Important: The German version of this document is legally binding under Austrian law, irrespective of the reader's jurisdiction (Versa Training GmbH is an Austrian company). This English version is an informational translation provided for convenience only. EU consumer protections of your country of residence apply regardless of this binding-language clause (Rome I Regulation, Art. 6(2)). In case of conflict between the German and English texts, the German text governs.
German version
This document describes the technical and organisational measures (TOMs) implemented by Versa Training GmbH to protect the personal data processed via the Versa Platform.
Versa implements the measures described below. The infrastructure providers and sub-processors used to do so are listed at app.versa.training/legal/subprocessors.
Pseudonymisation and Encryption
| Measure | Description |
|---|
| Encryption in transit | TLS 1.3 for all data in transit |
| Encryption at rest | AES-256 encryption for all stored data |
| Key management | Database encryption keys are managed by the infrastructure provider. API keys for AI providers are stored with restricted access (authorised personnel only). Service role keys are rotated upon infrastructure changes. |
| Pseudonymisation | Applied to data used for AI quality improvement; direct identifiers are stored separately from pseudonymised records |
Confidentiality
| Measure | Description |
|---|
| Access control | Role-Based Access Control (RBAC) on the principle of least privilege; access is reviewed quarterly |
| Authentication | Graduated access controls for administrative access; SSO/SAML support for customer organisations |
| Data separation | Row Level Security (RLS) on all database tables; per-organisation data separation via workspace-based policies with SECURITY DEFINER helper functions |
| Network security | WAF and DDoS mitigation at the deployment layer; HTTPS enforced on all endpoints |
| Endpoint security | Production database access restricted to the service role; direct database access limited to authorised personnel with audit logging |
| Personnel security | All employees, agents, and contractors are bound by documented confidentiality obligations pursuant to § 6 of the Austrian Data Protection Act (DSG); the obligation survives termination of the employment or contractual relationship |
| Security training | Mandatory data protection and security awareness training for all persons with access to personal data; training at onboarding and annually thereafter |
| Physical security | Delegated to the cloud infrastructure providers; data centres in use are ISO 27001-certified. |
Integrity
| Measure | Description |
|---|
| Change management | All code changes are subject to peer review and staged deployment |
| Development security | Security requirements are addressed in the design phase; automated static analysis in the CI/CD pipeline |
| Audit logging | System event logging and user activity audit logs; logs are protected against tampering |
| Monitoring and alerting | Automated monitoring of system health and security events; alerts on anomalous activity |
| Input validation | Validation of all data inputs at application level |
Availability and Resilience
| Measure | Description |
|---|
| Backup and recovery | Daily automated backups, retained for 30 days; recovery procedures tested at least annually; RPO target: 24 hours; RTO target: 4 hours |
| Business continuity | Documented disaster recovery procedures; reviewed and tested annually |
| Infrastructure | EU-hosted cloud infrastructure with built-in redundancy |
Testing and Evaluation
| Measure | Description |
|---|
| Vulnerability management | Automated dependency scanning; security patches applied within 30 days (critical: 7 days) |
| Security assessments | Annual security review of the platform and infrastructure; penetration testing by qualified third parties at least annually |
| Incident response | Documented incident response procedures with severity classification, escalation paths, and post-incident review; tested at least annually |
| Sub-processor assessment | Sub-processors are selected on the basis of their security posture; preference is given to providers with ISO 27001 or SOC 2 Type 2 certification |
Data Protection by Design and by Default
| Measure | Description |
|---|
| Data minimisation | Only the data necessary to provide the service are collected |
| Retention management | Data lifecycle management in accordance with agreed retention periods; deletion is ensured through automated processes and manual review |
| Privacy defaults | New features default to the minimum necessary data processing; additional processing requires explicit activation |
Questions? Contact privacy@versa.training