CTO / Security Officer (Tobias Macke)
This policy defines the requirements for the use of encryption to protect information collected, processed, transmitted, or stored by Interactive Paper GmbH. Its objective is to safeguard the confidentiality and integrity of personal data and confidential business information in accordance with Art. 32 GDPR and the company's Internal Security Policy and Technical and Organisational Measures (TOMs).
This policy applies to all employees, contractors, systems, and services of Interactive Paper GmbH, including the Interactive Paper platform ( letsinteract.com ), internal IT systems, endpoints, and data exchanged with customers, partners, and sub-processors. - All web traffic to and from Interactive Paper services is encrypted using HTTPS with TLS (Transport Layer Security), in line with Art. 25(1) GDPR (data protection by design).
- Personal data disclosed internally or to third parties (e.g. production partners) is transferred exclusively in encrypted form.
- Sensitive information must not be sent by e-mail unless encrypted.
- Remote access to systems and data requires two-factor authentication (2FA) and encrypted connections.
- Locally stored data on company devices is encrypted (full-disk encryption on laptops and workstations).
- Production data is hosted exclusively with EU-based providers (Hetzner Online GmbH, Germany; DigitalOcean, Frankfurt, Germany) on infrastructure employing state-of-the-art encryption at rest.
- Passwords are never stored in plain text. Stored credentials use one-way encryption or salted hash values. Password files are kept separate from application data.
- The Managing Director acts as Authorized Signatory for the issuance of digital certificates.
- The CTO / Security Officer (Tobias Macke) is responsible for the administration of encryption keys and TLS certificates, including issuance, renewal, and revocation.
- Access to key material is restricted to authorized system administrators.
- Only industry-standard, state-of-the-art protocols and algorithms may be used (e.g. TLS 1.2 or higher for transport encryption, AES-256 for storage encryption, salted one-way hashes for credentials).
- Deprecated or broken algorithms and protocols must not be used and are to be phased out promptly when identified.
- Data carriers used for transfers are erased or destroyed after completion of the transfer in accordance with data protection regulations.
- Before storage media are reused or disposed of, they are completely erased in accordance with the current state of the art.
Compliance with this policy is verified as part of the periodic security reviews defined in the Internal Security Policy. Exceptions require formal approval by the Managing Director and are recorded by the CTO / Security Officer. This policy is reviewed at least annually and updated as required.