Annex to the Data Processing Addendum under Article 32 GDPR. These measures describe how KROK GROUP LTD (operating Fourmina) protects the personal data it processes on behalf of its business customers. We review and update them as the service evolves; changes never lower the overall level of protection.
Production systems run in professional data centres operated by our cloud hosting provider in the EU [to be completed: hosting provider and region]. Physical access to those facilities is controlled by the provider through perimeter security, access badges, visitor logging and CCTV. Fourmina staff have no physical access to production hardware. Our own premises hold no production data.
Personal data is encrypted in transit using TLS and at rest using industry-standard encryption provided by our hosting and storage infrastructure. Credentials and keys are stored in a secrets manager, not in code.
We collect only the data needed to run the customer's assistant. Conversation data is attributed to the customer account, not indexed by end-customer identity. Where full content is not needed - for analytics and quality metrics - we work with aggregated or pseudonymised data. Retention limits (see the Privacy Policy) delete conversation data when it is no longer needed.
Each customer's data is logically separated by customer identifier at the application and database level. Production and development environments are separate; production personal data is not used for development or testing.
Subprocessors are engaged only under a written data processing agreement imposing obligations equivalent to our DPA, including confidentiality and security requirements. We assess each subprocessor before engagement and keep the list current. The named list is available on request and customers are notified of changes in advance, as described in the DPA. [to be completed: named subprocessor list]
We maintain an incident response procedure: detect, contain, assess, remediate, document. If a personal data breach affects a customer's data, we notify that customer without undue delay after becoming aware of it, with the information the customer needs for its own notification duties under Articles 33 and 34 GDPR. Incidents and remediation steps are logged.
Every person we authorise to process personal data - employees and contractors - is bound by a written confidentiality obligation before receiving access, and is instructed in data protection basics relevant to their role. The obligation survives the end of the engagement. See also the Verschwiegenheitserklärung for customers subject to professional secrecy.
We review these measures at least once a year and after any significant change to the service or infrastructure, and update this annex accordingly. The date above shows the current version.