Back to list
Annexes

ANNEX 4 – Technical and Organizational Measures (TOMs)

Open print view
Version v1.6Last updated 17.08.2026Next review 01.10.2026Contractually binding

Owner: CTO · Approver: CEO

ANNEX 4 – Technical and Organizational Measures (TOMs)

This annex describes the technical and organizational measures (TOMs) implemented by Lyyli AI Oy in processing personal data. The description is based on verifiable controls; it does not include measures that are not documented or in use.

Organizational Controls

TOM-ORG-01 – Security management: Risk-based security management model; annual review.

TOM-ORG-02 – Personnel: NDAs, onboarding, role-based access, security training.

TOM-ORG-03 – Vendor management: Subprocessor DPAs and list in Annex 5; audit rights per agreement.

TOM-ORG-04 – Privacy contact: Privacy matters: hello@lyyli.ai.

Technical Controls

TOM-TEC-01 – Encryption in transit: TLS for all customer traffic.

TOM-TEC-02 – Encryption at rest: Infrastructure provider (e.g., database, storage) encryption controls.

TOM-TEC-03 – Access control: SSO/IdP (Clerk), principle of least privilege, regular access reviews. MFA support is not currently enabled.

TOM-TEC-04 – Organizational isolation: Workspaces and customer data isolated at the organizational level.

TOM-TEC-05 – Logging: Application and audit logs; content actions traceable; retention 180 days (Annex 6).

TOM-TEC-06 – Vulnerabilities: Dependency scans in CI/CD pipeline; risk-based remediation.

TOM-TEC-07 – Backups: Daily encrypted backups; restore tests on a regular basis.

TOM-TEC-08 – Development: Code reviews, CI/CD checks, dev/test/prod environment separation.

TOM-TEC-09 – Network: Cloud provider network controls (firewalls, segmentation); DDoS protection via infrastructure service.

Data Location and Transfers

TOM-DAT-01: Primary application data for customer workspaces is stored in the EU region.

TOM-DAT-02: In some processing stages (AI APIs, authentication, email delivery) data may be processed outside the EU/EEA. International transfers use GDPR Chapter V safeguards (SCCs, EU–US DPF where applicable).

AI Data Processing

TOM-AI-01: Language models process requests under Zero Data Retention via Vercel AI Gateway. Model-specific regions are documented in the AI model register.

TOM-AI-02: Customer content is not used to train models. Gemini: Google Cloud Service Specific Terms + Cloud Data Processing Addendum.

TOM-AI-03: Allowlist of approved models and routes; new routes documented in the AI model register before production use.

TOM-AI-04: ZDR enforcement on all language-model routes in Vercel AI Gateway; data collection deny and prompt logging disabled at configuration level.

TOM-AI-05: Fallback provider blocking or restriction on critical routes; route-level logging for audit.

TOM-AI-06: Language-model processing region (EU or Global) is recorded in logs and auditable. Claude and Gemini inference is locked to the EU; GPT processing cannot currently be limited to the EU only.

Infrastructure regions

TOM-INFRA-01 (Supabase): Project AWS region eu-north-1 (Stockholm); support/logs/backups separated from primary customer storage.

TOM-INFRA-02 (Vercel hosting): Function region eu-north-1 (Stockholm); dev/preview environment regions reviewed quarterly.

TOM-INFRA-03 (Resend): Resend send region eu-west-1 (Ireland).

TOM-INFRA-05 (Vercel AI Gateway): Language-model requests are routed via the Gateway; ZDR is enforced; processing region is model-specific and auditable in logs.

TOM-INFRA-04: Supabase ISO 27001 certification applies to Supabase, not Lyyli AI Oy.

Vendor management (extended)

TOM-VENDOR-01: Subprocessor DPA versions and execution dates maintained in internal evidence register.

TOM-VENDOR-02: Subprocessor change notification subscription and PDF archive; change notice at least 30 days in advance.

TOM-VENDOR-03: Quarterly vendor register review (regions, roles, DPA status).

Maintenance Windows

Planned maintenance windows are notified at least 3 business days in advance.

Version history