Technical and organizational measures

The technical and organizational measures (TOM) set out which suitable measures Dualoo (hereinafter referred to as the Provider) takes in accordance with the applicable privacy policy (including Art. 8 FADP), in particular to ensure data security appropriate to the risk. These are regularly reviewed by the Provider and updated as necessary.

The contents of this technical and organisational measures have been translated automatically. Only the original in German has legal validity. The online version in German can be found HERE.

Updated: December 4, 2025

Table of contents

1. Technical requirements

The Provider offers the Dualoo software (hereinafter referred to as the Application) as Software as a Service (SaaS). The application is executed via the browser(https://login.dualoo.com). Documents generated by the application are saved on the server as Microsoft Office (docx) and Adobe (PDF) files. All data is stored in UTF-8 character encoding, which allows all languages to be represented. Internet access with a supported web browser and an e-mail address are required to use the application. Otherwise, no installation is necessary.

2. Supported desktop browsers

Chrome: latest version
Firefox: latest version
Edge: latest version
Safari: latest version

3. data processing according to GDPR and DSG

If the user processes or uses personal data through the application, the internal organization must be designed in accordance with data protection law (GDPR and DSG) in such a way that it meets the special requirements of data protection. The provider supports users in this.


By definition, commissioned data processing is carried out by the provider. As the provider is covered by commissioned data processing, the following points, which are important for commissioned data processing, are listed in this document.


The Dualoo standard contract for commissioned data processing is based on the Dualoo Terms of Use, Privacy Policy and the technical and organizational measures. This is concluded with the agreement to the terms of use.


If deviating changes or a separate contract are required, the costs amount to CHF 300 / hour (at cost), which are necessary for checking or drawing up a contract on the part of the provider.

4. Access control

Access to the provider’s premises is secured by employee ID cards and personal keys. Access to the application, or rather to the data, only works via a personal login using a user name (e-mail address) and password. The password of each individual user is encrypted (hash function) and stored in the database.
User data is stored on the ISO-27001-protected server and not on employees’ local devices, which increases data security. The provider does not have access to user data unless explicit permission has been granted.

MFA (multi-factor authentication): The provider makes it possible to protect each user account with MFA and allows its customers (companies) to enforce this for their employees (users).

Protection of end devices and access data: Users are responsible for adequately protecting their devices (e.g. computers, tablets, smartphones) as well as their access data (passwords, authentication procedures). The Provider cannot be held liable for damage caused by inadequate protection of these devices or access data.

5. Access control

Individual rights can be assigned within the application (what can which user do). The customer (e.g. administrator in the company) is fully responsible for internal access authorization. He controls which access authorizations the other users (e.g. employees) have.
The provider, in turn, is responsible for external access to the data by ensuring that the data is appropriately protected and encrypted.

6. Pseudonymization and encryption

All data transmitted between the user and the server is encrypted and transmitted using TLS 1.2 or higher with the current configuration.


The provider automatically anonymizes personal data of applicants and supports customers in complying with the legal framework. This is done in 2 steps:

  1. For anonymisation of the data after set deadlines, see: https: //help.dualoo.com/de/articles/8153134
  2. A further 90 days after a record has been anonymized, all emails, documents (such as CVs, letters of motivation, handouts of ratings, etc.) and comments are irrevocably deleted from the database.

7. Input control / logging

To ensure the traceability of entries, changes and access to personal data, all relevant system activities are automatically logged. In particular, the provider or hosting provider records technical access data such as IP address, time of access, user ID and system information (e.g. browser type and operating system).

Logging is used for IT security, system integrity, error analysis and the investigation of misuse or fraud. Log data is stored securely, checked regularly and evaluated exclusively by authorized personnel.

The maximum retention period is 12 months, after which the data will be deleted or anonymized, unless legal or security-related reasons require longer retention.

8. Availability control and resilience

The storage and processing of data takes place in the data centers of the hosting provider commissioned by the provider. The hosting providers commissioned by the provider are listed in the separate document “Third-Party Subprocessors”.

The data centers have a technical and organizational level of protection appropriate to the risk to ensure the availability, resilience and recoverability of the systems and data (in accordance with Art. 32 para. 1 lit. b GDPR / Art. 8 FADP). Operation takes place in ISO 27001- and ISO 9001-certified environments with multiple redundant power, network and storage supplies.

Regular data backups, continuous system monitoring and automated failover and restart mechanisms are used to ensure system availability.

The effectiveness and functionality of these measures is regularly reviewed and improved where necessary.

Backups: Regular, automated data backups are performed to ensure the availability, integrity and recoverability of customer data. Backups are made every hour and are deleted after seven days at the latest. In addition, an archive copy is created every month and stored for a maximum of six months. Data is stored in encrypted form in data centers located in Switzerland or the EU/EEA. The recoverability of the backups is regularly checked and documented.

Virus protection: The customer bears sole responsibility and is obliged to check the data received and transmitted for viruses. The Provider also scans the transmitted files for viruses. The provider cannot be held liable for this, but helps to reduce the risk.

Energy supply / sustainability: The provider keeps its CO₂ emissions as low as possible and offsets unavoidable emissions by supporting carefully selected climate protection projects.

The proof of the pudding is in the eating.

The proof of the pudding is in the eating.