Home / Technical and organisational measures (TOM)

Technical and organisational measures (TOM)

Annex 1 to the Data Processing Agreement (DPA)
Version 1.4 · Date: 14.09.2026

Traniva AG
Zimbergstrasse 11
8335 Hittnau
Switzerland
CHE-491.543.762


1. Purpose and Scope

This Annex describes the technical and organisational measures implemented by Traniva AG to protect personal data in connection with TAOM.AI and TAOM Process Studio.

The measures are intended, in particular, to ensure a level of protection appropriate to the respective risk with regard to

  • confidentiality,
  • integrity,
  • availability,
  • resilience,
  • traceability and
  • recoverability

of the data processed and the systems used.

The measures apply to the processing carried out by Traniva within the framework of the Data Processing Agreement (DPA).

The nature, scope and design of individual measures may vary depending on the TAOM version used, the licence tier, the technical configuration and individually agreed enterprise services.


2. Security Organisation and Responsibilities

Overall responsibility for the operation, information security and data protection of TAOM.AI and TAOM Process Studio lies with the management of Traniva AG.

There are designated contact persons and reporting channels for data protection, compliance and security matters.

Security and data protection incidents are assessed, documented and, where necessary, escalated in accordance with defined responsibilities.

Employees and other authorised persons are only involved in the processing of customer data in accordance with their roles and responsibilities.

Access to personal data is granted in accordance with the principles of need-to-know and least privilege.


3. Access and Infrastructure Security

The production infrastructure of TAOM Process Studio is operated by professional hosting and infrastructure service providers employed for this purpose.

The physical security of data centres, server rooms and technical infrastructure is ensured by the respective infrastructure operators.

Depending on the specific infrastructure, this includes, in particular, measures relating to:

  • physical access control,
  • infrastructure monitoring,
  • fire and environmental protection,
  • power supply and operational safety,
  • technical monitoring,
  • restricting access to authorised persons.

Traniva does not provide general direct physical access for customers to the production infrastructure.

The infrastructure providers and sub-processors currently employed are listed in TAOM’s current list of sub-processors.


4. Identity and access control

Access to TAOM Process Studio is granted via user-specific access rights and authorisations.

Access rights are granted in accordance with the intended role and function.

The measures implemented include, in particular:

  • individual user identities;
  • role- and function-based authorisations;
  • restriction of access to necessary functions and data;
  • separation of different user and work areas;
  • server-side processing of login credentials and technical access information;
  • restriction of administrative access;
  • revocation or adjustment of authorisations in the event of changes to access requirements.

Login credentials for connected systems are not transmitted to the user’s browser, provided they are stored for server-side integration.

Connected systems retain their own authorisation and access controls.

Technical integration with TAOM therefore does not automatically confer full access to the connected system.

Technical credentials for connected systems are held exclusively on the server side and are not made accessible to the user’s browser, even on request.


5. Client and workspace separation

Client data and workspaces are logically separated from one another.

Users are only granted access to the workspaces and content assigned to them or made available to them.

Under normal operating conditions, a customer is not permitted to access the workspaces or content of other customers.

Authorisation checks are carried out on the basis of the respective user’s identity, role and assignment.

This separation is also taken into account for functions that process data via integrations or AI services.

Responses sent back to the platform by external services – for example from the automation layer or from connected target systems – are authenticated before processing and assigned to the tenant and workspace they relate to. Responses without a valid assignment are not processed.


6. Protection of data transmission

Data is transmitted between users and TAOM Process Studio via encrypted communication channels.

This applies in particular to communication between the browser and the platform.

Encrypted transmission channels are also used when communicating with external technical services and integrations, provided this is supported by the respective service and technically feasible.

Access credentials and technical secrets for server-side integrations are not delivered to users as part of regular browser content.


7. Protection of stored data

Customer data stored in production is processed within the hosting and storage infrastructure provided for TAOM.

Access to stored data is restricted to authorised systems, services and individuals.

Security measures at the level of databases, file systems, storage services and infrastructure are partly provided by the hosting and infrastructure providers used.

Encryption and other security measures for stored data are implemented in accordance with the technical capabilities of the infrastructure in use.

Where specific security measures are provided by infrastructure or cloud providers, their technical and organisational security measures shall apply in addition.

Traniva does not guarantee any further encryption of specific stored data or databases, unless this has been expressly documented or individually agreed.


8. Logging and Traceability

TAOM Process Studio has functions for ensuring the traceability of relevant operations.

Depending on the function and configuration, the following information in particular may be documented:

  • User or executing agent;
  • Time of an operation;
  • Affected object;
  • Change or processing status;
  • Version;
  • Status;
  • Approval;
  • Involvement of an AI function;
  • technical events and security-related operations.

Logging serves, in particular, the purposes of traceability, fault analysis, security and the verification of changes.

The scope and retention period of technical logs depend on the respective purpose and the technical configuration.

The operational log is cleaned up automatically after a configurable period. The default is 30 days, adjustable between 0 and 365 days. Clean-up is performed automatically once the period has elapsed and can be verified in operation.


9. Integrity and Versioning

TAOM employs mechanisms that enable changes to relevant process and documentation objects to be traced.

These may include, in particular:

  • unique object identifiers;
  • versioning;
  • change information;
  • timestamps;
  • user or agent assignment;
  • approval information;
  • indication of AI involvement;
  • provenance information.

Where TAOM applies a provenance or verification seal to documents, additional details such as document identifier, version, creation date and verification status may be used.

A QR code or verification function may be used to verify the associated document or provenance information.

These functions serve the purposes of traceability and integrity verification. They do not, in themselves, constitute an official, qualified electronic signature or regulatory certification, unless this is expressly stated.

Every model file generated by TAOM Process Studio carries a provenance seal. It is based on a cryptographic checksum of the file content in accordance with SHA-256. It allows verification of whether a file originates from this environment and whether it has been altered since it was generated. Verification is carried out through a dedicated interface; the underlying key material remains with Traniva.

Documents issued by TAOM – invoice, licence document, Data Processing Agreement and certificate – carry a document seal with document number and seal value together with a reference to a verification page on which authenticity and integrity can be confirmed.

Process steps receive an identifier assigned by the system which remains the same across processing runs and serves as the reference point for links into connected target systems. Once an identifier has been assigned, it can no longer be changed in the interface.

Contributions to a process element are attributed by means of a non-speaking identifier of the account concerned; it contains neither name nor address nor user name. Risks and controls – such as a four-eyes control – can also be recorded on the process element, so that requirement and evidence are kept on the same object.


10. Data Backup and Recovery

Procedures for data backup and recovery are in place for the production TAOM infrastructure.

In particular, the backup and recovery mechanisms of the hosting and infrastructure environment used are utilised for this purpose.

These measures serve to restore the availability of data and systems following technical faults or data loss.

Backups are subject to access restrictions and are processed within the infrastructure designated for this purpose.

Deleted data may still be technically present until existing backup copies are overwritten or deleted as part of the regular schedule.

Backups are not used for regular operational processing, unless this is necessary for recovery.

Individual recovery objectives, guaranteed recovery times or special backup requirements apply only insofar as they have been expressly agreed in a contract.


11. Network and System Security

The infrastructure used for TAOM is protected by technical safeguards against unauthorised network and system access.

Depending on the specific infrastructure, these include, in particular:

  • network access controls;
  • restriction of publicly accessible services;
  • technical protection mechanisms of the hosting infrastructure;
  • monitoring of system operations;
  • separation of different system and access levels;
  • security-related configuration of the services used.

Infrastructure-related security measures may, in some cases, be provided by the hosting and cloud providers used.


12. Software, Update and Change Management

Changes to TAOM Process Studio are implemented into the platform in a controlled manner.

Security-related updates and identified technical faults are assessed and addressed according to their significance.

Changes to production functions are made in such a way that data protection and security requirements are taken into account.

Technical and organisational measures are reviewed and, where necessary, adapted in the event of significant changes to the platform, infrastructure or risk situation.


13. Data protection through design and privacy-friendly default settings

TAOM takes into account the principles of Privacy by Design and Privacy by Default in the design and further development of the platform.

These include, in particular:

  • restriction of processing to data necessary for the respective function;
  • role-based access rights;
  • separate workspaces;
  • controlled disclosure to connected services;
  • transparent labelling of AI functions;
  • Traceability of relevant processing operations;
  • Options for managing and deleting data in accordance with the respective function and configuration.

Within the scope of the intended functions, the customer determines which personal data they process in TAOM Process Studio.


14. AI services and external integrations

AI functions and external integrations are connected in a controlled manner via the interfaces provided for this purpose.

Only the data and contextual information required for the respective function are transmitted to the relevant service.

Technical access data for external services are managed on the server side and are not routinely transmitted to the user’s browser.

The external processors and processing locations used in each case are listed in the current list of sub-processors.

Where different models, providers, processing regions or storage configurations are offered, the settings agreed for the relevant licence or Enterprise configuration shall apply.

Features such as Zero Data Retention, a specific processing region or a specific model provider are only deemed to be guaranteed if they have been expressly documented or contractually agreed for the configuration in question.

Where an Enterprise ZDR configuration has been agreed, technical availability is examined before commissioning for the model provider actually used, for the models and API endpoints employed and for the agreed processing region. The configuration applicable to the customer is recorded in the contract or system documentation.


15. Sub-processors and Supplier Control

Sub-processors are selected in accordance with their function and the data processing associated with their activities.

Where a service provider processes personal data on behalf of Traniva, the necessary data protection agreements shall be concluded.

The following factors shall be taken into account in particular when selecting and utilising such providers:

  • the purpose and scope of the processing;
  • the nature of the data processed;
  • the location of the processing;
  • the legal basis for data protection;
  • technical and organisational security measures;
  • any necessary safeguards for international data transfers.

Traniva maintains and updates a publicly available list of the sub-processors it uses.

Changes are made in accordance with the procedure described in the DPA.


16. Erasure and retention

Personal customer data shall not be processed for longer than is necessary for the agreed purposes, the performance of the contract or to comply with legal requirements.

The specific retention period may depend on the licence level, workspace type and technical configuration.

Shorter retention periods may apply to demo and test accounts.

Licensed customer data is not automatically deleted without a valid reason or in accordance with a defined rule.

Following termination of the contract, the deletion and return procedures set out in the General Terms and Conditions (AVV)/Data Processing Agreement (DPA) and the main contract shall apply.

Data in backup copies is deleted or overwritten as part of the regular backup lifecycle.

Workspace retention is configured per type of use: demo workspaces are removed after 7 days, web user workspaces after 90 days; both values are adjustable. Workspaces, operational log and expired accounts are subject to jointly controlled retention.


17. Security and Data Protection Incidents

Traniva maintains an organisational reporting and escalation process for security and data protection incidents.

Once an incident has come to light, it is, depending on its nature and potential impact:

  1. recorded and documented,
  2. assessed,
  3. contained through technical or organisational measures,
  4. investigated,
  5. rectified where possible,
  6. assessed with regard to necessary follow-up and preventive measures.

If a data security breach affects personal data that Traniva processes on behalf of a customer, the customer shall be informed in accordance with the DPA and the applicable legal requirements.


18. Confidentiality and organisational measures

Persons with authorised access to customers’ personal data are bound by confidentiality obligations or are subject to corresponding statutory or contractual confidentiality obligations.

Access is restricted to those persons and systems necessary for the task in question.

Data protection and security requirements are taken into account in organisational and technical decisions.

Responsibilities and points of contact for data protection, compliance and security matters are defined.


19. Risk assessment and effectiveness monitoring

Traniva reviews the technical and organisational measures on a regular basis and as and when necessary.

An ad hoc review takes place in particular in the event of:

  • significant changes to the TAOM architecture;
  • the introduction of new relevant service providers or integrations;
  • significant changes to data processing;
  • security or data protection incidents;
  • significant new threats or vulnerabilities;
  • relevant changes to legal requirements.

Identified risks and necessary measures are assessed and addressed in accordance with their significance.


20. Data locations and infrastructure

TAOM’s primary platform, database, file, backup and email infrastructure is operated in accordance with the current system architecture and the information provided in the TAOM Trust Centre.

Where external services, automation platforms or AI providers are used, data may be transferred to their documented processing locations for the respective function.

The current providers, purposes and processing locations are documented in the TAOM list of sub-processors.

Enterprise customers may use different infrastructure, provider or processing models, depending on the contractually agreed configuration.

In regular operation three legal areas are involved: Switzerland for platform, database and file operations, Germany for the automation layer, and the United States for processing by the language model. Without an agent run the content does not leave Switzerland.


21. Further development of measures

The technical and organisational measures described in this document constitute the security framework applicable as at the specified version date.

Traniva may replace individual measures with technically or organisationally equivalent or superior measures and further develop the security architecture in line with technical developments.

This must not result in a significant reduction in the overall agreed level of protection.

Significant changes shall be documented in accordance with contractual and statutory requirements.

Each version of this annex carries a version number and a date. What has changed or improved with a version is recorded per version as release notes.

The release notes for TAOM and for this annex are available to customers in their login area, without a separate request. They are maintained at Traniva through a dedicated area in the administration section of Process Studio.


22. Relationship to other documents

These TOM constitute Annex 1 to the TAOM Process Studio Data Processing Agreement (DPA).

Supplementary information on the current technical architecture, sub-processors, data locations, AI providers and security measures may be provided, in particular, in the TAOM Trust Centre, in the compliance and governance documentation and in the list of sub-processors.

In the event of any inconsistencies, the DPA and any contract provisions expressly agreed upon individually shall take precedence.


Document version

Document: TAOM Process Studio – Technical and Organisational Measures
Document type: Annex 1 to the DPA
Version: 1.3
Date: 14.09.2026
Publisher: Traniva AG
CHE: CHE-491.543.762


Related documents