Data Encryption Policy

Data Encryption Policy

Title
Title
Author
Tobias Macke
Owner
CTO / Security Officer (Tobias Macke)
Version
1.0
Status
Final
Approved by
Managing Director
Last review
August 2026

Purpose

This policy defines the requirements for the use of encryption to protect information collected, processed, transmitted, or stored by Interactive Paper GmbH. Its objective is to safeguard the confidentiality and integrity of personal data and confidential business information in accordance with Art. 32 GDPR and the company's Internal Security Policy and Technical and Organisational Measures (TOMs).

Scope

This policy applies to all employees, contractors, systems, and services of Interactive Paper GmbH, including the Interactive Paper platform ( letsinteract.com ), internal IT systems, endpoints, and data exchanged with customers, partners, and sub-processors.

Encryption of Data in Transit

  • All web traffic to and from Interactive Paper services is encrypted using HTTPS with TLS (Transport Layer Security), in line with Art. 25(1) GDPR (data protection by design).
  • Personal data disclosed internally or to third parties (e.g. production partners) is transferred exclusively in encrypted form.
  • Sensitive information must not be sent by e-mail unless encrypted.
  • Remote access to systems and data requires two-factor authentication (2FA) and encrypted connections.

Encryption of Data at Rest

  • Locally stored data on company devices is encrypted (full-disk encryption on laptops and workstations).
  • Production data is hosted exclusively with EU-based providers (Hetzner Online GmbH, Germany; DigitalOcean, Frankfurt, Germany) on infrastructure employing state-of-the-art encryption at rest.
  • Passwords are never stored in plain text. Stored credentials use one-way encryption or salted hash values. Password files are kept separate from application data.

Key and Certificate Management

  • The Managing Director acts as Authorized Signatory for the issuance of digital certificates.
  • The CTO / Security Officer (Tobias Macke) is responsible for the administration of encryption keys and TLS certificates, including issuance, renewal, and revocation.
  • Access to key material is restricted to authorized system administrators.

Algorithms and Standards

  • Only industry-standard, state-of-the-art protocols and algorithms may be used (e.g. TLS 1.2 or higher for transport encryption, AES-256 for storage encryption, salted one-way hashes for credentials).
  • Deprecated or broken algorithms and protocols must not be used and are to be phased out promptly when identified.

Media and Disposal

  • Data carriers used for transfers are erased or destroyed after completion of the transfer in accordance with data protection regulations.
  • Before storage media are reused or disposed of, they are completely erased in accordance with the current state of the art.

Compliance and Review

Compliance with this policy is verified as part of the periodic security reviews defined in the Internal Security Policy. Exceptions require formal approval by the Managing Director and are recorded by the CTO / Security Officer. This policy is reviewed at least annually and updated as required.