SECURITY AWARENESS AND ACCEPTABLE USE POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this policy is to establish requirements regarding security awareness, responsible use of Company systems and protection of Company information assets.
The Company recognizes that personnel play a critical role in maintaining information security and protecting customer information.
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Temporary personnel
- Management Board members
The policy applies to all systems, devices, applications and services used to conduct Company business.
3. Acceptable Use Requirements
Company systems shall be used only for legitimate business purposes.
Users shall:
- Follow Company security policies
- Protect customer information
- Use approved software and services
- Maintain confidentiality of credentials
- Report suspicious activities
Users shall not:
- Share passwords
- Circumvent security controls
- Access information without authorization
- Install unauthorized software that may introduce security risks
- Use Company systems for unlawful activities
4. Password Security
Users are responsible for maintaining secure credentials.
Requirements include:
- Strong passwords
- Unique passwords
- Protection against unauthorized disclosure
- Use of Multi-Factor Authentication where available
Passwords must never be shared with unauthorized individuals.
5. Phishing and Social Engineering
Personnel should remain vigilant against phishing attempts, fraudulent communications and social engineering attacks.
Users should:
- Verify suspicious requests
- Avoid opening unexpected attachments
- Report suspicious emails
- Confirm unusual payment or credential requests through approved channels
6. Data Protection Responsibilities
Personnel are expected to:
- Protect personal data
- Protect confidential information
- Follow classification requirements
- Prevent unauthorized disclosure
Information shall only be shared with authorized individuals.
7. Remote Work and Device Security
When working remotely, personnel should:
- Use secure networks where possible
- Protect devices from unauthorized access
- Lock devices when unattended
- Report lost or stolen devices promptly
8. Incident Reporting
All personnel must report:
- Suspicious activities
- Potential security incidents
- Credential compromise
- Unauthorized access attempts
- Malware detections
Reports should be made as soon as reasonably possible.
9. Violations
Failure to comply with this policy may result in:
- Suspension of access privileges
- Disciplinary measures
- Termination of cooperation
- Legal action where appropriate
10. Policy Review
This policy shall be reviewed annually or following significant organizational or technological changes.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board