We implement appropriate technical and organisational measures (access management, encryption, logging, backup, training, contractual confidentiality). We require a comparable level of protection from processors according to Articles 28 and 32 GDPR. We require contractual processors to provide a list of their processors if their processor is a sub-processor of personal data provided by our company to the processor.