Information Security Policy
This document is under legal review and may change.
1. Our approach
We protect the personal and business information entrusted to us with practical safeguards proportionate to its sensitivity.
2. Access control
- Internal systems require individual accounts and passwords.
- Access is limited by role: staff see only the modules their job needs.
- Accounts are removed or disabled when someone leaves the team.
- Employee forms are available only through private links.
3. Data protection
- Connections to our website and systems use HTTPS encryption.
- Sensitive identifiers are stored encrypted; the encryption key is kept apart from the data.
- Uploaded documents are stored outside public access and served only to authorized users.
- Regular backups are kept to recover from failures.
4. Application safeguards
Public forms include anti-abuse controls (rate limiting and bot detection), and file uploads are restricted by type and size.
5. People
Staff with access to personal data are expected to keep it confidential and to use it only for their work.
6. Incidents
Suspected security incidents are investigated promptly. Where personal data is affected, we notify the people and clients concerned as the law and our agreements require.
7. Report a concern
If you believe you have found a vulnerability or a problem with your data, write to us at the email below.
Contact
Better Choice Services · Orlando, Florida · info@betterchoiceservices.com