ACCESS CONTROL POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this Access Control Policy is to establish requirements for granting, managing, reviewing and revoking access to Company information systems, applications, infrastructure and data.
The objective of this policy is to ensure that access to information assets is restricted to authorized individuals and is provided only when required for legitimate business purposes.
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Management Board members
- Temporary personnel
- Third-party service providers
The policy covers:
- Cloud infrastructure
- Internal applications
- Production systems
- Development environments
- Databases
- Communication platforms
- File storage systems
- Customer information
3. Access Control Principles
The Company applies the following principles:
Principle of Least Privilege
Users receive only the minimum permissions required to perform their duties.
Need-to-Know Principle
Access to information is granted only when necessary for legitimate business purposes.
Individual Accountability
Access credentials must be assigned to individual users and must not be shared.
Segregation of Duties
Where practical, responsibilities are separated to reduce security and operational risks.
4. User Account Management
All user accounts must:
- Be uniquely assigned to an individual
- Be protected by strong authentication
- Be created through an approved process
- Be disabled when no longer required
Shared accounts should be avoided whenever possible.
5. Authentication Requirements
The Company requires appropriate authentication controls including:
- Strong passwords
- Multi-Factor Authentication where available
- Unique credentials
- Protection against unauthorized access
Users are responsible for maintaining the confidentiality of authentication credentials.
Passwords must never be shared with unauthorized individuals.
6. Access Provisioning
Access requests must:
- Be based on business necessity
- Be approved before activation
- Be documented where appropriate
Access rights are granted according to the user’s role and responsibilities.
7. Privileged Access
Administrative and privileged accounts present increased security risks and are subject to additional controls.
Administrative access shall be:
- Restricted to authorized personnel
- Granted only when necessary
- Reviewed periodically
- Removed when no longer required
Privileged accounts shall not be used for routine business activities unless necessary.
8. Access Reviews
The Company performs periodic reviews of user access rights to ensure that permissions remain appropriate.
Reviews may include:
- User permissions
- Administrative privileges
- Third-party access
- Dormant accounts
Access that is no longer required shall be removed.
9. Termination and Offboarding
When employment or cooperation ends:
- Access rights shall be revoked
- User accounts shall be disabled
- Credentials shall be invalidated
- Company assets shall be returned where applicable
Access removal should occur as soon as reasonably possible.
10. Monitoring and Logging
Access-related activities may be logged and monitored for security purposes.
Examples include:
- Login attempts
- Administrative actions
- Permission changes
- Authentication events
Monitoring activities support incident investigations and security reviews.
11. Violations
Violations of this policy may result in:
- Suspension of access privileges
- Disciplinary actions
- Termination of cooperation
- Legal action where appropriate
12. Policy Review
This policy shall be reviewed annually or whenever significant organizational or technological changes occur.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board