Technical and organisational measures
The measures under Art. 32 GDPR for the Torch platform. Last updated: 22 September 2026 · TORCHTECHNOLOGY LTD
1. Status, scope and structure
Last updated: 22 September 2026. The version published on this page is always the authoritative one; it is available at any time and is revised whenever our processing changes.
This document sets out the technical and organisational measures with which TORCHTECHNOLOGY LTD ensures the security of processing under Art. 32 GDPR. It applies to the Torch platform and to every product delivered through it, and it forms an annex to our Art. 28 GDPR data processing agreement.
Its contractual basis is § 20.5 of our terms. Purposes, legal bases, recipients and storage periods are set out in the privacy policy; that is where they belong, not in a list of measures.
We describe each measure by its nature and effect and deliberately name no individual system, configuration or access path. That restraint is itself a protective measure.
The structure follows the categories a review expects: confidentiality, integrity, availability and resilience, procedures for regular review, and control of processing on instructions.
2. Confidentiality — physical access control
We operate no data centres of our own. Processing takes place exclusively in the data centres of specialised providers that we have engaged as processors under Art. 28 GDPR. The physical security of those sites — building security, admission rights, monitoring — is governed by the contracts we hold with them.
The processing locations are fixed by contract, not left to chance: database, authentication and file storage in an EU region in Frankfurt am Main, the application services including server logs in an EU region in Amsterdam (Privacy § 3 and 9).
Customer data and results are processed exclusively within those services and are not moved onto local media for storage.
3. Confidentiality — system access control
Using the services requires an account. An account may only be used by the authorised person or organisation; user seats are personal and may not be shared between several people. The customer is responsible for the users it creates as it is for its own conduct (Terms § 3.3 and 3.5).
Sign-in and session handling are provided by a processor whose instances are pinned to an EU region in Frankfurt am Main (Privacy § 9).
Credentials must be kept confidential and protected against third-party access; any unauthorised use must be reported to us without delay (Terms § 3.4).
Circumventing or defeating security measures and access controls is contractually prohibited (Terms § 16.3). We respond to breaches in proportionate steps — from notice, through the suspension of individual functions, to suspension of the account; the customer is informed in text form with reasons and given the opportunity to comment (Terms § 16.5 and 16.6).
4. Confidentiality — data access control
We process inputs and results solely for the purposes exhaustively named in the contract: delivering the services, generating the results, keeping the platform running, fixing faults and meeting legal obligations (Terms § 13.2).
Inputs and results are never used to train general AI models — ours or anyone else's. Our AI processors have given us the same commitment contractually (Terms § 13.3, Privacy § 9).
To improve the service we evaluate aggregated usage statistics only, with no link to a person or a customer (Terms § 13.3).
Both parties are bound to confidentiality. The obligation expressly covers security information and applies for the term of the contract and five years beyond it (Terms § 15.5).
We do not sell personal data and we do not use customer content for advertising (Privacy § 9). We name a customer as a reference only with prior consent in text form (Terms § 14.2).
5. Confidentiality — separation control
Customer content is assigned to the account and workspace of the respective customer and processed within that scope (Privacy § 9).
Processing for different purposes stays separate. Our website analytics run without cookies, store no personal data, process exclusively on servers inside the EU and are never combined with customer content (Privacy § 7 and 8). Server logs are likewise not combined with other data sources (Privacy § 3).
Special categories of personal data within the meaning of Art. 9 GDPR are excluded from processing unless separately agreed in advance (Terms § 20.4).
6. Integrity — transmission control
Every connection to our website and to the applications is encrypted in transit (TLS). Browsers are additionally instructed to call our domain, including all subdomains, over encrypted connections only (Privacy § 12).
Delivery is protected by security headers: against embedding our pages in third-party websites, against misinterpretation of content types, and against passing full address information to third parties. Camera, microphone and location access are switched off for our pages.
Customer data is processed and stored on infrastructure inside the European Union. Transfers to third countries take place solely on the basis of an adequacy decision or appropriate safeguards within the meaning of Art. 44 et seq. GDPR (Terms § 20.2).
For text and image generation, the content required for it is transferred to AI processors in the United States. The basis is the EU Standard Contractual Clauses; prompt content is not retained by default and storage is bounded by the contract term (Privacy § 9).
Full card or bank details never reach us; payments are handled by a payment service provider established in the European Union (Privacy § 6).
7. Integrity — input control
Processing inputs and results in order to detect, investigate, prevent and document abuse, security incidents and legal violations is established in the contract as a separate, delimited purpose. It ends when the statutory retention and limitation periods expire and expressly excludes any training of general AI models (Terms § 14.6).
Website requests are recorded in server logs: browser type and version, operating system, referrer URL, host name of the requesting device, time of the request and IP address. The logs arise in the EU region in Amsterdam, are technically required to deliver the site and are not combined with other data sources (Privacy § 3).
For every version our AI systems produce, a provenance record is stored that identifies the content as AI-generated. A human always decides what gets published (Privacy § 13).
Where there are concrete indications of a legal violation, we may block or remove the content concerned; we inform the customer without delay unless legal obligations prevent it (Terms § 13.5).
8. Availability and resilience
We provide the platform with 99.0 % availability on a monthly average. Announced maintenance windows, periods of force majeure and faults within the customer's own sphere do not count as downtime (Terms § 17.1).
Planned maintenance is carried out in low-usage periods wherever possible and announced with reasonable notice in the application or by email. Measures that cannot be deferred in order to maintain operational and data security may be carried out without prior notice (Terms § 17.2).
Backup and restoration are established in the contract as a separate processing purpose (Terms § 14.6).
Safeguarding the confidentiality and security of the data the customer stores, and observing the obligations under the data processing agreement, are identified as material contractual duties (Terms § 18.3).
Independently of this, the customer remains required to back up data important to it outside the platform as well (Terms § 18.6).
9. Procedures for regular review, assessment and evaluation
For reports of vulnerabilities we operate a published reporting channel, registered under RFC 9116 at /.well-known/security.txt. We acknowledge every report within five business days and keep the reporter informed until the issue is fixed; the scope and rules of the process are set out on our security and privacy page.
We maintain the list of our processors with an as-of date and update it as soon as a provider is added or replaced (Privacy § 11).
Changes to the services that follow from IT security requirements are expressly provided for in the contract and are made at no additional cost to the customer (Terms § 17.4).
This overview of measures is revised whenever our processing or the processors we engage change; the date at the head of this page identifies the version in force.
For the current status of independent audits and certifications, see our security and privacy page. We answer security questionnaires directly and in full.
10. Control of processing on instructions
Where we process personal data on behalf of our customers, the data processing agreement we provide under Art. 28 GDPR becomes part of the contract automatically on conclusion. It sits in the account and is provided as a document with the order confirmation; a signed version is available on request (Terms § 20.3).
The data processing agreement takes precedence over the terms in matters of processing personal data on instructions. The controller's rights to issue instructions, to information and to audit, as well as the obligations in the event of a personal data breach, are governed by that agreement (Terms § 20.3).
We engage sub-processors only under a flow-down of the obligations that bind us. The full list, with processing country and transfer safeguard, is in § 11 of the privacy policy; business customers receive the data processing agreement including those flow-down terms on request.
The controller is responsible for the lawfulness of transferring personal data to us and for the existence of a legal basis (Terms § 20.4).
11. Deletion, return and retention
After the contract ends, inputs and results remain available for export in a common format for 30 days. Once that period expires, the data is deleted in accordance with our privacy policy and statutory retention obligations (Terms § 19.5).
The processing right that survives the end of the contract is limited exhaustively to operation and backup, the defence and documentation of security incidents, compliance with legal obligations and the defence of legal claims. It ends when the statutory retention and limitation periods expire (Terms § 14.6).
We give effect to data subjects' rights of access, rectification, erasure, restriction, portability and objection in accordance with the privacy policy (Privacy § 14).
12. Contact
Data processing agreement, security questionnaires and questions about these measures: hello@torchtechnology.de.
Vulnerability reports: hello@torchtechnology.de. The process is described on our security and privacy page.
TORCHTECHNOLOGY LTD, 25 Martiou 27, D. Michael Tower, Flat/Office 105A, Egkomi, 2408 Nicosia, Republic of Cyprus. Company registration number HE 496008.