Security Policy
1. Introduction
Data Vault considers the security of the information managed through its website as a fundamental pillar of its business operations. This policy aims to protect the personal data of visitors, ensure the integrity and availability of information, and comply with applicable data protection legislation, particularly Regulation (EU) 2016/679 (GDPR).
2. Information Security Principles
Our approach is based on three fundamental principles: confidentiality, integrity, and availability. Confidentiality is ensured by restricting access to information only to authorized individuals. Integrity is maintained by protecting data from unauthorized modifications, alterations, or loss. The availability of our systems and services guarantees that information is always accessible to users and partners who need it.
3. Technical Security Measures
To protect our website, we implement advanced technical security measures. Connections to the site are established via HTTPS protocol, ensuring encrypted communication. Additionally, we utilize firewall technologies and mechanisms to prevent Distributed Denial of Service (DDoS) attacks. All systems and software are regularly updated to eliminate known vulnerabilities. Administrator access is secured with strong passwords and two-factor authentication, while regular secure backups are performed and stored safely for recovery purposes.
4. Organizational Measures and Training
Security is not limited to technology. All Data Vault employees receive regular training on digital security and data protection. We enforce strict access management procedures and implement information handling policies with clearly defined roles and responsibilities. Our partners and suppliers are bound by confidentiality agreements, and we adopt a business continuity plan to ensure the uninterrupted operation of our services even during crises.
5. Compliance with the General Data Protection Regulation (GDPR)
Data Vault processes personal data only in a lawful and transparent manner. Website visitors are informed about the data processing and have the right to access, rectify, delete, and restrict the use of their personal data. We do not share personal data with third parties without a legal or contractual basis and apply the principle of data minimization, collecting only the necessary information. Where required, Data Protection Impact Assessments (DPIAs) are conducted to evaluate risks.
6. Use of Cookies and Analytics
The Data Vault website uses cookies to maintain technical functionality, optimize the user experience, and anonymously analyze traffic. Visitors have the ability to manage their cookie settings and choose whether to enable them. The use of analytics tools such as Google Analytics is conducted in a way that ensures the anonymity of IP addresses, in full compliance with European legislation.
7. Security Incident Response
Data Vault has an organized security incident management plan. Each incident is recorded, assessed and promptly addressed by a specialized team. If required, the competent authorities are informed within 72 hours and, when necessary, the data subjects are also notified. Corrective actions are implemented without delay, with the aim of restoring security and preventing future incidents.
8. Policy Audits and Review
This security policy is reviewed at least annually or when significant changes in technology or the legal framework occur. In addition, regular internal audits are conducted and we collaborate with external experts to conduct security tests to identify potential weaknesses in our systems and take appropriate preventive measures.
9. Contacting Data Vault
For any issue related to website security or personal data protection, users can contact us at info@datavault.gr. You can also call [Contact Number] or visit us at Artis 1, Athens.
10. Commitment to Security and Trust
Data Vault operates with responsibility, professionalism and transparency, offering digital management solutions that fully respect the security and privacy of each partner. For us, security is not just a technical obligation, but an essential part of the reliability and quality of the services we offer.