branchly®
Book demo

Technical and Organizational Measures

Preamble

branchly GmbH, Am Kartoffelgarten 14, 81671 Munich ("branchly"), hereinafter also referred to as "branchly", implements the following technical and organizational measures for data security within the meaning of Art. 32 GDPR:

1. Confidentiality

Physical Access Control

Measures in data centers: The platform infrastructure is operated in the data centers of Microsoft Azure (Frankfurt (Germany West Central, Amsterdam (Europe West) and Gävle/Sandviken (Sweden Central)) and OVH Cloud (Frankfurt). Access is strictly regulated. Only persons who require physical access for operational reasons have access. Access rights are regularly reviewed based on this criterion, and rights are revoked immediately if necessary. External visitors do not have access to the data center; however, the security of the facilities is certified by external auditors. The facilities are monitored 24/7 by video surveillance and secured with alarm systems. Security personnel are carefully selected and on-site at all times. Access to the data center is restricted by biometric access barriers. All data centers used are operated by certified operators (including ISO 27001).

Measures at company headquarters: Access is regulated. Visitors do not have direct access without an escort. Employees have access via keys. The issuance of keys is regulated and logged. Cleaning personnel have been carefully selected.

System Access Control 

Access to data and systems is granted according to the "principle of least privilege": Employees only have access to information, data, and systems that they strictly need to perform their work. This is ensured by management only assigning access to systems and permissions within systems if they are necessary for performing the tasks. This assessment is made on a case-by-case basis. The granting and revoking of permissions are logged by our management personnel. Permissions are re-evaluated when roles and responsibilities change.

Access to systems is generally granted via personalized accounts with username and password; sharing accounts ("account sharing") is not permitted. Password requirements (including minimum length of 20 characters) are technically enforced. Passwords must be changed regularly (every 90 days); this is technically mandated through the use of a password management system. Through IT security training, which takes place upon employee onboarding and at regular intervals, employees are instructed to choose secure passwords so that attacks using dictionaries can be minimized.

Additionally, multi-factor authentication (MFA) is used wherever the respective service or system environment supports it, particularly for administrative access, cloud management portals, and development environments.

All relevant systems incl. notebooks are encrypted with a strong password (minimum 20 characters, changed at least every 90 days, protection against dictionary attacks). Mobile storage media are likewise encrypted. Regular security checks (including for viruses and malware)
are carried out.

Remote access to security-relevant systems can only take place via VPN access.

Various systems and measures such as firewalls, restrictive permission management, encryption, threat detection software, and intrusion detection systems are deployed in the cloud to prevent third-party access to the servers.

Through IT security training (upon employee onboarding and at regular intervals), employees are instructed to set up an automatic screen lock and to manually lock their screen when leaving their workstation.

Data Access Control

Access to data and systems is granted according to the "principle of least privilege": Employees only have access to information, data, and systems that they strictly need to perform their work. This minimizes the number of authorized access users and administrators in each system. The granting and revoking of permissions are logged by management personnel. Permissions are re-evaluated when roles and responsibilities change.

Access to local systems as well as access to cloud servers is logged. Storage media are generally managed by our certified cloud providers. Storage media managed by us that are no longer in use are securely destroyed by an external service provider. No analog documents are generated during operational activities.

Separation

Customer data and all other data are completely isolated systematically. Within the customer database, technical methods such as "tagging" prevent cross-access (from customers with access to the system to data of other customers).

Development, testing, and production environments are completely isolated from each other through the use of separate environments with dedicated resources.

Pseudonymization & Encryption

All data is encrypted in transit using state-of-the-art encryption technologies (HTTPS, SSL/TLS). All data assets stored with Microsoft Azure/OVH Cloud are encrypted at rest ("Encryption at Rest"). All backup copies are likewise encrypted to ensure data security. Logged IP addresses are anonymized.

Production data (personal data from platform operations) is not exchanged via email; email is used exclusively for organizational communication.

2. Integrity

Input Control

Through targeted user role assignment, it can be traced which users have the ability to enter, modify, or delete personal data. Configuration changes in the platform (e.g., dashboard configurations) are recorded with a logging history:
For each entry, it is documented who created or last updated it and when (creation and modification history with user and timestamp).

Corrections, deletions, and restrictions of personal data are implemented without undue delay upon the client's instructions.

Access to local systems and cloud servers is logged. Application operations are conducted with centralized logging via an observability platform; critical and security-relevant events are logged and monitored during ongoing operations. Protocol and log data are deleted after 30 days.

Transfer Control

All data is transmitted in digitally encrypted transit following modern security standards (HTTPS, SSL/TLS). Physical data transfer does not take place, as this is a purely digital solution.

Upon instruction of the controller, the data processed on their behalf (e.g., conversations, session and analytics data) can be exported by branchly employees and provided in a structured, machine-readable format (e.g., JSON/CSV). This supports the controller in fulfilling data subjects' right to data portability (Art. 20 GDPR) as well as in the return of data records.

Upon termination of the contract, all accounts assigned to the client and all associated data are deleted from the systems. Upon client request, this can be confirmed in writing by branchly.

3. Availability and Resilience

Redundant server systems in different geographic locations (so-called availability zones) ensure high availability. Server rooms are air-conditioned and equipped with fire and smoke detection systems, temperature and humidity sensors, and fire extinguishers. An uninterruptible power supply (UPS) is also in place. Access to server rooms is video-monitored and alarm-protected.

All systems and databases have a redundant architecture to prevent data loss. Regular data backups both in the cloud and locally form the basis for rapid data recovery in the unlikely event of a complete system failure. Cloud backups are performed automatically on a daily basis. All backups are stored encrypted and retained for 30 days.

An IT emergency plan is in place.

4. Data Minimization and Deletion Periods

No more personal data is collected than is necessary for the respective purpose (data minimization, Art. 5(1)(c) GDPR). By default, the platform is configured so that only data required for operations is processed (data protection by default, Art. 25(2) GDPR).

The following periods apply to the deletion of personal data:

Upon termination of the contractual relationship, deletion takes place in accordance with Section 2 (Transfer Control).

5. Subcontractors and International Data Transfers

Carefully selected, externally certified sub-service providers who come into contact with personal data in the course of service delivery are contractually bound by data processing agreements (Art. 28 GDPR). The infrastructure is operated on the Microsoft Azure cloud platform (Frankfurt (Germany West Central) and Amsterdam (Europe West); certified according to ISO 27001) as well as OVH Cloud (cluster, infrastructure, and databases). Optionally, Google Cloud EMEA Limited services are used exclusively in EU regions for running AI models.

For services with a connection to third countries, the requirements of Chapter V GDPR are met: EU Standard Contractual Clauses (SCCs) were directly concluded with Clerk Inc. (management of user accounts for customer employees, USA). Cloudflare, Inc. (provision of static content via the content delivery network, USA) and Microsoft are certified under the EU-U.S. Data Privacy Framework (DPF). Google Cloud processes exclusively in EU regions; any technical or operational access by the US parent company is secured through the DPF and EU Standard Contractual Clauses.

The current list of subcontractors can be viewed at branchly.io/subunternehmer and is updated on an ongoing basis.

6. Procedures for Regular Review, Assessment, and Evaluation

Employees are contractually bound to handle personal data with care.

An internal Data Protection Officer (Mr. Markus Linnenberg, Auerfeldstraße 18, 81541 Munich, Email: datenschutz@branchly.io) has been appointed.

Subcontractors are selected under due diligence criteria (especially regarding data protection and data security). A Data Processing Agreement is concluded with each subcontractor.

These technical and organizational measures are regularly reviewed, evaluated, and updated – at least annually and in the event of significant changes to processing – to ensure their effectiveness (Art. 32(1)(d), Art. 25(1) GDPR).