Skip to main content

ACCESS CONTROL POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this Access Control Policy is to establish requirements for granting, managing, reviewing and revoking access to Company information systems, applications, infrastructure and data.

The objective of this policy is to ensure that access to information assets is restricted to authorized individuals and is provided only when required for legitimate business purposes.


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Management Board members
  • Temporary personnel
  • Third-party service providers

The policy covers:

  • Cloud infrastructure
  • Internal applications
  • Production systems
  • Development environments
  • Databases
  • Communication platforms
  • File storage systems
  • Customer information

3. Access Control Principles

The Company applies the following principles:

Principle of Least Privilege

Users receive only the minimum permissions required to perform their duties.

Need-to-Know Principle

Access to information is granted only when necessary for legitimate business purposes.

Individual Accountability

Access credentials must be assigned to individual users and must not be shared.

Segregation of Duties

Where practical, responsibilities are separated to reduce security and operational risks.


4. User Account Management

All user accounts must:

  • Be uniquely assigned to an individual
  • Be protected by strong authentication
  • Be created through an approved process
  • Be disabled when no longer required

Shared accounts should be avoided whenever possible.


5. Authentication Requirements

The Company requires appropriate authentication controls including:

  • Strong passwords
  • Multi-Factor Authentication where available
  • Unique credentials
  • Protection against unauthorized access

Users are responsible for maintaining the confidentiality of authentication credentials.

Passwords must never be shared with unauthorized individuals.


6. Access Provisioning

Access requests must:

  • Be based on business necessity
  • Be approved before activation
  • Be documented where appropriate

Access rights are granted according to the user’s role and responsibilities.


7. Privileged Access

Administrative and privileged accounts present increased security risks and are subject to additional controls.

Administrative access shall be:

  • Restricted to authorized personnel
  • Granted only when necessary
  • Reviewed periodically
  • Removed when no longer required

Privileged accounts shall not be used for routine business activities unless necessary.


8. Access Reviews

The Company performs periodic reviews of user access rights to ensure that permissions remain appropriate.

Reviews may include:

  • User permissions
  • Administrative privileges
  • Third-party access
  • Dormant accounts

Access that is no longer required shall be removed.


9. Termination and Offboarding

When employment or cooperation ends:

  • Access rights shall be revoked
  • User accounts shall be disabled
  • Credentials shall be invalidated
  • Company assets shall be returned where applicable

Access removal should occur as soon as reasonably possible.


10. Monitoring and Logging

Access-related activities may be logged and monitored for security purposes.

Examples include:

  • Login attempts
  • Administrative actions
  • Permission changes
  • Authentication events

Monitoring activities support incident investigations and security reviews.


11. Violations

Violations of this policy may result in:

  • Suspension of access privileges
  • Disciplinary actions
  • Termination of cooperation
  • Legal action where appropriate

12. Policy Review

This policy shall be reviewed annually or whenever significant organizational or technological changes occur.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board