Security Measures:
All stored and transmitted data is encrypted with at least AES 256-bit, unless otherwise required by the data controller in specific situations.
Personal data transmitted over established connections with the data controller is done exclusively via an SSL-encrypted connection.
Pseudonymization is applied to the extent required by the data controller, according to the specification of the desired application and/or development.
The requirements for ensuring continuous confidentiality, integrity, availability, and resilience are met through compliance with recognized information security standards such as the D-Mærket. All data will be processed in accordance with implemented policies and procedures.
The data controller determines the requirements for maintaining continuous confidentiality, integrity, availability, and resilience in relation to the desired application development or similar projects. The data processor will always provide guidance on this matter.
The data processor performs the processing described in the main agreement/contract or in Annex D, ensuring the restoration of accessibility and access in case of a physical or technical incident.
Coignite undergoes a D-Mærket audit and communicates the results to the data controller to evaluate the effectiveness of the technical and organizational security measures in place.
Internet access to data is granted based on the requirements of the data controller and is documented in the specification approved by the customer. The data processor accesses information only via SSL-encrypted connections.
Personal data in transit is encrypted with at least AES 256-bit.
Personal data in storage is encrypted with at least AES 256-bit.
No physical data is processed at physical locations. Data is processed exclusively at the data processor’s address or other locations via encrypted VPN connections.
The physical security at the data processor's location is ensured by key locks.
Home workstations must meet the same security requirements as office workstations.
All activities related to the processing of personal data are logged.