Last updated: 2026-09-03 · GDPR Art. 32 · Technical and Organisational Measures
This page describes the technical and organisational measures INTYGIO implements to protect Customer Data and ensure the integrity and availability of the Service. These measures form part of INTYGIO's obligations under its Data Processing Agreement.
Cryptographic Integrity
Every Digital Product Passport is signed with an eIDAS-aligned advanced electronic seal issued to Kader Cadre AB, visible to relying parties as "Signed by INTYGIO". A qualified electronic seal certificate (QSealC) from DigiCert Europe Netherlands B.V., a qualified trust service provider on the EU Trusted List, is contracted and activates when the qualified signature creation device goes live.
Signing keys are managed by an EU-based qualified trust service provider. Private key material never leaves the HSM environment.
Signed passport payloads are immutable. Any update to a passport creates a new versioned signing event; prior versions remain verifiable.
Data Residency and Transfer
All Customer Data is stored and processed exclusively within the European Economic Area, on infrastructure operated by INTYGIO in Sweden.
No Customer Data is transferred outside the EEA. All sub-processors are EEA-incorporated.
Data is encrypted in transit using TLS 1.3 and at rest using AES-256.
Access Controls
Tenant isolation is enforced at the data model layer. Cross-tenant queries are technically impossible — no configuration or privilege escalation can bridge tenant boundaries.
INTYGIO personnel access to production systems follows least-privilege principles and requires multi-factor authentication.
All production access is logged with tamper-resistant audit trails retained for a minimum of 12 months.
Availability and Incident Response
The Service targets 99.9% monthly API availability, excluding scheduled maintenance windows notified in advance.
INTYGIO maintains an incident response procedure. Customers are notified without undue delay of any personal data breach affecting their data, as required under GDPR Art. 33.
Scheduled maintenance is announced via status.intygio.com with at least 48 hours' notice.
Organisational Measures
All personnel with access to Customer Data are subject to written confidentiality obligations.
INTYGIO conducts periodic internal security reviews. Customers may request audit cooperation subject to the terms of their Data Processing Agreement.
Security contact. To report a vulnerability or request security documentation for due diligence purposes, contact security@intygio.com. For data protection matters, contact legal@intygio.com.