gynorms
Our servicesPricingOur workInsightsCompany
Client portal Start a conversation

Legal & help

Legal

Billing & paymentsTerms of serviceRefund & cancellationPrivacy policyInformation security

Help

Client support

LEGAL

Information
security policy.

Our policy for protecting company, customer, and sensitive information. Last updated September 2026.

In this policy

01 Introduction02 Information security policy03 Acceptable use04 Disciplinary action05 Compliance and security documentation06 Protecting stored data07 Information classification08 Access to sensitive data09 Physical security10 Protecting data in transit11 Disposal of stored data12 Security awareness13 Network and system security14 Passwords and authentication15 Vulnerability, configuration, and change management16 Logging, secure development, and testing17 Incident response18 Roles and responsibilities19 Third parties and access management20 Wireless and encryption21 Acknowledgement and records

1. Introduction

This policy governs the protection of confidential company information. It is issued to employees and contractors, reviewed at least annually, and updated when security standards or the operating environment change.

2. Information security policy

Gynorms protects sensitive information and customer data through appropriate safeguards, limited access, secure handling practices, and timely incident reporting. Personnel must protect accounts and passwords, lock unattended screens, keep desks clear, and obtain approval before connecting new hardware, software, or third-party services.

3. Acceptable use

Company technology and communications systems must be used responsibly and lawfully. Users must use approved devices and authenticated accounts, prevent unauthorized access, avoid sharing credentials, use secure screen locks, and take particular care with portable devices and unexpected email attachments.

4. Disciplinary action

Violations of this policy or related standards may result in disciplinary action, up to and including termination of employment or contract, subject to applicable law.

5. Compliance and security documentation

The company identifies the information it processes and the laws, regulations, industry standards, assets, network diagrams, data flows, and repositories that apply. Security procedures, standards, asset lists, and diagrams are maintained and reviewed for accuracy at least annually.

6. Protecting stored data

Sensitive data must be protected against unauthorized use and securely, irrecoverably disposed of when no longer needed. Payment card data is masked where the full number is not required. Track data, card verification values, PINs, and encrypted PIN blocks must never be stored.

7. Information classification

Information and media are classified and labeled according to sensitivity. Confidential information, including account and cardholder data, receives the highest protection; internal-use information is protected from unauthorized disclosure; public information may be freely shared.

8. Access to sensitive data

Access is authorized, role-based, and limited to the least privilege necessary for a legitimate business need. Privileged access is restricted, access rights are reviewed, and sensitive payment data is displayed only in a masked form. Service providers that can access or affect sensitive data are subject to due diligence, written responsibilities, and compliance monitoring.

9. Physical security

Physical and electronic media containing sensitive information are restricted to authorized personnel. Visitors are identified and escorted in sensitive areas; devices and payment terminals are inventoried, protected from tampering, inspected periodically, and maintained securely.

10. Protecting data in transit

Sensitive data must be protected when transported physically or electronically. Cardholder data is not sent through ordinary email, chat, or other end-user messaging tools. Any approved transmission uses strong encryption and controlled, tracked delivery methods.

11. Disposal of stored data

Data is securely disposed of when no longer required. Paper records are cross-cut shredded, incinerated, or pulped. Electronic media is securely wiped, degaussed, or physically destroyed so information cannot be recovered; material awaiting destruction is kept in restricted, locked storage.

12. Security awareness

Employees and contractors receive security awareness training at hire and at least annually, including phishing awareness and secure handling procedures. Personnel acknowledge that they have read and understood this policy, and people handling sensitive data may be subject to appropriate background checks where permitted by law.

13. Network and system security

Firewalls, network segmentation, documented configurations, default-deny inbound rules, and regular firewall-rule reviews protect company systems. Systems use secure configuration standards, supported software, anti-malware protection, timely patches, and controlled remote and administrative access.

14. Passwords and authentication

Each user receives a unique account. Passwords must be kept secret, meet defined strength requirements, and be managed through formal controls. Shared or generic accounts are not permitted except where explicitly authorized with compensating controls.

15. Vulnerability, configuration, and change management

The company maintains vulnerability scanning, risk ranking, remediation, secure configuration baselines, and controlled change processes. Changes are assessed, authorized, tested, documented, and reviewed so that security is sustained throughout the system lifecycle.

16. Logging, secure development, and testing

Security-relevant events are logged, protected, reviewed, and retained in accordance with applicable standards. Applications are developed with security requirements, code review, testing, and separation of development and production environments. Penetration testing and remediation are performed on a regular basis and after significant changes.

17. Incident response

Suspected security incidents must be reported without delay to the designated incident-response contact. The company maintains procedures to contain, investigate, document, notify, recover from, and learn from security incidents, including escalation to affected partners or payment brands where required.

18. Roles and responsibilities

The security officer or equivalent oversees security policies, risk analysis, awareness, incident response, vulnerability management, and service-provider oversight. Technology, network, system, application, human-resources, and legal functions each maintain the controls and reviews assigned to them.

19. Third parties and access management

Third parties providing critical services are subject to appropriate agreements, due diligence, security obligations, and continuity expectations. User access follows documented onboarding, change, periodic-review, and prompt offboarding procedures.

20. Wireless and encryption

Unauthorized wireless devices and networks are prohibited. Approved wireless use must be securely configured, inventoried, and periodically tested. Sensitive stored payment data is rendered unreadable with strong encryption and properly managed, rotated, and separated encryption keys.

21. Acknowledgement and records

Personnel acknowledge their obligation to protect company and customer information, return information at the end of their engagement, and report suspected policy violations. The company maintains approved-device and service-provider records as part of its security governance.

LET’S BUILD WHAT’S NEXT

Make your next
move matter.

Start a conversation
gynorms

Technical clarity for ambitious organizations navigating technology, data, and AI.

support@gynorms.com

Services

Technology strategyData foundationsApplied AIAll services

Explore

PricingJoin the networkCareersOur workInsightsHow we workAbout Gynorms

For clients

Client portalClient support

Legal

Billing & paymentsTerms of serviceRefund & cancellationPrivacyInformation security
gynorms

© 2026 Gynorms. All rights reserved.

BillingPrivacyTermsContact