Skip to main content
Vendo

Information Security & Data Protection Policy

Last Updated: July 22, 2026

1. Introduction

Vendo Data is committed to ensuring the security, confidentiality, integrity, and availability of all information and data assets within our control. This Information Security and Data Protection Policy establishes the framework for protecting Vendo Data's information and data assets, including those belonging to our customers, partners, and employees.

2. Purpose

The purpose of this policy is to:

  • Define the principles and requirements for information security and data protection at Vendo
  • Establish a framework for protecting our information and data assets from unauthorized access, disclosure, modification, or destruction
  • Ensure compliance with applicable legal, regulatory, and contractual requirements
  • Define roles and responsibilities for information security and data protection within the organization

3. Scope

This policy applies to:

  • All employees, contractors, consultants, temporary workers, and other personnel affiliated with Vendo
  • All information and data assets, regardless of format or medium, that are created, collected, processed, stored, transmitted, or otherwise managed by Vendo
  • All information systems, applications, networks, and infrastructure owned, operated, or managed by Vendo, including those hosted in third-party environments
  • All business processes and activities conducted by or on behalf of Vendo

4. Policy Statement

Vendo is committed to implementing and maintaining an effective information security and data protection program that:

  • Protects the confidentiality, integrity, and availability of our information and data assets
  • Complies with all applicable legal, regulatory, and contractual requirements
  • Aligns with industry best practices and standards
  • Supports our business objectives and enhances customer trust
  • Continuously improves through regular assessment and adaptation

5. Principles

Vendo's information security and data protection program is guided by the following principles:

  • Risk-based approach: Security controls and resources are allocated based on risk assessment and risk management
  • Defense in depth: Multiple layers of security controls are implemented to protect our information and data assets
  • Least privilege: Access to information and systems is limited to what is necessary for individuals to perform their job functions
  • Separation of duties: Critical functions are divided among different individuals to prevent conflicts of interest and reduce the risk of fraud or abuse
  • Security by design: Security and privacy requirements are integrated into the design and development of our systems and processes
  • Privacy by design: Privacy principles are embedded into the design and operation of our systems, processes, and business practices

6. Roles and Responsibilities

6.1 Executive Management

  • Provide oversight and governance for the information security and data protection program
  • Approve information security and data protection policies
  • Ensure adequate resources are allocated to the information security and data protection program

6.2 All Personnel

  • Understand and comply with this policy and related standards, procedures, and guidelines
  • Report security incidents, vulnerabilities, or concerns promptly
  • Protect information and data assets within their control
  • Complete required security and privacy training

7. Key Security Controls

7.1 Access Control

Vendo implements access control measures to ensure that:

  • Access to information and systems is granted based on the principle of least privilege
  • Access rights are regularly reviewed and updated
  • Strong authentication mechanisms are used to verify user identities
  • Access privileges are promptly removed or modified when personnel roles change or upon termination

7.2 Network Security

Vendo uses encryption to protect data in transit across public networks.

7.3 System Security

Vendo implements system security measures to protect our systems and applications, including:

  • Anti-malware solutions

7.4 Data Protection

Vendo implements data protection measures to safeguard our data assets, including:

  • Encryption for sensitive data at rest and in transit

7.5 Physical Security

Vendo uses cloud infrastructure providers that maintain physical and environmental safeguards for the facilities where Vendo services are hosted. Vendo also applies appropriate safeguards to workplaces, equipment, and physical information assets under its control.

  • Controlled physical access to hosting facilities
  • Monitoring and environmental protections at data centers
  • Appropriate handling and disposal of equipment and media

7.6 Incident Management

Vendo implements incident management procedures to:

  • Detect and respond to security incidents promptly
  • Investigate and remediate security incidents effectively
  • Communicate with affected parties as required
  • Learn from incidents to improve our security posture

7.7 Business Continuity and Disaster Recovery

Vendo implements business continuity and disaster recovery measures to:

  • Ensure the continuity of critical business operations during disruptions
  • Recover systems and data in a timely manner following a disaster or major incident
  • Minimize the impact of disruptions on our customers and business operations
  • Periodically test continuity and recovery measures and use the results to improve readiness

8. Compliance

8.1 Legal and Regulatory Compliance

Vendo maintains its information security and data protection program to support compliance with the laws, regulations, contractual requirements, and industry obligations that apply to Vendo's services and role.

8.2 Contractual Compliance

Vendo complies with all contractual obligations related to information security and data protection in our agreements with customers, partners, vendors, and other third parties.

8.3 Policy Compliance

All personnel are required to comply with this policy and related standards, procedures, and guidelines. Non-compliance may result in disciplinary action, up to and including termination of employment or contract.

9. Training and Awareness

Vendo provides security and privacy awareness training so personnel understand their responsibilities, common threats, and how to report concerns or suspected incidents.