaining them is on our roadmap.
Contact
For any question about these measures, or to report a security issue: contact@geonova.be. All our legal documents are listed on ourlegal page.