Data & Security Policy
Purpose
This policy outlines how Global Design Corp (“GDC”) manages data protection, information security, and confidentiality when handling client and website-related information.
It is designed for enterprise and regulated environments where data security is a critical requirement.
Scope
This policy applies to:
Website users
Prospective clients
Client engagement data
Internal systems and tools used by GDC
Data Handling Principles
GDC follows the following principles:
Data minimisation: We only collect data necessary for defined purposes
Purpose limitation: Data is used only for legitimate business purposes
Confidentiality: Client and engagement information is treated as confidential
Integrity: Data is maintained accurately and securely
Information Security Measures
We implement appropriate safeguards including:
Access-controlled systems
Role-based access to client data
Secure storage and communication tools
Encryption in transit where applicable
Secure authentication practices
Confidentiality
All client-related information shared with GDC during engagements is treated as confidential unless otherwise agreed in writing.
We do not disclose client work, documentation, or materials without explicit permission.
Third-Party Tools
We may use secure third-party tools for:
Communication
Project management
File storage
Analytics
All vendors are selected based on reasonable security and compliance standards.
Data Breach Response
In the event of a data security incident:
We will take immediate steps to contain the issue
Investigate root cause and impact
Notify affected parties where legally required
Implement corrective measures
Client Responsibilities
Clients are responsible for:
Providing accurate and lawful data
Ensuring they have rights to share any data provided
Maintaining their own internal security practices
Contact
This policy may be updated periodically to reflect operational, legal, or regulatory changes.
For privacy-related enquiries:
info@globaldesign-corp.com