Organisation: Audienzz AG Address: Falkenstrasse 11 | 8021 Zurich Product: adconsole Last updated: 25.06.2026 Validity: Until the next update; reviewed at least annually
This document describes the technical and operational measures used by Audienzz AG to protect personal data in the context of operating the adconsole platform. It applies uniformly to all clients and is referenced as Appendix 2 to the Data Processing Agreement (DPA).
The currently applicable version is binding. Clients will be proactively notified of any material changes; the level of protection described therein will not be reduced.
1. Confidentiality
pursuant to Art. 32(1)(b) GDPR
This section covers all measures ensuring that personal data is accessible only to authorised persons and is protected against unauthorised physical access, system access and data access.
1.1 Physical access control
Measures suitable for preventing unauthorised persons from gaining physical access to the data processing facilities used to process or use personal data. Suitable measures include automated access control systems, smart cards and transponders, reception/security guard services and alarm systems. Servers, telecommunications systems and network hardware are kept in lockable server cabinets. Supplementary organisational measures include a policy requiring offices to be locked when unattended.
Technical measures
Organisational measures
Alarm system
Automated access control system
Biometric access barrier
Badges / chip cards / transponder systems
Manual locking system
Security locks
Locking system with code lock
Doorbell system with camera
Video surveillance of entrances
Key management policy / key list
Reception / front desk / gatekeeper (NZZ)
Visitor log / visitor records (NZZ reception)
Employee / visitor ID badges
Visitors accompanied by employees
Due diligence in selecting security staff (NZZ reception)
Due diligence in selecting cleaning services (via NZZ)
1.2 System access control
Measures suitable for preventing data processing systems from being used by unauthorised persons. These include user authentication via passwords, password-protected screen savers, use of smart access cards and call-back procedures, as well as organisational rules on the positioning of screens and choice of secure passwords.
Technical measures
Organisational measures
Login with username + password
Login with biometric data
Multi-factor authentication (MFA) for access to personal data
Anti-virus / anti-malware software on servers, clients and mobile devices
Firewall
Intrusion detection systems
Partial use of VPN for remote access
Encryption of storage media
Smartphone encryption
Chassis locking
BIOS protection (separate password)
Blocking of external interfaces (USB)
Automatic desktop lock
Encryption of notebooks / tablets
Management of user permissions
Creation of user profiles
Centralised password assignment
“Secure password” policy (NZZ)
“Deletion / destruction” policy (NZZ)
“Clean desk” policy (NZZ)
General data protection and security policy (NZZ)
Mobile device policy
AI governance (NZZ)
1.3 Data access control
Measures ensuring that persons authorised to use a data processing system can access only the data covered by their access authorisation, and that personal data cannot be read, copied, altered or deleted without authorisation during processing, use or storage. Appropriate authorisation concepts enable differentiated control of access based on data content and access functions. The granting and withdrawal of access rights are documented and updated (when individuals join, change roles, leave). Particular attention is paid to the role of administrators.
Technical measures
Organisational measures
Document shredder (min. level 3, cross cut)
External document destruction service (DIN 32757)
Physical destruction of storage media
Logging of access to applications (entry, modification, deletion)
Traceability of changes to critical roles
Temporary access management with activity log
Use of authorisation concepts (role model)
Minimal number of administrators
Data protection safe
User rights administered by administrators
1.4 Separation control
Measures ensuring that data collected for different purposes can be processed separately. This can be achieved through logical and physical separation of the data.
Technical measures
Organisational measures
Separation of production and test environments
Physical separation (databases / storage media)
Dedicated instance per tenant
Separate virtual systems, sandboxing / containers
Control via authorisation concept
Definition of database rights
Records tagged with purpose attributes
1.5 Pseudonymisation
The processing of personal data in such a way that it can no longer be associated with a specific data subject without the use of additional information, providing such additional information is kept separately and is subject to appropriate technical and organisational measures.
Technical measures
Organisational measures
Where pseudonymisation is applied: separation of the mapping data and storage in a separate, secured and encrypted system
Internal instruction to anonymise / pseudonymise personal data where possible before disclosure or after statutory retention periods expire
2. Integrity
pursuant to Art. 32(1)(b) GDPR
Measures to ensure the integrity of personal data during electronic transmission, storage and processing.
2.1 Transmission control
Measures ensuring that personal data cannot be read, copied, altered or deleted without authorisation during electronic transmission, while in transit, or while stored on data storage media, and that it is possible to verify the parties to whom a transfer is intended. Confidentiality can be ensured through encryption and the use of a VPN, for example.
Technical measures
Organisational measures
Email encryption (S/MIME / PGP)
Email signing (S/MIME / PGP)
Use of VPN
Logging of access and retrievals
Secure transport containers
Provision via encrypted connections (SFTP, HTTPS)
WAF, DDoS and brute-force protection on exposed interfaces
Documentation of data recipients and of the planned duration of transfer or the retention periods
Overview of recurring retrieval and transmission processes
Disclosure in anonymised or pseudonymised form
Due diligence in selecting transport staff and vehicles
Personal handover with record
2.2 Input control
Measures ensuring that when personal data has been entered into, altered in or removed from data processing systems, it can subsequently be verified and established whether this has been done and by whom. Input control is achieved through logging at various levels (operating system, network, firewall, database, application).
Technical measures
Organisational measures
Technical logging of the entry, modification and deletion of data
Manual or automated review of logs
Provision of suitable log data for analysis by the controller
Overview of which programs can be used to enter, modify or delete which data
Traceability of entry, modification and deletion through individual user names (no shared accounts)
Granting of entry, modification and deletion rights based on an authorisation concept
Retention of forms from which data was transferred into automated processing
3. Availability and resilience
pursuant to Art. 32(1)(b) GDPR
3.1 Availability control
Measures ensuring that personal data is protected against accidental destruction or loss. Topics covered: uninterruptible power supply, climate control, fire protection, data backups, secure storage of data media, virus protection, RAID systems, disk mirroring.
Technical measures
Organisational measures
Storage in certified data centres (ISO/IEC 27001, EU/EEA – Hetzner)
Uninterruptible power supply (UPS)
Air conditioning / fire protection in the data centre
RAID systems / disk mirroring
Regular data backups, backup and restore processes tested
Data processing exclusively in Switzerland or an EU/EEA member state.
Tested restore at least annually
4. Process for regular review, assessment and evaluation
Process for regular review, assessment and evaluation
The following subsections describe data protection management, incident response management, privacy-friendly default settings and instruction control in the case of outsourcing to third parties.
4.1 Data protection management
Technical measures
Organisational measures
Data protection management software in use
Central documentation of all data protection procedures and policies, accessible to employees as needed / authorised (via NZZ)
Security certification per ISO 27001, BSI IT-Grundschutz or ISIS12
Alternative information security concept
Other documented security concept
Review of the effectiveness of the TOMs at least annually (audit report on request)
Internal / external data protection officer: Fabienne Genoud, NZZ
Employees trained on confidentiality / data secrecy (also beyond the end of employment)
Regular employee awareness training, at least annually
Internal / external information security officer
Data protection impact assessment (DPIA) carried out where required
Organisation complies with the information obligations under Art. 13 and 14 GDPR
Formalised process for handling data subject access requests
4.2 Incident response management
Support in responding to security breaches. Structured approach to handling security incidents and data breaches, with set procedures for detection, response, reporting and recovery.
Technical measures
Organisational measures
Firewall in use with regular updates
Spam filter in use with regular updates
Virus scanner in use with regular updates
Intrusion detection system (IDS)
Intrusion prevention system (IPS)
Continuous monitoring to detect attacks / data exfiltration
Immediate remediation of critical vulnerabilities (hotfix process)
Documented process for detecting and reporting security incidents / data breaches (including notification duties towards the supervisory authority)
Documented procedure for handling security incidents (NZZ)
Involvement of the DPO in security incidents and data breaches (NZZ)
Documentation of security incidents and data breaches via ticketing system
Formal process and responsibilities for the follow-up of security incidents
Emergency management aligned with international standards (ISO/IEC 27035, NIST SP 800-61)
Notification of the controller within 48 hours
4.3 Privacy-friendly default settings
Privacy by Design / Privacy by Default
Technische Massnahmen
Organisatorische Massnahmen
Es werden nicht mehr personenbezogene Daten erhoben, als für den jeweiligen Zweck erforderlich sind
Einfache Ausübung des Widerrufsrechts des Betroffenen durch technische Massnahmen
Datenminimierung als integraler Bestandteil von Entwicklungs- und Konfigurationsentscheidungen
4.4 Instruction control
Measures ensuring that personal data processed on behalf of the client can only be processed in accordance with the client’s instructions. This also covers maintenance and system administration, whether onsite or remote. Where Audienzz engages service providers as processors, the following points are agreed with them.
Technical measures
Organisational measures
Documented list of sub-processors in use (see annex)
Prior review of the security measures taken by the processor and their documentation
Selection of the processor with due diligence (in particular data protection and data security)
Conclusion of the required data processing agreement or EU standard contractual clauses
Written instructions to the processor
Obligation of the processor’s employees to maintain data secrecy
Obligation for the processor to appoint a data protection officer where required
Agreement on effective audit rights vis-à-vis the processor
Rules on the engagement of further sub-processors
Ensuring the destruction of data after the end of the engagement
For longer engagements: ongoing review of the processor and its level of protection
5. Appendices
List of sub-processors
Sub-processor
Service
Registered office
Place of processing
Transfer
Hetzner Online GmbH
Hosting
Germany
Germany EU
within the EU
Simbaze Development OÜ
Software development
Estonia EU
Estonia EU
within the EU
Anthropic, Inc.
AI inference Claude
USA San Francisco
USA
EU SCCModule 2
OpenAI, L.L.C.
AI inference GPT
USA San Francisco
USA or EU where the EU endpoint is enabled
EU SCCModule 2
Google Ireland Limited
AI inference Gemini / Vertex AI
Ireland EU · Dublin
EU europe-west4 / west3
EU-internalor SCC
SCC = EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module 2 – controller to processor.
Notes on AI processing: personal data processed using AI services is limited to the minimum required for the task in question. Where appropriate and practicable, the data is pseudonymised before transfer. Client data is not used by any of the service providers to train their models (contractually excluded).
For EU/Swiss clients subject to strict data residency requirements, EU-hosted endpoints (OpenAI eu.api.openai.com, Google Vertex AI europe-west4) are available, by arrangement.
Any extension of this list requires the client to be notified in advance and given the opportunity to object within 30 days.
6. Approval
This document has been approved by the responsible body and applies uniformly to all clients in the context of operating the adconsole platform.
7. Version history
Version 1.0 Initial version
Version 2.0 Addition of AI sub-processors: Anthropic (Claude), OpenAI (GPT), Google (Gemini / Vertex AI) - 25/6/2026