Security Statement
Security Statement
Last updated: December 2024
IngredientsWorldwide.com is committed to protecting the security of your data. This statement outlines the measures we have in place.
Our Security Approach
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction.
Technical Measures
Access Controls
- Role-based access control (RBAC) limits access to authorised personnel
- Multi-factor authentication for administrative access
- Principle of least privilege for system access
Data Protection
- Encryption in transit using TLS 1.2+
- Secure storage with appropriate access controls
- Separation of sensitive data (e.g., original documents stored separately)
Infrastructure Security
- Hosted on enterprise-grade cloud infrastructure
- Regular security updates and patches
- DDoS protection and traffic monitoring
Monitoring
- Audit logging of security-relevant events
- Incident detection and alerting
- Regular review of access logs
Organisational Measures
Policies and Procedures
- Information security policies
- Incident response procedures
- Data handling guidelines
Access Management
- Background checks for personnel with data access
- Access reviews and revocation procedures
- Confidentiality agreements
Incident Response
In the event of a security incident:
- We will investigate and contain the incident
- Affected individuals will be notified as required by UK GDPR
- The ICO will be notified of qualifying breaches within 72 hours
- We will take remedial action to prevent recurrence
Reporting Security Concerns
If you discover a potential security vulnerability, please report it to: sales@ingredientsworldwide.com
We appreciate responsible disclosure and will work with researchers to address issues promptly.
Limitations
While we implement reasonable security measures, no system is completely secure. We cannot guarantee absolute security of data transmitted or stored.
Users are responsible for:
- Maintaining the security of their account credentials
- Using secure networks when accessing the Platform
- Reporting suspicious activity promptly
Third-Party Services
We use third-party service providers who maintain their own security practices. We select providers with appropriate security certifications and conduct due diligence.
Compliance
Our security practices are designed to support compliance with:
- UK GDPR
- Data Protection Act 2018
- Industry best practices
Contact
For security enquiries: sales@ingredientsworldwide.com
Translate