{"component": "clause", "props": {"groups": [{"snippet_links": [{"key": "measures-to", "type": "clause", "offset": [29, 40]}, {"key": "student-data", "type": "clause", "offset": [57, 69]}, {"key": "data-processing-systems", "type": "clause", "offset": [137, 160]}, {"key": "reporting-systems", "type": "clause", "offset": [184, 201]}, {"key": "audit-trails", "type": "clause", "offset": [208, 220]}, {"key": "and-documentation", "type": "clause", "offset": [221, 238]}], "samples": [{"hash": "fjtyWJXsFuJ", "uri": "/contracts/fjtyWJXsFuJ#entry-control", "label": "Student Data Privacy Agreement", "score": 32.0753898621, "published": true}, {"hash": "fysIWFhq6Nz", "uri": "/contracts/fysIWFhq6Nz#entry-control", "label": "Student Data Privacy Agreement", "score": 31.7332191467, "published": true}, {"hash": "e8JeolbT0Ky", "uri": "/contracts/e8JeolbT0Ky#entry-control", "label": "Student Data Privacy Agreement", "score": 31.2432289124, "published": true}], "size": 9, "snippet": "Technical and organizational measures to monitor whether Student Data have been entered, changed or removed (deleted), and by whom, from data processing systems, include: \u25cfLogging and reporting systems; and \u25cfAudit trails and documentation.", "hash": "87212972a75f766f164e013ef7c37cbb", "id": 1}, {"snippet_links": [{"key": "measures-to", "type": "clause", "offset": [29, 40]}, {"key": "personal-data", "type": "clause", "offset": [57, 70]}, {"key": "data-processing-systems", "type": "clause", "offset": [138, 161]}, {"key": "reporting-systems", "type": "clause", "offset": [186, 203]}, {"key": "audit-trails", "type": "clause", "offset": [211, 223]}, {"key": "and-documentation", "type": "clause", "offset": [224, 241]}], "samples": [{"hash": "cShfCBwzypu", "uri": "/contracts/cShfCBwzypu#entry-control", "label": "Data Processing Addendum (Blockstack Inc.)", "score": 30.5140323639, "published": true}, {"hash": "PZ16CAuGew", "uri": "/contracts/PZ16CAuGew#entry-control", "label": "Data Processing Addendum (Blockstack Inc.)", "score": 30.5140323639, "published": true}, {"hash": "bE3F0f0r1nP", "uri": "/contracts/bE3F0f0r1nP#entry-control", "label": "Data Processing Addendum (Blockstack Token LLC)", "score": 30.3689250946, "published": true}], "size": 8, "snippet": "Technical and organizational measures to monitor whether Personal Data have been entered, changed or removed (deleted), and by whom, from data processing systems, include: \u00b7 Logging and reporting systems; and \u00b7 Audit trails and documentation.", "hash": "61062c3c42edfe0320254afab99cbd41", "id": 2}, {"snippet_links": [{"key": "control-of-the", "type": "clause", "offset": [0, 14]}, {"key": "the-premises", "type": "clause", "offset": [24, 36]}, {"key": "data-processing-systems", "type": "clause", "offset": [40, 63]}, {"key": "dp-system", "type": "definition", "offset": [65, 74]}, {"key": "unauthorised-persons", "type": "clause", "offset": [79, 99]}, {"key": "the-central", "type": "clause", "offset": [239, 250]}, {"key": "also-included", "type": "clause", "offset": [383, 396]}, {"key": "end-devices", "type": "definition", "offset": [405, 416]}, {"key": "remote-access", "type": "definition", "offset": [426, 439]}, {"key": "office-spaces", "type": "clause", "offset": [469, 482]}, {"key": "of-the-company", "type": "clause", "offset": [645, 659]}, {"key": "arrival-and-departure", "type": "clause", "offset": [781, 802]}, {"key": "company-persons", "type": "definition", "offset": [810, 825]}, {"key": "availability-of", "type": "clause", "offset": [828, 843]}, {"key": "reception-area", "type": "clause", "offset": [852, 866]}, {"key": "company-personnel", "type": "definition", "offset": [934, 951]}, {"key": "of-employees", "type": "clause", "offset": [1006, 1018]}, {"key": "access-equipment", "type": "definition", "offset": [1031, 1047]}, {"key": "for-company", "type": "definition", "offset": [1101, 1112]}, {"key": "determination-of", "type": "clause", "offset": [1185, 1201]}, {"key": "to-enter", "type": "definition", "offset": [1221, 1229]}, {"key": "scope-of-the", "type": "clause", "offset": [1245, 1257]}, {"key": "access-to", "type": "definition", "offset": [1287, 1296]}, {"key": "security-areas", "type": "definition", "offset": [1312, 1326]}, {"key": "chip-card", "type": "definition", "offset": [1373, 1382]}, {"key": "server-room", "type": "clause", "offset": [1501, 1512]}, {"key": "provision-of", "type": "clause", "offset": [1587, 1599]}, {"key": "for-employees", "type": "clause", "offset": [1637, 1650]}, {"key": "key-control", "type": "clause", "offset": [1651, 1662]}, {"key": "storage-and-use", "type": "clause", "offset": [1735, 1750]}, {"key": "a-general", "type": "clause", "offset": [1754, 1763]}, {"key": "protection-of", "type": "definition", "offset": [1806, 1819]}, {"key": "locking-system", "type": "definition", "offset": [1879, 1893]}], "samples": [{"hash": "jRLTQvTfXvE", "uri": "/contracts/jRLTQvTfXvE#entry-control", "label": "Data Privacy & Security", "score": 33.1686134338, "published": true}, {"hash": "e9MCEu56hgA", "uri": "/contracts/e9MCEu56hgA#entry-control", "label": "Data Privacy & Security", "score": 33.1686134338, "published": true}, {"hash": "jj9UYEsQmA1", "uri": "/contracts/jj9UYEsQmA1#entry-control", "label": "Data Privacy & Security", "score": 30.9568214417, "published": true}], "size": 7, "snippet": "Control of the entry to the premises of data processing systems (DP system) by unauthorised persons. Entry control must prevent persons who are not authorised from being able to get near a DP system. The DP systems include, in addition to the central unit including the integrated drives, the connected peripheral units such as terminals, PCs, printers, plotter and tape units, etc. Also included are the end devices used for remote access. Entry control to PCs within office spaces is ensured, e.g. by measures that are taken to prevent customers from getting near the PCs or being able to view the screen. Entry regulation for persons outside of the company; the implementation is carried out by the following points: \u2022 Regulations for entry by external persons \u2022 Logging of the arrival and departure of non-company persons \u2022 Availability of central reception area (gatekeeper/reception) \u2022 Issuance of visitors ID \u2022 Presence of non-company personnel anywhere in the company building only in the presence of employees \u2022 Return of access equipment after the authorisation has expired Entry regulation for company personnel; the implementation is carried out by the following points: \u2022 Determination of persons authorised to enter, including the scope of the authorisations, for physical access to relevant rooms/security areas \u2022 Issuance of entry authorisation cards (e.g. chip card with logging) \u2022 Logging of employees\u2019 arrival and departure Determination of persons authorised to enter the computer/server room Measures so that only authorised entry to the computer/server room occurs Provision of lockable cabinets/rolling containers for employees Key control if keys are used, (locked doors; issue keys only to authorised persons; storage and use of a general key) Measures for object protection (e.g. protection of ducts and windows; area monitoring) Secured entrance (e.g. locking system, ID reader)", "hash": "a4cdeb8164a04848c6c0b0b129d6462c", "id": 3}, {"snippet_links": [{"key": "personal-data", "type": "clause", "offset": [19, 32]}, {"key": "data-processing-systems", "type": "clause", "offset": [50, 73]}, {"key": "when-employees", "type": "clause", "offset": [138, 152]}, {"key": "terms-of", "type": "definition", "offset": [281, 289]}, {"key": "employees-in", "type": "clause", "offset": [486, 498]}], "samples": [{"hash": "jErrCdnOPly", "uri": "/contracts/jErrCdnOPly#entry-control", "label": "Data Processing Agreement", "score": 24.8590011597, "published": true}, {"hash": "bpT2Sc3llHI", "uri": "/contracts/bpT2Sc3llHI#entry-control", "label": "Data Processing Agreement", "score": 24.8590011597, "published": true}, {"hash": "87PTAkzQidH", "uri": "/contracts/87PTAkzQidH#entry-control", "label": "Data Processing Agreement", "score": 24.8590011597, "published": true}], "size": 6, "snippet": "The rooms in which personal data are processed or data processing systems are installed may not be freely accessible. They must be locked when employees are away. Entry authorizations must be assigned in a regulated procedure on a need-to-know basis and are generally monitored in terms of whether they are necessary. Rooms in which data processing systems (datacenter, server, network distributor, etc.) are located must have particular entry protections and may be accessible only to employees in IT administration (management, if necessary). Alternately, the devices must be stored in suitable and locked cabinets. Visitors and non-company individuals must be registered in a documented procedure and monitored while visiting the o\ufb03ces.", "hash": "3e5668f5a9fba1cc838bae1431c5bc14", "id": 4}, {"snippet_links": [{"key": "personal-data", "type": "clause", "offset": [19, 32]}, {"key": "data-processing-systems", "type": "clause", "offset": [50, 73]}, {"key": "when-employees", "type": "clause", "offset": [138, 152]}, {"key": "terms-of", "type": "definition", "offset": [281, 289]}, {"key": "employees-in", "type": "clause", "offset": [486, 498]}, {"key": "the-company-has", "type": "definition", "offset": [742, 757]}, {"key": "the-requirement", "type": "clause", "offset": [770, 785]}, {"key": "locked-building", "type": "definition", "offset": [798, 813]}, {"key": "electronic-security", "type": "clause", "offset": [829, 848]}, {"key": "locking-system", "type": "definition", "offset": [849, 863]}, {"key": "assignment-process", "type": "definition", "offset": [914, 932]}, {"key": "registration-area", "type": "clause", "offset": [941, 958]}, {"key": "electronic-entry", "type": "definition", "offset": [1012, 1028]}, {"key": "alarm-system", "type": "definition", "offset": [1060, 1072]}, {"key": "server-room", "type": "clause", "offset": [1113, 1124]}], "samples": [{"hash": "hvl8C7E6TVg", "uri": "/contracts/hvl8C7E6TVg#entry-control", "label": "Data Protection Agreement", "score": 31.1675987244, "published": true}, {"hash": "iTmyEOQyMdb", "uri": "/contracts/iTmyEOQyMdb#entry-control", "label": "Data Protection Agreement", "score": 29.8536624908, "published": true}, {"hash": "38LdCtC1Vfv", "uri": "/contracts/38LdCtC1Vfv#entry-control", "label": "Data Protection Agreement", "score": 29.8536624908, "published": true}], "size": 4, "snippet": "The rooms in which personal data are processed or data processing systems are installed may not be freely accessible. They must be locked when employees are away. Entry authorizations must be assigned in a regulated procedure on a need-to-know basis and are generally monitored in terms of whether they are necessary. Rooms in which data processing systems (datacenter, server, network distributor, etc.) are located must have particular entry protections and may be accessible only to employees in IT administration (management, if necessary). Alternately, the devices must be stored in suitable and locked cabinets. Visitors and non-company individuals must be registered in a documented procedure and monitored while visiting the offices. The company has implemented the requirement as follows: Locked building Locked offices Electronic security locking system Mechanical security locking system Documented key assignment process Visitor registration Area-dependent authorization IDs Locked server rooms with electronic entry control Locked server cabinets Alarm system for building / offices Alarm system for server room Electronic entry control", "hash": "4fa15271a6768bf1815a1686a10ef8bb", "id": 5}, {"snippet_links": [{"key": "customer-personal-data", "type": "definition", "offset": [51, 73]}, {"key": "to-ensure", "type": "clause", "offset": [149, 158]}, {"key": "to-company", "type": "definition", "offset": [172, 182]}, {"key": "identification-of-authorized-persons", "type": "clause", "offset": [212, 248]}, {"key": "access-controls", "type": "definition", "offset": [302, 317]}, {"key": "smart-cards", "type": "clause", "offset": [337, 348]}, {"key": "surveillance-equipment", "type": "definition", "offset": [386, 408]}, {"key": "individual-person", "type": "definition", "offset": [439, 456]}, {"key": "alarm-systems", "type": "clause", "offset": [559, 572]}], "samples": [{"hash": "gj0oJ0uWwBI", "uri": "/contracts/gj0oJ0uWwBI#entry-control", "label": "Saas Agreement", "score": 30.6108970642, "published": true}, {"hash": "6aGZAkh7lW9", "uri": "/contracts/6aGZAkh7lW9#entry-control", "label": "Software as a Service Agreement", "score": 29.6866836548, "published": true}, {"hash": "10HlSU77L0v", "uri": "/contracts/10HlSU77L0v#entry-control", "label": "Software as a Service Agreement", "score": 25.3477077484, "published": true}], "size": 4, "snippet": "Entry to buildings, rooms, and facilities in which Customer Personal Data is collected, processed or used, will be restricted to authorized persons. To ensure secure entry to company buildings and rooms, and the identification of authorized persons, Entco will deploy and use effective and appropriate access controls such as electronic smart cards, door locking systems, and technical surveillance equipment. Such controls will be at the individual person level as appropriate. Furthermore, appropriate and effective surveillance equipment such as video and alarm systems will be installed.", "hash": "a6f40483c94d63eec2b279dd76e3ae8d", "id": 6}, {"snippet_links": [{"key": "physical-facilities", "type": "clause", "offset": [29, 48]}, {"key": "processing-data", "type": "definition", "offset": [64, 79]}, {"key": "data-processing-facilities", "type": "clause", "offset": [81, 107]}, {"key": "third-party-vendors", "type": "definition", "offset": [136, 155]}, {"key": "no-personal-data", "type": "clause", "offset": [181, 197]}, {"key": "the-third-party", "type": "definition", "offset": [249, 264]}, {"key": "terminal-equipment", "type": "clause", "offset": [304, 322]}, {"key": "other-hardware", "type": "clause", "offset": [330, 344]}, {"key": "protection-of-personal-data", "type": "clause", "offset": [396, 423]}, {"key": "security-measures", "type": "definition", "offset": [463, 480]}, {"key": "the-gdpr", "type": "definition", "offset": [501, 509]}, {"key": "iso-27001", "type": "definition", "offset": [556, 565]}, {"key": "technical-measures", "type": "clause", "offset": [570, 588]}, {"key": "cloud-security", "type": "clause", "offset": [604, 618]}, {"key": "further-assurances", "type": "definition", "offset": [687, 705]}, {"key": "technical-and-organizational-measures", "type": "definition", "offset": [799, 836]}, {"key": "in-the-event-of", "type": "definition", "offset": [839, 854]}, {"key": "security-incidents", "type": "clause", "offset": [855, 873]}, {"key": "access-control", "type": "clause", "offset": [952, 966]}, {"key": "data-centers", "type": "clause", "offset": [974, 986]}], "samples": [{"hash": "g3l64N2EsgN", "uri": "/contracts/g3l64N2EsgN#entry-control", "label": "Data Processing Agreement", "score": 30.6310749054, "published": true}, {"hash": "14CJeTAyuNH", "uri": "/contracts/14CJeTAyuNH#entry-control", "label": "Contract for the Commissioned Processing of Personal Data", "score": 30.4914684296, "published": true}, {"hash": "lphnFljUjC7", "uri": "/contracts/lphnFljUjC7#entry-control", "label": "Technical and Organizational Measures", "score": 30.4285087585, "published": true}], "size": 3, "snippet": "Seatti does not have its own physical facilities for storing or processing data. Data processing facilities are utilized by established third party vendors as previously described. No personal data is ever stored on any equipment other than that of the third party vendors. Therefore, physical access to terminal equipment or any other hardware under Seatti's jurisdiction is not relevant to the protection of Personal Data. AWS as a data center offers extensive security measures for compliance with the GDPR. Several standards are implemented, including ISO 27001 for technical measures, ISO 27017 for cloud security, and ISO 27018 for cloud privacy. In the AWS GDPR DPA, AWS provides further assurances: \u25aa Data is processed exclusively in the precisely instructed manner \u25aa AWS maintains detailed technical and organizational measures \u25aa In the event of security incidents, AWS customers are notified of incidents as soon as they become aware of them Access control to AWS data centers and all other technical and organizational measures implemented by AWS are detailed at \u2587\u2587\u2587\u2587\u2587://\u2587\u2587\u2587.\u2587\u2587\u2587\u2587\u2587\u2587.\u2587\u2587\u2587/de/compliance/data- center/controls/.", "hash": "7d53cf36edf366ba995b19d2522b025d", "id": 7}, {"snippet_links": [{"key": "sanitary-services", "type": "clause", "offset": [29, 46]}, {"key": "services-for", "type": "clause", "offset": [57, 69]}, {"key": "waiting-time", "type": "definition", "offset": [89, 101]}, {"key": "and-documentation", "type": "clause", "offset": [115, 132]}], "samples": [{"hash": "aeHAQ5K61Ku", "uri": "/contracts/aeHAQ5K61Ku#entry-control", "label": "Lease Agreement (Netshoes (Cayman) Ltd.)", "score": 26.2607803345, "published": true}, {"hash": "l0rUdt2n70m", "uri": "/contracts/l0rUdt2n70m#entry-control", "label": "Lease Agreement (Netshoes (Cayman) Ltd.)", "score": 26.2032852173, "published": true}, {"hash": "cXhDEILEVUp", "uri": "/contracts/cXhDEILEVUp#entry-control", "label": "Lease Agreement (Netshoes (Cayman) Ltd.)", "score": 25.9541416168, "published": true}], "size": 3, "snippet": "m2 Installation with private sanitary services, sanitary services for trucker drivers in waiting time, and control and documentation room of access of trucks, private and staff vehicles.", "hash": "5f3a0305006c64fc056cb79bf19e3752", "id": 8}, {"snippet_links": [{"key": "personal-data", "type": "clause", "offset": [32, 45]}, {"key": "data-processing-systems", "type": "clause", "offset": [86, 109]}, {"key": "changes-and-deletions", "type": "clause", "offset": [139, 160]}, {"key": "management-systems", "type": "definition", "offset": [256, 274]}], "samples": [{"hash": "b0FvArsViU4", "uri": "/contracts/b0FvArsViU4#entry-control", "label": "Data Processing Agreement", "score": 33.4895324707, "published": true}, {"hash": "1qyjC3HZkpJ", "uri": "/contracts/1qyjC3HZkpJ#entry-control", "label": "Data Processing Agreement", "score": 29.7003707886, "published": true}, {"hash": "3gtNoZOcv8J", "uri": "/contracts/3gtNoZOcv8J#entry-control", "label": "Data Processing Agreement", "score": 24.6810398102, "published": true}], "size": 3, "snippet": "Determining whether and by whom Personal Data has been entered, altered or removed in data processing systems.\n2.2.1 Are all data entries, changes and deletions logged and evaluated? \u2013 Yes.\n2.2.2 Do you have an administrator log? \u2013 Yes.\n2.2.3 Are document management systems used? \u2013 Yes.", "hash": "01fe14cd14c714220d73d512ea9c27a5", "id": 9}, {"snippet_links": [{"key": "to-ensure", "type": "clause", "offset": [9, 18]}, {"key": "personal-data", "type": "clause", "offset": [88, 101]}, {"key": "it-system", "type": "definition", "offset": [142, 151]}, {"key": "security-events", "type": "clause", "offset": [183, 198]}, {"key": "security-logs", "type": "clause", "offset": [293, 306]}], "samples": [{"hash": "3R95uJ8WMC0", "uri": "/contracts/3R95uJ8WMC0#entry-control", "label": "Data Processing Agreement", "score": 33.7454528809, "published": true}, {"hash": "l6qoSc72Enl", "uri": "/contracts/l6qoSc72Enl#entry-control", "label": "Data Processing Agreement", "score": 33.5968704224, "published": true}, {"hash": "kngJEnE8ldG", "uri": "/contracts/kngJEnE8ldG#entry-control", "label": "Data Processing Agreement", "score": 33.1995315552, "published": true}], "size": 3, "snippet": "Measures to ensure that it can be subsequently reviewed and determined if and from whom Personal Data was entered, altered, or deleted in the IT system:\n(a) Systems are monitored for security events to ensure quick resolution.\n(b) Logs are centrally stored and indexed. Critical logs, such as security logs, are retained for at least 2 months. Logs can be traced back to individual unique usernames with timestamps to investigate nonconformities or security events.", "hash": "cfe8fe13adb7cacc260bd1a0d2b45f83", "id": 10}], "next_curs": "ClYSUGoVc35sYXdpbnNpZGVyY29udHJhY3RzcjILEhZDbGF1c2VTbmlwcGV0R3JvdXBfdjU2IhZlbnRyeS1jb250cm9sIzAwMDAwMDBhDKIBAmVuGAAgAA==", "clause": {"title": "Entry control", "size": 93, "children": [["", ""], ["incident-response-management", "Incident Response Management"], ["supervision-and-accompaniment-of-third-parties", "Supervision and accompaniment of third parties"], ["electronic-door-security", "Electronic door security"], ["controlled-key-assignment", "Controlled key assignment"]], "parents": [["confidentiality", "Confidentiality"], ["miscellaneous", "Miscellaneous"], ["eu-general-data-protection-regulation", "Eu General Data Protection Regulation"], ["assistance", "Assistance"], ["extent-of-disposition", "Extent of Disposition"]], "id": "entry-control", "related": [["subsidy-control", "SUBSIDY CONTROL", "SUBSIDY CONTROL"], ["primary-contacts", "Primary Contacts", "Primary Contacts"], ["job-control", "Job Control", "Job Control"], ["registry-continuity", "Registry Continuity", "Registry Continuity"], ["traffic-control", "Traffic Control", "Traffic Control"]], "related_snippets": [], "updated": "2025-07-15T00:51:33+00:00"}, "json": true, "cursor": ""}}