DATA CLASSIFICATION AND ENCRYPTION POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this Data Classification and Encryption Policy is to establish requirements for identifying, classifying, handling and protecting information processed by ECOMMIGO GROUP Sp. z o.o.
The Company recognizes that information assets have different levels of sensitivity and require appropriate protection measures based on risk, legal obligations and business requirements.
This policy defines classification categories and encryption requirements used to protect Company, customer and partner information.
2. Scope
This policy applies to:
- Employees
- Contractors
- Consultants
- Management Board members
- Third-party service providers
The policy covers all information processed through:
- Applications
- Databases
- Cloud infrastructure
- Internal systems
- Communication platforms
- File storage systems
- Portable devices
3. Information Classification Framework
Information shall be classified according to its sensitivity and business impact.
Public Information
Information approved for public disclosure.
Examples:
- Marketing materials
- Public website content
- Press releases
- Public documentation
Unauthorized disclosure presents minimal risk.
Internal Information
Information intended for internal business use.
Examples:
- Internal procedures
- Internal communications
- Operational documentation
- Project information
Access should be limited to authorized personnel.
Confidential Information
Information requiring enhanced protection.
Examples:
- Customer information
- Business contracts
- Financial information
- Commercial data
- Security documentation
- Product roadmaps
Unauthorized disclosure could result in financial, legal or reputational harm.
Restricted Information
Information requiring the highest level of protection.
Examples:
- Authentication credentials
- Encryption keys
- Administrative access information
- Security incident information
- Critical infrastructure configurations
Access must be strictly controlled and monitored.
4. Information Handling Requirements
Personnel shall handle information according to its classification level.
The Company requires:
- Appropriate access controls
- Secure transmission methods
- Secure storage methods
- Protection against unauthorized disclosure
- Secure disposal procedures
Higher classification levels require stronger safeguards.
5. Encryption Requirements
The Company uses encryption to protect information during storage and transmission.
Encryption controls may include:
- TLS encryption
- HTTPS communications
- Encrypted cloud services
- Encrypted storage solutions
- Secure authentication mechanisms
Encryption is applied where appropriate based on risk and operational requirements.
6. Data in Transit
Information transmitted across networks shall be protected using secure communication protocols whenever appropriate.
Examples include:
- HTTPS
- TLS-secured services
- Secure APIs
- Encrypted communication channels
The use of insecure transmission methods should be avoided whenever possible.
7. Data at Rest
Sensitive information stored within Company systems should be protected using appropriate security controls.
Protection mechanisms may include:
- Encryption
- Access restrictions
- Authentication controls
- Backup protections
- Infrastructure security controls
Storage environments are selected with consideration for security and reliability.
8. Access Control Integration
Information classification levels influence access decisions.
Access to confidential and restricted information shall be limited to authorized individuals with a legitimate business need.
The Company applies the Principle of Least Privilege when granting access.
9. Data Retention and Disposal
Information shall be retained only for as long as necessary to satisfy:
- Business requirements
- Contractual obligations
- Legal requirements
- Security requirements
When information is no longer required, it shall be securely deleted, destroyed or anonymized.
10. Responsibilities
Personnel are responsible for:
- Classifying information appropriately
- Protecting sensitive information
- Following security procedures
- Reporting suspected data exposure events
Management is responsible for ensuring adequate controls are maintained.
11. Compliance
Failure to comply with this policy may result in disciplinary action, termination of access privileges or termination of cooperation.
The Company may periodically review compliance with this policy.
12. Policy Review
This policy shall be reviewed annually or following significant legal, organizational or technological changes.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board