Legal
Information security policy
Because we sell data protection, we also write our own practices down openly. This text summarises the principles we apply as an organisation.
Last updated: 2026-09-21
The trade name, registry number and phone details in this text will be updated once the company registration details are complete. Please use our email address for current contact.
Approach
We treat information security not as a separate project but as part of every piece of work we do. We apply the controls we recommend to clients in our own processes first.
Access management
Access rights are granted according to job definition and the principle of least privilege applies.
Privileged accounts are managed separately, shared passwords are not used and multi-factor authentication is mandatory.
Permissions are reviewed periodically; accounts are updated on role change and departure.
Logging and monitoring
System access and permission changes are recorded. Records are stored so their integrity holds, for the defined period.
Protection of client data
Access to client systems is made only within the scope defined in the contract and limited to the time required.
Real personal data is not used in development and test environments; masking or synthetic data is applied where needed.
Supplier security
The infrastructure and software providers we use are assessed on their data processing scope and security commitments; contracts are signed with them as data processors.
Incident response
A defined response flow runs for security incidents: detection, containment, impact assessment, notification and remediation.
Where a personal data breach occurs, the notification obligations required by legislation are fulfilled.
Awareness
The team is briefed regularly on information security and personal data protection. For new joiners this briefing is part of onboarding.

