General information
Contact
Section titled “Contact”Both the contacts of News Innovativ GmbH and the customer’s contacts are recorded in the separate document “Technical Agreements”, which is made available to the customer.
Support and maintenance
Section titled “Support and maintenance”Access to the maXzie installation (server and databases) is only granted by News Innovativ GmbH after prior confirmation in text form (e-mail) from the customer. All employees listed as contacts are authorized to commission support and maintenance activities as well as to provide information that may contain sensitive data.
If, in the opinion of a support employee at News Innovativ GmbH, the assignment primarily concerns aspects of user support or technical configuration, the assignment must come from a person listed as [contact] (#contact).
For the safety of the customer, the following is checked by the News Innovativ support staff when an order is placed:
- Is it ensured that this is the authorized person on the customer side?
- Does the person have the required authorization?
For this purpose, News Innovativ GmbH can call you back using the above-mentioned telephone numbers. News Innovativ GmbH is entitled to record and save the verification telephone call with the support or change requests for verification purposes.
On the part of News Innovativ GmbH, administrative work is carried out exclusively by the employees listed as contacts. News Innovativ GmbH guarantees that its employees comply with the data protection agreement between the customer and News Innovativ GmbH. Otherwise, the agreements between the customer and News Innovativ GmbH apply unchanged.
Access for monitoring purposes, server checks, application, system and security updates, etc. is carried out by News Innovativ GmbH without being commissioned by the customer.
Server systems and network integration
Section titled “Server systems and network integration”Architecture
Section titled “Architecture”maXzie is a web application, which means access from all users, including mobile devices, is via HTTPS and a web browser.
A maXzie instance consists of the following services:
- An application server based on the Java Virtual Machine (OpenJRE)
- A database server (PostgreSQL)
Access by users
Section titled “Access by users”maXzie is a web application, which means access from all users, including mobile devices, is via HTTPS and a web browser. The end user can access maXzie via the corresponding URL.
The customer’s IT is responsible for providing end users with this access by appropriately configuring the DNS entry for the corresponding maXzie URL and, if necessary, taking further necessary network integration steps (e.g. routing, firewalls, VPNs).
Furthermore, if necessary, the customer’s IT generates suitable SSL certificates upon request from News Innovativ GmbH.
Maintenance
Section titled “Maintenance”Restore
Section titled “Restore”If necessary, a restore will be carried out in collaboration with News Innovativ GmbH.
Support
Section titled “Support”Support process: User support
Section titled “Support process: User support”Questions and feedback from end users should preferably be addressed as follows:
- End users first direct their questions or requests for support to the responsible internal key users.
- If the internal key users cannot provide the necessary support, this will be forwarded to News Innovativ GmbH support.
- If necessary, News Innovativ GmbH will contact customer support for support or vice versa.
Change in support staff at News Innovativ GmbH
Section titled “Change in support staff at News Innovativ GmbH”The list of News Innovativ GmbH support employees can be found in the document Technical Agreements. The following steps are carried out for new support employees at News Innovativ GmbH:
- News Innovativ GmbH informs the customer about new support employees.
- The customer sends these employees the necessary declarations of confidentiality for signing.
- New support employees from News Innovativ GmbH sign these declarations and send them back to the customer.
- News Innovativ GmbH updates the document Technical Agreements and sends the new version to everyone involved.
Change in customer support staff
Section titled “Change in customer support staff”The list of customer support staff can be found in the Technical Agreements document. The following steps are taken for new customer support representatives:
- The customer informs News Innovativ GmbH support about the new employees and their contact details. The customer confirms in writing that they may commission maintenance work from News Innovativ GmbH support and obtain information that may require access to data worthy of protection.
- News Innovativ GmbH updates the document Technical Agreements and sends the new version to everyone involved.
Change of superusers
Section titled “Change of superusers”Information about the concept of superusers can be found in the following chapter. The superuser table can be found in the document Technical Agreements. To change the superuser, the following steps are carried out:
- The customer informs News Innovativ GmbH support about a change in superusers.
- For new superusers, the customer confirms in writing that new people in the superuser list can override all access restrictions within the maXzie software.
- News Innovativ GmbH configures the current list of super users in maXzie.
- News Innovativ GmbH continues to update the document Technical Agreements and sends the new version to everyone involved.
Roles and access permissions at the user level
Section titled “Roles and access permissions at the user level”maXzie contains several concepts that regulate the authorization or restriction of reading and writing access to sensitive data via the user interface.
Any use of maXzie via the user interface is only possible after a login that links the session to an employee managed by maXzie. Any decision as to whether access to data is permitted is based on the identity of the employee assigned to the active session.
During installation, News Innovativ GmbH can mark certain employees identified by their login name as superusers. Once logged in to the user interface, superusers have no access restrictions, regardless of other configurations. Superusers can therefore read and write all data of all employees. Some configurations, such as defining key performance indicators and managing target templates, are only available to superusers. The current list of configured superusers is kept in the Technical agreements document.
Employees who are not superusers can only access data linked to themselves without further configuration. Access beyond this is configured by the superuser within the user interface. This is done using entries in the “Permissions” page and the assignment of employees to groups, which are also created by superuser.