IVS - Data Privacy & Information Security
Scope
This SOP applies to all IVS employees, contractors, and third parties with access to IVS or client data. It aligns with core principles of ISO/IEC 27001 and general data-protection best practices.
Objectives
- Protect confidentiality, integrity, and availability of data
- Prevent unauthorized access, disclosure, alteration, or loss
- Ensure responsible handling of client and internal information
Data Classification
All data must be treated according to its sensitivity level:
1. Confidential Data
- Client data (leads, recordings, CRMs, scripts)
- Credentials, API keys, system access
- Contracts, pricing, internal strategies
- Employee personal data
2. Internal Data
- SOPs, internal emails, internal reports
- Operational documentation
3. Public Data
- Approved marketing material
- Public website content
Default classification is Confidential unless explicitly stated otherwise.
Access Control
- Access is granted strictly on a need-to-know basis
- Users must only access systems and data required for their role
- Account sharing is strictly prohibited
- All access must be revoked immediately upon role change or exit
Password & Authentication Policy
- Strong passwords are mandatory (minimum 12 characters)
- Password reuse across systems is prohibited
- Multi-factor authentication (MFA) must be enabled where available
- Credentials must never be shared via email, chat, or verbally
Device & Workspace Security
- Only IVS-approved devices may access IVS systems
- Devices must be protected with:
- Password or biometric lock
- Automatic screen lock when idle
- Workstations must not be left unattended while logged in
- Public or shared computers are prohibited for IVS work
Data Storage & Transfer
- Store data only on IVS-approved platforms and systems
- Local downloads of client data are prohibited unless approved
- Personal cloud storage (Google Drive, iCloud, Dropbox, etc.) is not allowed
- Data transfers must use secure channels (encrypted email, VPN, secure portals)
Email & Communication Security
- Use only official IVS email accounts for work communication
- Do not forward confidential data to external addresses
- Verify recipients before sending sensitive information
- Do not share data through unapproved messaging apps
Use of AI & External Tools
- Uploading IVS or client data to external AI tools is strictly prohibited
- No screenshots, recordings, or exports of systems without approval
- Any tool handling data must be approved by IVS management
Incident & Breach Management
A security incident includes: - Data leaks or exposure - Lost or stolen devices - Unauthorized system access - Phishing or credential compromise
Immediate Actions
- Report the incident immediately to management or HR
- Do not attempt self-remediation
- Preserve evidence and follow instructions
Failure to report incidents is considered a serious violation.
Compliance & Audits
- Employees must comply with all security audits and reviews
- Periodic access and process reviews may be conducted
- Non-compliance may trigger corrective actions
Termination & Offboarding
Upon termination or resignation:
- All system access is revoked immediately
- Devices and credentials must be returned
- No data copies may be retained
- Confidentiality and data-protection obligations remain in force indefinitely
Enforcement & Disciplinary Action
Violations of this SOP may result in: - Disciplinary action - Immediate termination - Legal and financial liability
Acknowledgment
By accessing IVS systems or data, all personnel acknowledge and agree to comply with this Data Privacy & Information Security SOP.