Technical and Organizational Measures (TOMs)
Security measures Carewell implements to protect personal data.
Last updated · Version ·
2026-06-24 Applies to: Carewell Work and Carewell Pool
This document describes the technical and organizational measures (TOMs) implemented by Carewell SA to ensure the security and confidentiality of personal data processed in connection with its services. These measures draw on recognised information-security best practices, in particular the ISO/IEC 27001 standard.
1. Hosting and infrastructure
- Application data and databases are hosted in Switzerland by Infomaniak and Exoscale.
- All communications with Carewell services are encrypted in transit (TLS 1.2+).
- Data is encrypted at rest by the managed storage solutions (AES-256 encryption).
- Automatic daily database backups (managed service with point-in-time recovery), stored in Switzerland.
2. Access control
- Strong authentication for Carewell staff (mandatory MFA on sensitive tools).
- Mandatory two-factor authentication (2FA) on the platform’s administration interface.
- Access to data limited to staff with a justified operational need (need-to-know basis); centralised management of roles and permissions (RBAC).
- Periodic access reviews and immediate revocation when a staff member leaves.
- Environment segregation (production / pre-production / development).
3. Application security
- Protection against OWASP Top 10 attacks (SQLi, XSS, CSRF, etc.).
- Anti-spam and anti-bot protection via Cloudflare Turnstile on login forms.
- Rate limiting on sensitive operations.
- Systematic code audits and pull-request reviews.
- Frameworks and software dependencies kept up to date (patch management).
- Responsible vulnerability disclosure policy: dpo@carewell.ch.
4. Logging and traceability
- Application audit log: actions performed on the platform (creations, modifications, deletions) are recorded with their author, the object concerned and the details of the changes; retained for 12 months, then automatically purged.
- Logging of actions performed through the administration interface.
- Login history and last-activity records for user accounts.
- Application logs with daily rotation (14-day retention).
- Continuous error monitoring with alerting, infrastructure monitoring and availability probes.
5. Data retention and deletion
- Retention periods defined per data category and enforced through automated purges (for example: notifications under a tiered policy of 14 to 365 days; past scheduling data aggregated then deleted after 90 days; audit log purged after 12 months).
- Soft deletion followed by permanent deletion of records at the end of the retention period.
- The periods applicable to personal data are described in the privacy policy.
6. Incident management
- Documented security incident response procedure.
- Notification to the Controller in the event of a Personal Data Breach as soon as possible and, in any event, within 48 hours, in accordance with Art. 24 para. 3 revFADP. This 48-hour deadline is an internal commitment by Carewell, stricter than the 72-hour standard set by the GDPR.
7. Business continuity
- Redundancy of critical components (replicated application instances, managed database with point-in-time recovery).
- Disaster recovery plan being formalised (RTO/RPO objectives).
8. Awareness and training
- Mandatory security and data protection training for all new staff members.
- Continuous awareness-raising (simulated phishing campaigns, refreshers).
9. Sub-processors
All sub-processors with access to Personal Data are bound by a data processing agreement requiring at least an equivalent level of security. See the public lists: Carewell Work and Carewell Pool.
10. Contact
For any security-related question: dpo@carewell.ch.