Skip to main content

SECURITY AWARENESS AND ACCEPTABLE USE POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this policy is to establish requirements regarding security awareness, responsible use of Company systems and protection of Company information assets.

The Company recognizes that personnel play a critical role in maintaining information security and protecting customer information.


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Temporary personnel
  • Management Board members

The policy applies to all systems, devices, applications and services used to conduct Company business.


3. Acceptable Use Requirements

Company systems shall be used only for legitimate business purposes.

Users shall:

  • Follow Company security policies
  • Protect customer information
  • Use approved software and services
  • Maintain confidentiality of credentials
  • Report suspicious activities

Users shall not:

  • Share passwords
  • Circumvent security controls
  • Access information without authorization
  • Install unauthorized software that may introduce security risks
  • Use Company systems for unlawful activities

4. Password Security

Users are responsible for maintaining secure credentials.

Requirements include:

  • Strong passwords
  • Unique passwords
  • Protection against unauthorized disclosure
  • Use of Multi-Factor Authentication where available

Passwords must never be shared with unauthorized individuals.


5. Phishing and Social Engineering

Personnel should remain vigilant against phishing attempts, fraudulent communications and social engineering attacks.

Users should:

  • Verify suspicious requests
  • Avoid opening unexpected attachments
  • Report suspicious emails
  • Confirm unusual payment or credential requests through approved channels

6. Data Protection Responsibilities

Personnel are expected to:

  • Protect personal data
  • Protect confidential information
  • Follow classification requirements
  • Prevent unauthorized disclosure

Information shall only be shared with authorized individuals.


7. Remote Work and Device Security

When working remotely, personnel should:

  • Use secure networks where possible
  • Protect devices from unauthorized access
  • Lock devices when unattended
  • Report lost or stolen devices promptly

8. Incident Reporting

All personnel must report:

  • Suspicious activities
  • Potential security incidents
  • Credential compromise
  • Unauthorized access attempts
  • Malware detections

Reports should be made as soon as reasonably possible.


9. Violations

Failure to comply with this policy may result in:

  • Suspension of access privileges
  • Disciplinary measures
  • Termination of cooperation
  • Legal action where appropriate

10. Policy Review

This policy shall be reviewed annually or following significant organizational or technological changes.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board