IVS - Data Privacy & Information Security

Scope

This SOP applies to all IVS employees, contractors, and third parties with access to IVS or client data. It aligns with core principles of ISO/IEC 27001 and general data-protection best practices.


Objectives

  • Protect confidentiality, integrity, and availability of data
  • Prevent unauthorized access, disclosure, alteration, or loss
  • Ensure responsible handling of client and internal information

Data Classification

All data must be treated according to its sensitivity level:

1. Confidential Data

  • Client data (leads, recordings, CRMs, scripts)
  • Credentials, API keys, system access
  • Contracts, pricing, internal strategies
  • Employee personal data

2. Internal Data

  • SOPs, internal emails, internal reports
  • Operational documentation

3. Public Data

  • Approved marketing material
  • Public website content

Default classification is Confidential unless explicitly stated otherwise.


Access Control

  • Access is granted strictly on a need-to-know basis
  • Users must only access systems and data required for their role
  • Account sharing is strictly prohibited
  • All access must be revoked immediately upon role change or exit

Password & Authentication Policy

  • Strong passwords are mandatory (minimum 12 characters)
  • Password reuse across systems is prohibited
  • Multi-factor authentication (MFA) must be enabled where available
  • Credentials must never be shared via email, chat, or verbally

Device & Workspace Security

  • Only IVS-approved devices may access IVS systems
  • Devices must be protected with:
    • Password or biometric lock
    • Automatic screen lock when idle
  • Workstations must not be left unattended while logged in
  • Public or shared computers are prohibited for IVS work

Data Storage & Transfer

  • Store data only on IVS-approved platforms and systems
  • Local downloads of client data are prohibited unless approved
  • Personal cloud storage (Google Drive, iCloud, Dropbox, etc.) is not allowed
  • Data transfers must use secure channels (encrypted email, VPN, secure portals)

Email & Communication Security

  • Use only official IVS email accounts for work communication
  • Do not forward confidential data to external addresses
  • Verify recipients before sending sensitive information
  • Do not share data through unapproved messaging apps

Use of AI & External Tools

  • Uploading IVS or client data to external AI tools is strictly prohibited
  • No screenshots, recordings, or exports of systems without approval
  • Any tool handling data must be approved by IVS management

Incident & Breach Management

A security incident includes: - Data leaks or exposure - Lost or stolen devices - Unauthorized system access - Phishing or credential compromise

Immediate Actions

  • Report the incident immediately to management or HR
  • Do not attempt self-remediation
  • Preserve evidence and follow instructions

Failure to report incidents is considered a serious violation.


Compliance & Audits

  • Employees must comply with all security audits and reviews
  • Periodic access and process reviews may be conducted
  • Non-compliance may trigger corrective actions

Termination & Offboarding

Upon termination or resignation:

  • All system access is revoked immediately
  • Devices and credentials must be returned
  • No data copies may be retained
  • Confidentiality and data-protection obligations remain in force indefinitely

Enforcement & Disciplinary Action

Violations of this SOP may result in: - Disciplinary action - Immediate termination - Legal and financial liability


Acknowledgment

By accessing IVS systems or data, all personnel acknowledge and agree to comply with this Data Privacy & Information Security SOP.

Discard
Save
This page has been updated since your last edit. Your draft may contain outdated content. Load Latest Version

On this page

Review Changes ← Back to Content
Message Status Space Raised By Last update on