Technical and Organisational Measures (TOMs)
The security measures we implement pursuant to Art. 32 GDPR.
Version 1.0 · Last updated: 30 June 2026
This document describes the technical and organisational measures ("TOMs") implemented by LeadJourney Ltd. ("Processor") to ensure a level of security appropriate to the risk of processing personal data pursuant to Art. 32 GDPR. These measures apply to all personal data processed by LeadJourney on behalf of its customers ("Controllers") under the Data Processing Agreement ("DPA").
LeadJourney regularly reviews and updates these measures to reflect changes in technology, threats, and applicable law.
1. Infrastructure & hosting
All personal data processed under the DPA is hosted exclusively within the European Economic Area (EEA):
- Cloud infrastructure: DigitalOcean, LLC in Frankfurt, Germany (FRA1 region)
- All production data remains within the EU at all times, with no default transfers to third countries
- Infrastructure is provisioned and managed via infrastructure-as-code (IaC) to ensure consistent, auditable configuration
- DigitalOcean maintains SOC 2 Type II attestation and ISO 27001 certification for its Frankfurt data centres
- Physical access to data centre facilities is controlled by DigitalOcean under industry-standard physical security protocols including biometric access, 24/7 CCTV monitoring, and on-site security personnel
2. Encryption of personal data
LeadJourney applies encryption at all stages of data processing:
- At rest: All personal data stored in LeadJourney databases and file storage is encrypted using AES-256 bit encryption.
- In transit: All data transmitted between clients and LeadJourney servers, and between internal services, is protected using Transport Layer Security (TLS 1.2 or higher). Unencrypted connections are rejected.
- Webhook payloads: Outbound webhook events are signed using HMAC (Hash-based Message Authentication Code) to ensure authenticity and integrity. Recipients can verify that payloads originate from LeadJourney and have not been tampered with.
- Backup encryption: Database backups are encrypted at rest using AES-256 and stored within the EEA.
3. Access control & authentication
Access to personal data is strictly controlled on the basis of the least-privilege and need-to-know principles:
- Role-based access control (RBAC) is implemented across all systems; each employee and service account is granted only the minimum permissions necessary for their role
- Two-factor authentication (2FA) is mandatory for all staff accessing production systems and the LeadJourney application
- Customer data is logically separated at the database level; no customer can access another customer’s data
- Access to production databases and infrastructure requires authentication through a secure, audited access mechanism; direct database access is prohibited for standard operations
- All access attempts, successful and unsuccessful, are logged and retained for audit purposes
- Access rights are reviewed regularly and revoked immediately upon termination of employment or change of role
- Shared or generic accounts are not permitted; each individual has a unique, identifiable account
4. Pseudonymisation & data minimisation
- LeadJourney’s server-side tracking architecture is designed to minimise the collection of personal data at the point of ingestion; only data explicitly configured by the Controller is collected
- Visitor identifiers (click IDs, session tokens) are hashed and pseudonymised where technically feasible, reducing re-identification risk
- IP addresses are processed server-side and are not stored in plain text in analytics reports
- Personal data is not collected or retained beyond what is necessary for the purposes configured by the Controller
5. Availability, resilience & recovery
LeadJourney maintains measures to ensure the ongoing availability and resilience of its processing systems:
- Infrastructure is deployed across multiple DigitalOcean availability zones within the Frankfurt region to ensure redundancy
- Automated database backups are performed on a regular schedule and retained within the EEA; backup integrity is tested periodically
- Monitoring and alerting systems operate 24/7; automated alerts are triggered for infrastructure anomalies, error spikes, or availability issues
- Application error monitoring and log management is provided by Better Stack s.r.o. (Czech Republic, EU), which captures real-time error events without storing full personal data payloads
- Recovery procedures are documented and tested to ensure the ability to restore availability and access to personal data in a timely manner following a physical or technical incident
- Business continuity plans are maintained and reviewed annually
6. System integrity, logging & monitoring
- All significant system events, including data access, modifications, deletions, authentication attempts, and administrative actions, are recorded in immutable audit logs
- Logs are retained for a minimum of 90 days and are accessible for security review and incident investigation
- System configurations are managed through version-controlled infrastructure-as-code; deviations from specified configurations are detected automatically
- Automated monitoring scans for anomalous activity, unauthorised access attempts, and service degradation continuously
- Separation of production and test environments is enforced; no real personal data is used in test or development environments without explicit anonymisation
7. Organisational measures & governance
- All employees with access to personal data receive data protection training at onboarding and at regular intervals thereafter
- All employees are bound by contractual confidentiality obligations that survive the termination of their employment
- A documented information security policy is in place; adherence is mandatory and subject to a formal disciplinary procedure
- A designated Data Protection Officer (Jonas Strambach, [email protected]) is responsible for overseeing compliance with data protection obligations
- Internal data processing activities are documented in a Record of Processing Activities (RoPA) maintained pursuant to Art. 30 GDPR
- Vendor assessments are conducted before engaging new sub-processors; sub-processors are required to maintain equivalent security standards
8. Sub-processor security
The transfer of personal data to sub-processors is only made where a corresponding Data Processing Agreement (DPA) or equivalent contractual instrument exists, and only for specified purposes. LeadJourney requires all sub-processors to:
- Implement technical and organisational measures equivalent to those described in this document
- Process personal data only on LeadJourney’s documented instructions
- Not engage further sub-processors without prior authorisation
Where personal data is transferred to sub-processors located outside the EEA (e.g. Stripe, Google, Mailtrap, Intercom, X Corp., Reddit), LeadJourney ensures adequate protection through Standard Contractual Clauses (SCCs) as adopted by the European Commission pursuant to Art. 46 GDPR, supplemented by transfer impact assessments where required.
9. Incident management & breach notification
- A documented incident response procedure is in place covering detection, containment, investigation, remediation, and notification
- All employees are required to report suspected security incidents immediately to the Data Protection Officer
- Personal data breaches are assessed without undue delay; where required under Art. 33/34 GDPR, the Controller is notified within 72 hours of the Processor becoming aware of the breach
- All personal data breaches are documented, including the facts, effects, and remedial action taken, regardless of whether notification to a supervisory authority is required
10. Data portability & erasure
- Upon the Controller’s written request, LeadJourney can export customer data in machine-readable formats (e.g. CSV, JSON) for portability
- Upon termination of the DPA or the Controller’s written request, all personal data is permanently deleted from active databases within 60 days
- Deletion is cascading: records deleted from active databases are removed from backup systems as backups are rotated per the data retention policy
- LeadJourney can provide written confirmation of deletion upon request
11. Regular testing & review
- Technical and organisational measures are reviewed at least annually, or following any significant change to infrastructure, processing activities, or applicable law
- Vulnerability scanning and security assessments are conducted on a regular basis
- Third-party penetration testing is performed periodically; findings are remediated according to severity
- The effectiveness of these measures is monitored continuously through automated tooling and periodic manual review
12. Summary of key measures
| Measure | Implementation |
|---|---|
| Hosting location | DigitalOcean FRA1, Frankfurt, Germany (EEA) |
| Encryption at rest | AES-256 bit encryption |
| Encryption in transit | TLS 1.2+ for all connections |
| Webhook integrity | HMAC-signed payloads |
| Access control | RBAC + least privilege + 2FA mandatory |
| Customer data separation | Logical separation at database level |
| Audit logging | All access and administrative actions logged |
| Availability | Multi-AZ deployment, automated backups, 24/7 monitoring |
| Error monitoring | Better Stack s.r.o. (Czech Republic, EU) |
| Breach notification | Within 72 hours of becoming aware |
| Data deletion | Within 60 days of contract end or request |
| Staff training | Onboarding + regular data protection training |
| DPO | Jonas Strambach, [email protected] |
| Sub-processor transfers | SCCs where outside EEA |
LeadJourney Ltd. · HE485008 · Artemidos 6, 6030 Larnaca, Cyprus · [email protected] · TOMs Version 1.0
Track every lead
With Pixel-Perfect Accuracy
Stop losing data to iOS, ad blockers and CRM gaps. Server-side tracking, built for lead generation — live in 21 minutes.

