Safeguarding Customer Data
At Gemtech Membership Systems Ltd, we take the privacy and security of our clients’ customer data seriously. We are committed to implementing robust measures to safeguard the information entrusted to us. This section outlines our approach to ensuring the confidentiality, integrity, and availability of customer data:
1. Data Encryption:
All customer data transmitted between our clients and our systems is encrypted using industry-standard protocols. This ensures that any sensitive information, such as personal details or payment data, remains secure during transmission.
2. Access Controls:
We employ strict access controls to limit and monitor who within our organization has access to customer data. Access is granted on a need-to-know basis, and all employees undergo training on data protection and privacy policies.
3. Data Storage:
Clients Customer data is stored by Gemtech Membership Systems Ltd at server level. Our servers are hosted by Digital Ocean servers in conjunction with Cloudways, in the Digital Ocean London Datacenter. You can find out more about Digital Ocean and their security and Cloudways data privacy by visiting their websites.
4. Security Vulnerability Scans:
Our systems are all installed with security vulnerability scanners and we are alerted immediately when there are security vulnerabilities detected and updates at security fixes are available. These scans help identify and address potential vulnerabilities, ensuring the ongoing protection of customer data.
5. Firewall and Antivirus Protection:
All our Client’s websites are installed with Bot Protection, Malware scanners and Firewall protection to safeguard against hackers and malicious threats. These are updated regularly and we are alerted to any potential threats immediately.
6. Data Retention and Deletion:
We only retain customer data for as long as necessary to fulfill the purposes outlined in our agreements with clients or as required by law. When data is no longer needed, it is securely deleted to prevent any unauthorized access.
7. Incident Response:
In the unlikely event of a data breach, we contact affected parties promptly and take immediate action to mitigate any potential impact.
8. Compliance with Regulations:
We adhere to applicable data protection laws and regulations, including but not limited to Data Protection & GDPR. Our privacy practices are designed to meet or exceed the requirements set forth in these regulations.
9. Client Responsibilities:
We collaborate with our clients to ensure they are aware of their responsibilities regarding customer data. This may include configuring account settings and permissions to align with their specific privacy and security requirements.
By adopting these measures, we aim to provide our clients with the confidence that their customers’ data is treated with the utmost care and diligence.
10. Backups
Cloudways provide a daily backup of our servers and also of all our client’s applications running on them. However, we also ensure that we take our own backups, including offsite backups and backups before and after each update.