Security

Data protection is part of our contract and our daily routine.

We process your customer data as a processor under Art. 28 GDPR. The technical and organisational measures are set out in the DPA, and nobody works without data protection sign-off.

Art. 28
GDPR
data processing with TOMs in the DPA
100%
Sign-off before deployment
documented from a subject-matter, technical and data protection perspective
27001
ISO/IEC
information security, 2022 version
1
Data protection officer
appointed: Torsten Franz, lawyer
How it works

This is how we safeguard data protection in the project.

01

Conclude the DPA and TOMs

Before the start, we conclude the data processing agreement with the technical and organisational measures. Our data protection officer is the contact for your review.

02

Bind and train staff

All staff are bound to data confidentiality. Data protection is one of five training modules before sign-off.

03

Apply it every day

Customer data is only accessed after identification and consent. Documentation takes place in the system we agree with you.

In detail

Your data protection review will find complete documentation with us.

01 · In detail

Data processing under Art. 28 GDPR

You remain the controller, and we process on your instructions. The DPA governs purpose, scope and measures.

Certified

Audited against the standards that matter here.

Certificates of aLIVE Support S.R.L., issued by ISOTRANS, valid until 06.09.2027.

FAQ

Questions about data protection in the call centre.

Question not listed? We reply within one working day.

Yes, before every project start. The DPA under Art. 28 GDPR contains the technical and organisational measures. We are also happy to review your template.

Our appointed data protection officer is Torsten Franz, lawyer. He is the contact for your data protection officer and for reviews in the project.

Accounts are only granted after documented subject-matter, technical and data protection sign-off. During calls, data is only accessed after the caller has been identified and has consented. All staff are bound to data confidentiality.

Yes. Romania is an EU member, and the GDPR applies there directly, supplemented by Romanian Law No. 190/2018. The competent supervisory authority is the ANSPDCP. aLIVE Support S.R.L. is independently certified to ISO/IEC 27001:2022.

The aLIVE group has worked for more than ten years for statutory health insurance funds, Associations of Statutory Health Insurance Physicians (KV) and hospitals. We clarify the requirements for social data with you in the DPA. Under § 80 SGB X, a processor of social data may also be based in another EU member state such as Romania; we review the other conditions of the provision together with you. We support your data protection review with all the necessary documents.