PostOmnia ← Back to the DPA Deutsch

Annex 1: Technical and organisational measures

Measures pursuant to Art. 32 GDPR, forming part of the Data Processing Agreement. Version 1.0, as of 2026-08-07. This describes the instance operated by Fade Media GmbH at https://postomnia.de.

1. Confidentiality

1.1 Physical access control

The application runs in a Hetzner Online GmbH data centre in Germany. Physical access, video surveillance, visitor logging and entry control are the data centre operator's responsibility and are certified to ISO/IEC 27001. No own hardware is operated.

1.2 System access control

1.3 Data access control

1.4 Separation control

Tenant separation is logical, based on the workspace reference on every resource. Production, test and development environments are separated; production data is not copied into test or development environments.

1.5 Pseudonymisation and encryption

2. Integrity

2.1 Transfer control

Transmission to social media platforms happens only for the accounts selected and content approved by the controller. Outbound fetches of external URLs (media import, previews) pass through an SSRF check that blocks access to internal network ranges. Data can be exported as JSON at any time; secrets are masked in the export.

2.2 Input control

Security-relevant actions are recorded in an audit log with timestamp, acting account and target object (logins, account connections, publications, deletions, billing changes, approvals). The log is visible to workspace administrators.

3. Availability and resilience

4. Procedures for regular review

5. Sub-processor control

Sub-processors are engaged only in accordance with § 7 of the DPA and are bound to an equivalent level of protection. The current list is in Annex 2; changes are announced 30 days in advance.

Version 1.0 · As of 2026-08-07