Constructor Technology technical and organisational measures

Effective date: August 4, 2026

These Technical and Organisational Measures describe the controls applied, as relevant, to systems and services used by Constructor Technology to process Customer Data. The implementation of individual controls may vary according to the service architecture, the nature and risks of the processing, and the applicable contractual requirements.

 

1. Information security management

Constructor Technology maintains an Information Security Management System comprising administrative, physical and technical controls designed to protect the confidentiality, integrity and availability of Customer Data.

Information-security risks are assessed at planned intervals and when material changes to services, systems, processing activities, legal requirements or the threat environment may affect those risks.

These Technical and Organisational Measures are reviewed and updated when necessary to reflect material changes to relevant controls or processing activities.

 

2. Personnel security

Constructor Technology defines information-security and data-protection roles and responsibilities for personnel whose work may affect Customer Data or systems used to process it.

Risk-based personnel screening is performed for roles for which screening is required, subject to applicable law and Constructor Technology’s screening procedures.

Personnel receive information-security and privacy awareness training during onboarding and at least annually thereafter. Additional role-specific training is required for personnel with relevant technical, security or data-protection responsibilities.

Personnel authorized to access Customer Data or relevant systems are informed of their confidentiality, security and data-protection obligations. Applicable confidentiality obligations continue following termination of employment or engagement.

 

3. Physical security

Customer Data is hosted in cloud data centres operated by third-party infrastructure providers.

Constructor Technology assesses the information-security arrangements of relevant infrastructure providers. Assessment may include review of contractual safeguards, security certifications, independent audit reports and other available assurance information.

Physical and environmental protection of cloud infrastructure is provided by the relevant infrastructure provider in accordance with its security controls and contractual responsibilities.

 

4. Logical access control

Constructor Technology maintains access controls designed to prevent unauthorized access to systems used to process Customer Data.

These controls include:

a) documented processes for requesting, approving, granting, changing and revoking access;

b) assignment of access according to business need and the principle of least privilege;

c) use of individual user accounts and appropriate authentication controls;

d) multi-factor authentication for privileged and other relevant forms of access;

e) role-based access controls where appropriate;

f) removal or adjustment of access following termination or a relevant change of role; and

g) periodic review of access rights and privileged access.

 

5. Access control and encryption

Access to Customer Data is limited to authorized persons and systems according to assigned roles and documented business requirements.

Relevant controls include:

a) documented procedures for granting, changing and withdrawing access;

b) role-based allocation of permissions appropriate to the relevant system;

c) periodic review of relevant access authorizations;

d) encryption of Customer Data in transit using approved cryptographic protocols;

e) encryption of Customer Data at rest within applicable cloud-storage environments;

f) protection of company-managed endpoints in accordance with applicable endpoint-security requirements;

g) logging of relevant authentication, security and administrative events where supported by the system and appropriate to the associated risk; and

h) protection and review of security logs in accordance with applicable logging and monitoring requirements.

 

6. Data handling and processing controls

Constructor Technology maintains controls governing the authorized handling and processing of Customer Data.

These controls include:

a) classification and handling requirements appropriate to the sensitivity of the information;

b) documented requirements governing authorized access, use, disclosure, retention and deletion;

c) communication of applicable security and data-protection requirements to personnel involved in the processing;

d) access controls appropriate to the relevant system and processing activity; and

e) logging and monitoring of security-relevant system and administrative activity where appropriate to the risk and supported by the relevant system.

 

7. Data transmission and network security

Constructor Technology applies controls designed to protect Customer Data during electronic transmission.

These controls include:

a) use of secure communication channels and approved encrypted communication protocols;

b) authentication controls appropriate to remote and privileged access;

c) network-separation and access-control measures appropriate to the relevant environment;

d) logging, monitoring and alerting for security-relevant events; and

e) review of relevant security events to support the identification and investigation of suspicious activity.

 

8. Availability, resilience and incident response

Constructor Technology maintains business continuity, disaster recovery, backup and recovery arrangements for relevant systems processing Customer Data.

These controls include:

a) documented business continuity and disaster recovery arrangements;

b) documented backup and recovery procedures;

c) testing of backup integrity and recovery capability at least annually for relevant systems;

d) processes for assessing and applying security updates and patches;

e) malware protection and other endpoint or server-security controls appropriate to the relevant environment;

f) monitoring of relevant service availability and performance; and

g) resilience and recovery controls appropriate to the criticality of the relevant service.

Constructor Technology maintains an incident response process defining responsibilities and procedures for assessing, containing, managing and recovering from information-security incidents. The process includes internal reporting and escalation, incident assessment, containment and recovery, preservation of relevant evidence, assessment of notification obligations, and post-incident corrective action.

 

9. Separation controls

Constructor Technology applies separation controls appropriate to the architecture of the relevant service.

These controls include:

a) tenant-isolation controls for multi-tenant services;

b) separation of development, testing, staging and production environments;

c) separate access controls for relevant environments; and

d) controls restricting the use of production Customer Data in development and testing.

 

10. Website and application security

Products, services and software components within the scope of Constructor Technology’s secure development requirements are developed and maintained through an established secure software development lifecycle.

The applicable controls include:

a) identification and documentation of security and privacy requirements;

b) security review of relevant architecture, data flows, trust boundaries and external dependencies;

c) secure coding requirements informed by recognized security standards and OWASP guidance;

d) peer review of code changes;

e) risk-based application-security testing, which may include static application security testing, dynamic application security testing, dependency scanning and container-image scanning;

f) identification, assessment and tracking of vulnerabilities through remediation, mitigation or documented risk acceptance;

g) separation of development, testing and production environments; and

h) application of security-by-design and privacy-by-design principles.

Constructor Technology maintains an annual penetration-testing programme. The scope of testing is determined according to risk and may include relevant applications and supporting infrastructure. Additional testing may be performed following significant architectural changes, major releases or the identification of elevated security risk.

 

11. Supplier and subprocessor oversight

Constructor Technology applies information-security controls when engaging relevant suppliers and subprocessors that may process Customer Data or provide services supporting its processing.

These controls include:

a) information-security due diligence before engaging relevant suppliers and subprocessors;

b) documented security, confidentiality and data-protection requirements in relevant agreements;

c) assessment of supplier security information, certifications, audit reports or other available assurance evidence;

d) monitoring and review proportionate to the nature and risk of the supplied service; and

e) maintenance of relevant supplier and subprocessor information.