We are committed to safeguarding the confidentiality, integrity, and availability of all data processed through our website and services. This Security Statement outlines the technical and organizational measures we apply to protect customer information against unauthorized access, misuse, or disclosure.
All sensitive communications, including login credentials and payment details, are protected using SSL/TLS encryption.
Payment transactions are processed exclusively through encrypted channels, ensuring that third parties cannot intercept or read transmitted data.
Access to personal data is restricted to authorized personnel only.
Role-based permissions and authentication mechanisms are enforced to minimize exposure.
Administrative accounts are protected with strong password policies and multi-factor authentication where applicable.
Our servers maintain log files that record access attempts, system activity, and potential anomalies.
Logs are regularly reviewed to detect suspicious behavior or unauthorized access attempts.
Customer and contract data are stored only as long as necessary to fulfill contractual obligations.
Data is deleted or anonymized once the business relationship ends, subject to legal retention requirements.
Regular backups are performed to ensure data availability in case of hardware failure or cyber incidents.
Disaster recovery procedures are tested periodically to guarantee service continuity.
Data shared with third parties (e.g., delivery companies, payment processors) is limited to what is strictly necessary to fulfill contractual obligations.
All third-party providers are required to comply with applicable data protection and security standards.
Systems are updated regularly with security patches to mitigate known vulnerabilities.
We employ industry-standard practices for vulnerability scanning and remediation.
Our security practices align with GDPR requirements and other applicable data protection laws.
Customers retain rights to access, correct, delete, or port their data, as outlined in our Privacy Policy.
In the event of a security breach, affected parties will be notified promptly in accordance with legal obligations.
A formal incident response plan ensures rapid containment, investigation, and remediation.