Loading...

Policy

Security Policy

Last Updated: April 8, 2026

This Security Policy outlines the technical and organisational measures Pivetra implements to protect personal and business data processed through Hiver Ticket in accordance with Art. 32 GDPR and BDSG.

Scope of this page

This page is a high-level summary of platform security controls, incident handling, and employee security practices. It is suitable for customer review without exposing sensitive operational details.

Section 1

Our Commitment

Pivetra implements comprehensive technical and organisational security measures (TOMs) in accordance with Art. 32 GDPR and BDSG to protect personal and business data processed through Hiver Ticket.

Section 2

Infrastructure & Data Centre

  • All data stored in ISO 27001-certified data centres within Germany.
  • Physical access to facilities is strictly controlled and monitored 24/7.
  • Redundant infrastructure ensures high availability and disaster recovery.
  • Regular independent security audits and penetration testing.

Section 3

Encryption

  • Data in transit: TLS 1.2+.
  • Data at rest: AES-256.
  • Encrypted backups stored in Germany.
  • Industry-standard key management practices.

Section 4

Access Control

  • Role-based access control (RBAC) limits data access to authorised personnel.
  • Multi-factor authentication (MFA) available and recommended for all accounts.
  • Administrative access requires MFA and is fully logged.
  • Access rights reviewed quarterly; revoked promptly on role change or departure.
  • Principle of least privilege applied throughout.

Section 5

Incident Response & Breach Notification

In the event of a personal data breach, Pivetra will:

  • Notify the BayLDA within 72 hours where the breach risks individuals' rights and freedoms (Art. 33 GDPR).
  • Notify affected Controllers (customers) within 72 hours of discovery (Art. 33(2) GDPR).
  • Notify affected individuals where the breach poses a high risk to their rights (Art. 34 GDPR).
  • Document all breaches and responses in our breach register.

Section 6

Vulnerability Disclosure

Report potential vulnerabilities responsibly to [email protected]. We acknowledge reports within 48 business hours and aim to remediate within 90 days before any public disclosure.

Section 7

Employee Security

  • All staff complete data protection and security training on onboarding and annually.
  • All staff with data access have signed confidentiality agreements.
  • Background checks conducted where permissible under German law.
Pivetra Security Policy