TLI S.A. / EasyBoard

Technical and Organizational Measures (TOMs)

Annex to the Data Processing Agreement pursuant to Article 32 GDPR
Version: 1.0
Date: March 2026
Document ID: EB-TOM-2026-001

This document describes the technical and organizational measures implemented by TLI S.A. ("the Processor") to ensure the security of personal data processed through the EasyBoard platform, in accordance with Article 32 of the GDPR.

1. Encryption

1.1 Encryption at Rest

1.2 Encryption in Transit

2. Access Control

2.1 Authentication

2.2 Authorization

2.3 Administrative Access

3. Data Minimization

4. Infrastructure Security

4.1 Hosting and Data Residency

Component Provider Location
Database (Firestore) Google Cloud / Firebase EU (europe-west1, Belgium)
File Storage Google Cloud Storage EU (europe-west1)
Web Hosting Netlify EU compute, global CDN
Serverless Functions Netlify Functions EU region

4.2 Network Security

5. Monitoring and Logging

6. Incident Response

6.1 Detection

6.2 Containment

6.3 Notification

6.4 Post-Incident Review

7. Business Continuity

8. Employee and Organizational Measures

9. Review and Updates

These technical and organizational measures are reviewed at least annually and updated as necessary to reflect changes in technology, threats, or regulatory requirements. The Controller will be notified of any material changes to these measures.