Information security
Peter Park operates systems for licence-plate-based parking management. These systems process personal data, including licence plates, vehicle images and payment data.
We run an Information Security Management System (ISMS) modelled on the structure of ISO/IEC 27001. It covers our platform, the associated devices at the parking sites, and the processes by which we develop and operate them. Our information security policy commits us to protecting confidentiality, integrity and availability, to risk-based management, to compliance with legal requirements, and to continual improvement.
Responsibility for the ISMS lies with the Information Security Management Leader, reachable at info-sec@peter-park.de.
How we protect systems and data
Access rights are limited to what is necessary, assigned by role, and reviewed. Multi-factor authentication is used for access to administrative systems.
Data in transit is encrypted with TLS 1.2 or higher. Data in our production environment is stored encrypted. Staff endpoints are centrally managed and their storage media encrypted.
New joiners are bound to confidentiality and trained on information security.
Changes are reviewed before release under the four-eyes principle. Source code and dependencies are scanned automatically for vulnerabilities. We also have our applications tested externally by specialist providers.
Security-relevant events in the production environment are logged and analysed. Vulnerabilities are assessed and prioritised under a documented procedure and tracked through to remediation. Production data is backed up, and recovery procedures are documented.
Hosting, data storage and privacy
We obtain hosting and other services from providers in the European Economic Area. We use cloud services in European regions.
Providers are assessed before engagement and contractually bound to data protection and security requirements. What governs a specific processing operation is the applicable privacy policy, the data processing agreement, and the sub-processor information.
Personal data is deleted once the purpose of processing has ceased and no retention obligation applies. Details of the processing, retention periods, our Data Protection Officer and data subject rights are set out in our privacy policy.
Security incidents and reporting a vulnerability
A documented process governs security incidents, with defined roles and escalation levels. The process covers notification duties towards affected customers and, in the case of a personal data breach, towards the competent supervisory authority under Art. 33 GDPR.
If you find a vulnerability in one of our systems, please report it to info-sec@peter-park.de before publishing any details. We will acknowledge receipt and tell you how we intend to proceed. Please limit your testing to what is necessary to demonstrate the finding, and do not access data belonging to others.
ISMS modelled on the structure of ISO/IEC 27001
Providers and cloud regions within the European Economic Area
TLS 1.2 or higher in transit, encrypted storage
Further security documentation, completed security questionnaires and evidence are available to customers and prospects on request, subject to a confidentiality agreement where appropriate.