ANNEX 4 – Technical and Organizational Measures (TOMs)
Owner: CTO · Approver: CEO
ANNEX 4 – Technical and Organizational Measures (TOMs)
This annex describes the technical and organizational measures (TOMs) implemented by Lyyli AI Oy in processing personal data. The description is based on verifiable controls; it does not include measures that are not documented or in use.
Organizational Controls
TOM-ORG-01 – Security management: Risk-based security management model; annual review.
TOM-ORG-02 – Personnel: NDAs, onboarding, role-based access, security training.
TOM-ORG-03 – Vendor management: Subprocessor DPAs and list in Annex 5; audit rights per agreement.
TOM-ORG-04 – Privacy contact: Privacy matters: hello@lyyli.ai.
Technical Controls
TOM-TEC-01 – Encryption in transit: TLS for all customer traffic.
TOM-TEC-02 – Encryption at rest: Infrastructure provider (e.g., database, storage) encryption controls.
TOM-TEC-03 – Access control: SSO/IdP (Clerk), principle of least privilege, regular access reviews. MFA support is not currently enabled.
TOM-TEC-04 – Organizational isolation: Workspaces and customer data isolated at the organizational level.
TOM-TEC-05 – Logging: Application and audit logs; content actions traceable; retention 180 days (Annex 6).
TOM-TEC-06 – Vulnerabilities: Dependency scans in CI/CD pipeline; risk-based remediation.
TOM-TEC-07 – Backups: Daily encrypted backups; restore tests on a regular basis.
TOM-TEC-08 – Development: Code reviews, CI/CD checks, dev/test/prod environment separation.
TOM-TEC-09 – Network: Cloud provider network controls (firewalls, segmentation); DDoS protection via infrastructure service.
Data Location and Transfers
TOM-DAT-01: Primary application data for customer workspaces is stored in the EU region.
TOM-DAT-02: In some processing stages (AI APIs, authentication, email delivery) data may be processed outside the EU/EEA. International transfers use GDPR Chapter V safeguards (SCCs, EU–US DPF where applicable).
AI Data Processing
TOM-AI-01: Language models process requests under Zero Data Retention via Vercel AI Gateway. Model-specific regions are documented in the AI model register.
TOM-AI-02: Customer content is not used to train models. Gemini: Google Cloud Service Specific Terms + Cloud Data Processing Addendum.
TOM-AI-03: Allowlist of approved models and routes; new routes documented in the AI model register before production use.
TOM-AI-04: ZDR enforcement on all language-model routes in Vercel AI Gateway; data collection deny and prompt logging disabled at configuration level.
TOM-AI-05: Fallback provider blocking or restriction on critical routes; route-level logging for audit.
TOM-AI-06: Language-model processing region (EU or Global) is recorded in logs and auditable. Claude and Gemini inference is locked to the EU; GPT processing cannot currently be limited to the EU only.
Infrastructure regions
TOM-INFRA-01 (Supabase): Project AWS region eu-north-1 (Stockholm); support/logs/backups separated from primary customer storage.
TOM-INFRA-02 (Vercel hosting): Function region eu-north-1 (Stockholm); dev/preview environment regions reviewed quarterly.
TOM-INFRA-03 (Resend): Resend send region eu-west-1 (Ireland).
TOM-INFRA-05 (Vercel AI Gateway): Language-model requests are routed via the Gateway; ZDR is enforced; processing region is model-specific and auditable in logs.
TOM-INFRA-04: Supabase ISO 27001 certification applies to Supabase, not Lyyli AI Oy.
Vendor management (extended)
TOM-VENDOR-01: Subprocessor DPA versions and execution dates maintained in internal evidence register.
TOM-VENDOR-02: Subprocessor change notification subscription and PDF archive; change notice at least 30 days in advance.
TOM-VENDOR-03: Quarterly vendor register review (regions, roles, DPA status).
Maintenance Windows
Planned maintenance windows are notified at least 3 business days in advance.
Version history
- Version v1.5Last updated 07.08.2026