Security

This document describes the technical and organisational security measures implemented by Martide Pte. Ltd. (“Martide” or the “Processor”) to protect Personal Data processed on behalf of its customers. It supplements the Data Processing Agreement (“DPA”) between the customer (“Controller”) and Martide, and contains the information required by Annex II of the EU Standard Contractual Clauses and Table 3 of the UK Addendum.

These measures are implemented in accordance with Article 32 of the General Data Protection Regulation (EU 2016/679) and are continuously reviewed and improved having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing.


1. Confidentiality

1.1 Physical Access Control

Measures to prevent unauthorised persons from gaining physical access to data processing systems and facilities.

Technical measures:

Organisational measures:

1.2 Logical Access Control

Measures to prevent unauthorised access to and use of data processing systems.

Technical measures:

Organisational measures:

1.3 Data Access Control

Measures to ensure that authorised users can access only the Personal Data to which they are entitled and that Personal Data cannot be read, copied, modified or removed without authorisation during processing, use and storage.

Technical measures:

Organisational measures:

1.4 Separation Control

Measures to ensure that Personal Data collected for different purposes is processed separately.

Technical measures:

Organisational measures:


2. Pseudonymisation and Encryption (Art. 32(1)(a) GDPR)

Measures for the pseudonymisation and encryption of Personal Data.

Technical measures:

Organisational measures:


3. Integrity

3.1 Data Transfer Control

Measures to ensure that Personal Data cannot be read, copied, modified or removed without authorisation during electronic transfer or transport, and that it is possible to verify to which recipients a transfer of Personal Data is intended.

Technical measures:

Organisational measures:

3.2 Data Input Control

Measures to ensure that it is possible to verify and establish whether and by whom Personal Data has been input into, modified in, or removed from data processing systems.

Technical measures:

Organisational measures:


4. Availability, Resilience and Recoverability (Art. 32(1)(b)–(c) GDPR)

4.1 Availability and Resilience

Measures to ensure the ongoing availability and resilience of processing systems and services.

Technical measures:

Organisational measures:

4.2 Recoverability

Measures for ensuring the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident.

Technical measures:

Organisational measures:


5. Incident Management and Personal Data Breach Procedures

Measures for the identification, assessment and notification of Personal Data Breaches.

Technical measures:

Organisational measures:


6. Review, Assessment and Evaluation (Art. 32(1)(d) and Art. 25(1) GDPR)

6.1 Data Protection Management

Measures for ensuring regular testing, assessment and evaluation of the effectiveness of technical and organisational measures.

Organisational measures:

6.2 Sub-processor Management

Measures for ensuring that Sub-processors process Personal Data in compliance with applicable Data Protection Laws.

Organisational measures:


7. Data Minimisation and Retention

Measures to ensure that Personal Data is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed, and that it is not retained longer than necessary.

Technical measures:

Organisational measures:


8. Data Quality

Measures to ensure the accuracy and currency of Personal Data.

Technical measures:

Organisational measures:


9. Data Portability and Erasure

Measures to support the Controller’s obligations in relation to Data Subject requests for data portability and erasure.

Technical measures:

Organisational measures:


10. Certifications and Security Assessments


Contact

For enquiries regarding these security measures or Martide’s data protection practices, please contact:

Data Protection Officer Martide Pte. Ltd. 1 HarbourFront Place, HarbourFront Tower One, #14-05/06, Singapore 098633 Email: software.support@martide.com

Last updated: 13th February 2026