Data Security Policy

Data Security Policy

1. Introduction

GalGom Solutions, SL (hereinafter referred to as “GalGom Solutions”) recognizes the importance of protecting the privacy and security of personal data managed through its Campaign AI platform. This data security policy applies to all employees, systems, and vendors involved in processing the personal data of our users.

2. Policy Scope

This policy covers all personal data collected, stored, and processed by Campaign AI, including customer information, billing data, and any other identifiable information handled on the platform.

3. Security Measures

3.1 Physical Security

● Campaign AI servers are hosted in secure data centers that comply with international certification standards (such as ISO 27001) and have restricted physical access.

3.2 Communication Security

● Campaign AI uses SSL/TLS encryption to protect the transmission of personal data between the user and our servers.
● All internal communication between servers is encrypted to prevent unauthorized access.

3.3 Data Storage Security

● Sensitive data, such as payment information, is encrypted at rest using AES-256 encryption. ● Databases are secured through multifactor authentication and access is limited exclusively to authorized personnel.

3.4 Intrusion Prevention and Detection

● Campaign AI employs intrusion detection systems (IDS) to monitor potential unauthorized access attempts (external provider: Cloudflare Inc.).
● Firewalls are implemented to protect servers from unauthorized traffic.

3.5 Access Control

● Access to personal data is restricted to authorized personnel based on their roles and is periodically reviewed.
● Two-factor authentication (2FA) is implemented for administrative access.

4. Incident Management

In the event of a security breach, GalGom Solutions will:
● Notify the relevant authorities within a maximum of 72 hours.
● Inform affected users if the incident could compromise their rights or freedoms.

5. Continuous Evaluation and Improvement

GalGom Solutions conducts regular security audits and reviews this policy at least annually or in response to legislative changes.

Contact: [email protected]