Security Policy
Last Updated: 18 July 2024
Promorewardquester is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and how we respond to security incidents.
1. Scope
This policy applies to all systems, services, infrastructure, and data operated by Promorewardquester, including our website, learning platform, user accounts, and any associated services. It applies to all users, staff, contractors, and third parties who interact with our systems.
2. Data Protection and Storage
We apply appropriate technical and organisational measures to protect personal and account data against unauthorised access, disclosure, alteration, or destruction.
- User data is stored on secured servers with access controls and monitoring in place.
- Sensitive data, including authentication credentials, is stored using industry-standard hashing and encryption methods.
- Data in transit between your browser and our servers is protected using Transport Layer Security (TLS).
- We do not store payment card data directly on our systems. Payment processing is handled by certified third-party providers.
3. Access Control
3.1 User Access
Access to user accounts is controlled through authentication mechanisms. Each user is responsible for maintaining the confidentiality of their login credentials. We recommend the following practices:
- Use a strong, unique password for your account.
- Do not share your credentials with any other person.
- Log out of your account when using shared or public devices.
- Enable any available multi-factor authentication options.
3.2 Internal Access
Access to production systems and user data by our team is restricted to authorised personnel only, on a need-to-know basis. All internal access is subject to authentication requirements and activity logging.
4. Network and Infrastructure Security
Our infrastructure is maintained with security as a primary consideration. Measures in place include:
- Firewalls and network segmentation to limit exposure of internal systems.
- Regular security patching and updates applied to servers, software, and dependencies.
- Intrusion detection and monitoring systems to identify anomalous activity.
- Regular vulnerability assessments and security reviews.
5. Application Security
Our platform is developed with security integrated into the development lifecycle. This includes:
- Code review processes that include security considerations.
- Protection against common web vulnerabilities, including those described in the OWASP Top Ten, such as SQL injection, cross-site scripting, and cross-site request forgery.
- Input validation and output encoding applied throughout the application.
- Session management controls, including automatic session expiry after inactivity.
6. Third-Party Services
We work with third-party service providers to deliver parts of our platform. We evaluate the security practices of these providers and require that they maintain appropriate safeguards. We are not responsible for the independent security practices of third-party websites or services linked from our platform.
7. Security Incident Response
We maintain an internal process for identifying, containing, and responding to security incidents. In the event of a confirmed breach that affects user data:
- We will investigate and contain the incident promptly.
- Affected users will be notified in accordance with applicable obligations.
- We will take corrective action to prevent recurrence.
- A post-incident review will be conducted to assess and improve our controls.
8. Responsible Disclosure
If you believe you have discovered a security vulnerability in our platform, we encourage you to report it to us responsibly. Please contact us at support@promorewardquester.site with a description of the issue, steps to reproduce it, and any relevant technical details. We ask that you:
- Do not exploit the vulnerability or access data beyond what is necessary to demonstrate the issue.
- Do not disclose the vulnerability publicly until we have had a reasonable opportunity to investigate and remediate it.
We will acknowledge your report, investigate the matter, and keep you informed of our progress where appropriate.
9. User Responsibilities
Security is a shared responsibility. As a user of our platform, you agree to:
- Keep your login credentials confidential and not share them with others.
- Notify us promptly if you suspect unauthorised access to your account.
- Use the platform in accordance with our Terms of Service and not attempt to probe, scan, or test the security of our systems without explicit written permission.
- Ensure that any devices used to access our platform are reasonably secured.
10. Data Retention and Deletion
We retain user data only for as long as necessary to provide our services and fulfil our obligations. When data is no longer required, it is deleted or anonymised using secure methods. Users may request deletion of their account and associated data by contacting us at the details provided below.
11. Backups and Business Continuity
We maintain regular backups of platform data to support recovery in the event of system failure or data loss. Backup data is subject to the same access controls and security standards as live data.
12. Physical Security
Our platform operates on infrastructure hosted in data centres that maintain physical security controls, including restricted access, environmental monitoring, and redundancy measures. Our administrative offices are secured against unauthorised physical access.
13. Updates to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the date at the top of this page. We encourage you to review this policy periodically. Continued use of our platform following any update constitutes your acceptance of the revised policy.
14. Contact
If you have questions, concerns, or requests related to this Security Policy, please contact us:
| Method | Details |
|---|---|
| support@promorewardquester.site | |
| Phone | +61 2 9399 7092 |
| Post | 1/6 Allen Pl, Wetherill Park NSW 2164, Australia |
| Website | promorewardquester.site |