Platform Policy
Security & Data Processing
Last updated June 16, 2026
This page summarizes how the [PLATFORM NAME] Service protects and processes data. It supports our Privacy Policy and any data-processing agreement between us and account holders.
1. Roles
For Customer Data you enter about your own customers and staff, you are the controller and we act as your processor, handling that data only to provide the Service and on your instructions reflected in our agreement.
2. Security Measures
- Encryption — data is encrypted in transit using current TLS. [Confirm encryption-at-rest details with your hosting provider.]
- Access control — role-based access, authentication, and the principle of least privilege for staff.
- Network & application security — hardened hosting, input validation, and routine patching.
- Backups — regular backups to support recovery. [Confirm backup frequency & retention.]
- Monitoring — logging of key activity to detect and investigate issues.
3. Subprocessors
We use vetted third-party providers (for example, cloud hosting, mapping, messaging, and payment processing) to deliver the Service. We require subprocessors to maintain appropriate safeguards. A current list is available on request: [security@yourcompany.com].
4. Payment Data
Card payments are handled by a third-party payment processor. We do not store full card numbers; the processor maintains PCI-DSS compliance for the handling of cardholder data.
5. Incident Response
We maintain procedures to detect, investigate, and respond to security incidents. If a breach affecting your Customer Data occurs, we will notify you without undue delay and as required by law, and cooperate in your own notification obligations.
6. Your Responsibilities
- Keep credentials confidential and use strong, unique passwords.
- Grant access only to staff who need it and remove access promptly when roles change.
- Promptly report suspected unauthorized access to [security@yourcompany.com].
7. Data Location & Retention
Data is processed in the United States. Retention follows our Privacy Policy and your agreement; on termination, data is available for export for [30] days and then deleted in the ordinary course unless law requires retention.