Seen CRM
Information Security Policy
| Document number | SEEN-POL-01 |
|---|---|
| Version | 1.0 |
| Effective date | On approval |
| Policy owner | Seen CRM Management |
| Approved by | Seen CRM Management |
| Classification | Public |
| Next review | Within 12 months of the effective date |
1. Purpose
This policy sets out how Seen CRM protects the information its customers entrust to it, and the principles that govern all of Seen CRM's security practices.
2. Scope
This policy applies to the Seen CRM platform, the information it processes, and all personnel and service providers who support it.
3. Policy
- Governance. Seen CRM maintains information security policies approved by management and reviews them at least once a year.
- Data separation. Each customer's data is kept logically separate. No customer can access another customer's data.
- Access. Access is granted on a least-privilege basis. Multi-factor authentication is required for all administrative access. Access is removed promptly when it is no longer needed.
- Encryption. Data is encrypted in transit and at rest. Sensitive personal data receives additional field-level encryption.
- Secure development. Every change to the platform is reviewed and automatically tested, including security testing, before release.
- Monitoring. The platform is monitored continuously. Personal data is removed from system error reports.
- Incidents. Security incidents are handled under the Incident Response Policy. Affected customers are notified without undue delay, in line with the Personal Data Protection Law.
- Continuity. Data is backed up and can be restored under the Backup and Recovery Policy.
- Service providers. Providers that process customer data are selected and reviewed under the Vendor Management Policy.
4. Responsibilities
Management approves this policy and any exception to it. All personnel and service providers must comply with it.
5. Exceptions
Any exception must be approved in writing by management, with a stated reason and an end date.
6. Review
This policy is reviewed at least once a year, and after any major security incident.
7. Contact
Questions about this policy: info@seencrm.com