Data Security Statement

Last updated: 10th May 2018

We have put in place appropriate security measures, both technical and organisational, to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. This Data Security Statement details and describes our technical and organisational data security measures. This Statement is referred to and forms part of our Data Protection and Privacy Policy, which is a separate document.

Server Security

We use a secure server. All supplied Personal Data is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our database to be only accessed by those authorised with special access rights to our systems, who are required to keep the information confidential.

Our application relies upon the physical and data security policies of Amazon Web Services, which you can read about here – https://aws.amazon.com/security/

Physical address of the Data Servers holding Users’ Data

Our server infrastructure is located in Dublin, Ireland, at a secure Amazon Web Services (AWS) data centre.

Our Data Storage Suppliers

We ensure that all third parties that we work with to process personal data comply with GDPR.

Encryption

All of the Personal Data that we hold is encrypted at rest, and all communications between our servers and database is encrypted. All our outbound emails are SSL/TLS encrypted.

 

Data Backups

We back up our live database every 5 minutes to two Amazon Web Services facilities based in the EU region. In the event of service failure due to a physical or technical incident, our full system can be restored and redeployed into an unaffected region within 30 minutes.

Your Passwords

Your passwords are protected by a strong one way hash algorithm. This means our employees and Associates can’t see your passwords, and there is no way to retrieve them if forgotten. If you lose your password, you must reset it through triggering an automated email.

 

Financial Transaction Security

Our payment processing vendor, Stripe, uses security measures to protect your information during and after your transaction. Stripe is certified as compliant with the appropriate card association security initiatives.

Access to the Data by us and our Associates (see Definitions)

It is possible for us, and occasionally our Associates, to access the Personal Data that we process on your behalf, but strict security protocols and processes mean that can only happen when essential for the purposes of providing the Services that we agree to provide to you, or when required by law.

Secure Working Practices for Employees and Associates

We ensure that we, and all our employees and Associates comply with the following Data Security measures when working with Personal Data:

  1. Where any Personal Data is to be erased or otherwise disposed of for any reason (including where copies have been made and are no longer needed), it should be securely deleted and disposed of. Hardcopies should be shredded, and electronic copies should be deleted securely.
  2. Personal Data may be transmitted over secure networks only; transmission over unsecured networks is not permitted in any circumstances;
  3. Personal Data may not be transmitted over a wireless network if there is a wired alternative that is reasonably practicable;
  4. Inbound emails (unsubscribe requests, bounces, etc) should be processed according to the user request and then deleted. Emails received personally should be deleted as soon as dealt with.
  5. No Personal Data shall be sent by facsimile transmission;
  6. Where Personal Data is transferred in hardcopy form it should be passed directly to the recipient;
  7. All hardcopies of Personal Data, along with any electronic copies stored on physical, removable media should be stored securely in a locked box, drawer, cabinet or similar;
  8. No Personal Data may be transferred to any employees, agents, volunteers, contractors, or other parties, whether such parties are working on our behalf or not, without the authorisation of the senior executive responsible for Data Protection;
  9. Personal Data must be handled with care at all times and should not be left unattended or on view to unauthorised employees, volunteers, agents, sub-contractors or other parties at any time;
  10. If Personal Data is being viewed on a computer screen and the computer in question is to be left unattended for any period of time, the user must lock the computer and screen before leaving it;
  11. No Personal Data should be transferred to any device personally belonging to an employee or volunteer and Personal Data may only be transferred to devices belonging to agents, contractors, or other parties working on our behalf where the party in question has agreed to comply fully with the letter and spirit of this Policy and of the Data Protection Legislation (which may include demonstrating to us that all suitable technical and organisational measures have been taken);
  12. All Personal Data stored electronically should be backed up with appropriate software based backup systems. All backups should be encrypted. All electronic copies of personal data should be stored securely using passwords and data encryption;
  13. All passwords used to protect Personal Data should be changed regularly and should not use words or phrases that can be easily guessed or otherwise compromised. All passwords must contain a combination of uppercase and lowercase letters, numbers, and symbols;
  14. Under no circumstances should any passwords be written down or shared between any employees, volunteers, agents, contractors, or other parties working on our behalf. If a password is forgotten, it must be reset using the applicable method.

Organisational Measures to Ensure Data Security

We also ensure that the following measures are taken by our Company with respect to the collection, holding, and processing of Personal Data:

  1. We limit access to your Personal Data to only those employees, agents, contractors and other third parties who have a business need to know such data. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality;
  2. We maintain a list of those employees, volunteers, agents, sub-contractors or other parties who have access to Personal Data controlled by the Company, and which data is accessed by whom, and this list will be kept up-to-date;
  3. All employees, volunteers, agents, contractors, or other parties working on our behalf are made fully aware of both their individual responsibilities and the Company’s responsibilities under the Regulation and under this Policy, and are provided with a copy of this Policy;
  4. No Personal Data may be shared informally and if an employee, agent, volunteer, sub-contractor, or other party working on our behalf requires access to any personal data that they do not already have access to, such access should be formally requested from the senior executive responsible for data protection;
  5. All employees, volunteers, agents, contractors, or other parties working on our behalf handling Personal Data will be appropriately trained to do so;
  6. All employees, volunteers, agents, contractors, or other parties working on our behalf handling Personal Data will be appropriately supervised;
  7. Methods of collecting, holding and processing Personal Data shall be regularly evaluated and reviewed;
  8. The performance of those employees, volunteers, agents, contractors, or other parties working on behalf of the Company handling Personal Data shall be regularly evaluated and reviewed;
  9. All employees, volunteers, agents, contractors, or other parties working on our behalf handling Personal Data will be bound to do so in accordance with the principles of the Data Protection Legislation and this Policy by contract;
  10. All agents, contractors, or other parties working on our behalf handling Personal Data must ensure that any and all of their employees who are involved in the processing of Personal Data are held to the same conditions as those relevant employees of the Company arising out of this Policy and the Data Protection Legislation;
  11. Where any agent, contractor or other party working on our behalf handling Personal Data fails in their obligations under this Policy that party shall indemnify and hold harmless the Company against any costs, liability, damages, loss, claims or proceedings which may arise out of that failure.