Last updated: August 2026
Technical and Organizational Measures
This page describes the technical and organizational measures we apply to protect personal data processed in Schedules, in accordance with Article 32 GDPR. It forms part of subsection 2.3 of our Terms and Conditions. We may change these measures to reflect technical progress, provided the level of protection is not reduced.
Encryption
- All data in transit is protected by HTTPS with a minimum of TLS 1.2 on all application and storage endpoints.
- All data at rest is encrypted with AES-256 using Azure Storage Service Encryption with Microsoft-managed keys. Customer-managed keys are not offered.
- Secrets used by the Service, including the Entra application credential and the storage and messaging connection strings, are held in Azure Key Vault and referenced by the applications.
- We hold no passwords: authentication uses Microsoft Entra ID single sign-on, and access tokens are not stored persistently.
Access control
- Authentication. Microsoft Entra ID single sign-on. Every request to the application interface is validated by the Azure platform against Entra ID — signature, issuer and audience — before application code runs. The ICS calendar feed and the public REST API are exceptions by design: they authenticate by secret token and by API key respectively.
- Authorization. A role model applies per schedule: Admin, Self-Editor, Viewer and None. Users without a role cannot open a schedule.
- Separation of customers. Each customer organization has its own set of storage tables. Every request is scoped to the organization identifier taken from the platform-validated token, so access across customer organizations is not possible.
- Administrative access. Limited to named Devsym administrators in Germany. Multi-factor authentication is enforced on all accounts with access to the production environment, and access rights are reviewed at least annually.
- No impersonation. There is no function by which Devsym personnel can sign in as one of your users.
- Physical access. Data centre security is provided by Microsoft Azure under its own certified controls.
Integrity and traceability
- Appointment and role records carry the identifier of the user who created them and who last changed them, together with timestamps.
- Administrative actions on the Azure platform are recorded in the Azure activity log and retained for 90 days.
- A public API key can only be issued by an Admin of the schedule concerned.
- Data is transmitted only over encrypted channels. No personal data is transferred on physical media.
Availability and resilience
- A full backup of all customer data is taken daily to a separate storage account in the same region, encrypted at rest, with access restricted to a dedicated managed identity.
- Backups are retained on a rolling 90-day basis and older snapshots are deleted automatically.
- Backup failures raise an automatic alert to our administrator, as do application errors.
- Recovery is performed by restoring the most recent daily backup, so the recovery point objective is up to 24 hours. No contractual recovery time objective is offered.
- Storage is locally redundant within one Azure data centre. No geo-redundant copy is maintained.
Testing and evaluation
- Dependencies are scanned weekly against the OSV vulnerability database, which raises remediation pull requests for known vulnerabilities in third-party packages.
- No third-party penetration test has been carried out to date. Devsym holds no ISO 27001, SOC 2 or equivalent certification. The underlying platform, Microsoft Azure, is certified to ISO 27001, SOC 1/2/3 and C5, and we rely on those certifications for infrastructure-level controls.
Data protection by design and by default
- The application requests only delegated Microsoft Graph permissions — User.ReadBasic.All, Calendars.ReadBasic and TeamsActivity.Send — and holds no application-level permissions, so it cannot access data without a signed-in user.
- Directory attributes are read at the time they are displayed rather than copied into our storage. Only name fields are stored.
- Outlook free/busy entries are cached for no more than 10 minutes and are never written into the appointment store, included in backups, or logged.
- The Outlook overlay is switched on per user. Assignment e-mails are off by default and can be disabled per schedule and per user. Teams activity notifications are on by default and can be switched off per schedule by an Admin, and per user through Microsoft Teams.
- ICS calendar feeds are created on request by an Admin or Viewer for a member of the schedule. The feed URL is protected by a random token and is otherwise unauthenticated, so anyone holding the URL can read that person's appointment subjects and times. There is currently no self-service revocation; a feed is withdrawn by contacting us.
Deletion
- Deleting a team member removes that person and the appointments assigned solely to them immediately. Where an appointment has several assigned persons, only that person is removed from it. The person's role assignment and personal preferences are removed separately by an Admin.
- Deleting a customer organization removes the schedule tables, the notification e-mail queue, the organization and licence records, ICS feeds, public API keys, subscription and billing-event records, usage statistics, and the history of e-mails sent to that organization.
- Two records are kept afterwards: a minimal record of the deleted organization for accounting and abuse prevention, and the deletion request itself, which names the administrator who submitted it.
- Operational logs are retained for 90 days and then deleted automatically by the platform.
- Data processed for our own purposes is held separately from data processed on behalf of a customer.
Data location
All services that process customer data run in Microsoft Azure, Germany West Central region. The static front-end files of the application, which contain no personal data, are delivered through Microsoft's content delivery network. Our subprocessors are listed in the privacy notice.
Contact
Questions about these measures, or requests for further security documentation, can be sent to info@devsym.de.

