Learn about Glassray's technical and organisational measures implemented to ensure the security of personal data processing in compliance with GDPR Article 32.
Last updated: 10th September 2026
Privasee Group LTD t/a Glassray (Company Registration 11605442)
The following technical and organisational measures have been implemented.
- Measures regarding pseudonymisation and encryption of personal data - Art. 32 (1a)
- Measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services - Art 32 (1b)
- Measures to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident - Art 32 (1c)
- Measures regarding regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing - Art 32 (1d)
- Additional measures to minimise risk
1. Measures regarding pseudonymisation and encryption of personal data - Art. 32 (1a)
Pseudonymisation means the processing of personal data in such a way that the personal data can no longer be attributed to a specified data subject without additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
Encryption is a way of altering readable data so that only authorised parties can understand the information.
The technical and organisational measures implemented are:
- Only secure wireless networks (WLAN) are used, all of which are encrypted with WPA-2.
- All employee devices are password-protected and storage drives are encrypted.
- Email communication is encrypted in transit to protect sensitive information.
- All traffic in transit is encrypted with TLS (1.2 or higher, 1.3 where the client supports it): between the Customer's systems and Glassray's ingest endpoints, between Glassray's own services, and to every sub-processor.
- Data at rest, including the database, its backups and stored trace payloads, is encrypted by the hosting provider using industry-standard ciphers.
- Credentials the Customer provides for connected trace sources are held only in a dedicated encrypted secrets vault, never in the application database, and are read per job.
- Ingest keys are write-only: a key that leaks from a Customer's environment can submit traces but cannot read any trace back.
- The Customer can pseudonymise or withhold trace content before it leaves its own systems: hide inputs or outputs wholesale, rely on automatic scrubbing of secret-shaped fields, register a redaction hook that fails closed, switch capture off per call, and exclude whole customers or traces with source filters.
- Stored trace payloads are addressed by a one-way hash of the Customer-supplied trace identifier, so a crafted identifier cannot reach another tenant's objects.
2. Measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services - Art 32 (1b)
The technical and organisational measures to ensure confidentiality, integrity and availability and resilience of processing systems and services ensure adequate security of personal data. Including measures implemented to ensure data cannot be read, copied, altered or removed without authorisation during their electronic transmission, during their transport or storage on data carriers. Protection against unauthorised or unlawful processing, against accidental loss, destruction or damage. Moreover, ensuring that it is possible to verify and establish where personal data has been transmitted and to ensure subsequent verification and determination of whether, when and by whom personal data have been submitted, modified or removed. In addition to measures that must be implemented prior to and monitored during data processing.
The technical and organisational measures implemented are:
- Devices are configured to lock automatically after a defined period of time with no user activity.
- Multi-Factor Authentication is used for key systems where available.
- Passwords for key systems used by us are required to follow a strong password policy where a combination of unique complex characters is used.
- A password manager is used to ensure passwords are stored encrypted, secure passwords are generated by default and sharing occurs in a secure way.
- Frequent backups of production data are performed by the managed database provider. Backups are encrypted and periodically tested to ensure it is possible to recover the data.
- Code changes are reviewed through pull requests and pass automated test suites in continuous integration before deployment. Database migrations are applied through the same pipeline, never by hand.
- Unique credentials are used to access key systems and accounts are not shared.
- All Personal Data in the Services may be deleted upon a Customer's request and promptly as per the Retention Policy (normally after they leave the service).
- Users are authenticated and authorised through a managed identity provider, with support for single sign-on (SAML and OIDC), multi-factor authentication and role-based access. API keys are bound to a single project and to explicit permissions.
- Individuals only have access to the information that their job function requires.
- Every tenant-scoped record carries the owning organisation's identifier. The tenant is read only from the verified session, never from request input, and every query runs through a tenant-scoped data layer.
- Stored trace payloads live in a private bucket partitioned by tenant and are reached only server-side with a service credential. The database's public data API and GraphQL endpoint are disabled.
- Service-to-service calls are authenticated with a shared secret over HTTPS. Outbound requests to Customer-supplied URLs reject non-HTTPS schemes and addresses that resolve to private, loopback, link-local or cloud-metadata ranges.
3. Measures to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident - Art 32 (1c)
Measures are implemented to ensure that systems can be recovered and restored in a timely manner in the event of a disaster scenario or security incident.
The measures implemented are:
- Emergency planning (emergency plan for security and data protection violations with specific instructions).
- Application, background-job and access activity is logged centrally. Background jobs are durable: they are retried with backoff, stalled jobs are reclaimed automatically, and failures are visible on an internal dashboard.
- Production services run on managed hosting providers with multi-availability-zone resilience, and the application and background worker are monitored for uptime with alerting.
4. Procedures for periodic review, assessment and evaluation - Art 32 (1d)
Regular review, assessment and evaluation of the effectiveness of the technical and organisational measures taken to ensure the security of the processing.
These measures are:
- A process is in place to detect, record and report security incidents involving personal data.
- The company has formally assigned and documented roles and responsibilities for data privacy and security functions.
- All employees receive Data Protection and Security training. We increase awareness to minimise the chance of them falling into traps, including phishing emails, the dangers of USB drives, email attachments and recognising data breaches and data subject access requests.
- The company maintains a formal inventory of production systems and other company assets (including cloud and on-premises assets) that hold data.
- The company has a vendor management program in place, including a critical third-party vendor inventory, vendor security and privacy requirements, and review of critical third-party vendors at least annually.
- The company maintains an internal Data Protection Policy which includes information and instructions about Security, Data Protection and uses of their assets and devices.
- The company has established a procedure to notify Controllers of changes in sub-processors within the specified time periods and form as per the respective DPAs.
- The company requires employees to sign a confidentiality agreement during onboarding.
5. Measures to minimise risk
Additional technical and organisational measures put in place to minimise risk are:
- All systems and devices are updated at regular intervals (software update).
- Enters into Data Processing Agreements with its Authorised Sub-Processors with data protection obligations substantially similar to those contained in this Addendum.
- Large language model and embedding providers are used through their commercial APIs, under terms that do not permit the use of Customer data to train their models.
- Follow an onboarding / offboarding checklist when employees join or leave the company. Credentials are deactivated or deleted immediately when employees leave the company.
- The company maintains cybersecurity insurance to mitigate the financial impact of business disruptions.
- A Data Subject Requests (DSRs) Policy and procedures have been put in place to ensure that the rights of Data Subjects are honoured.
- The company maintains a map of the information flows and has a list of the data they process, what is the purpose for processing that data and who the data belongs to.
- The company has appointed a Data Protection Officer (DPO) and their contact details are accessible in the company's Privacy Policy.
- The company has appointed an EU Representative to ensure compliance with Article 27 of the GDPR.
- Where consent is used, the company has ensured that consent is properly requested and recorded.