Skip to main content

DATA CLASSIFICATION AND ENCRYPTION POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this Data Classification and Encryption Policy is to establish requirements for identifying, classifying, handling and protecting information processed by ECOMMIGO GROUP Sp. z o.o.

The Company recognizes that information assets have different levels of sensitivity and require appropriate protection measures based on risk, legal obligations and business requirements.

This policy defines classification categories and encryption requirements used to protect Company, customer and partner information.


2. Scope

This policy applies to:

  • Employees
  • Contractors
  • Consultants
  • Management Board members
  • Third-party service providers

The policy covers all information processed through:

  • Applications
  • Databases
  • Cloud infrastructure
  • Internal systems
  • Communication platforms
  • File storage systems
  • Portable devices

3. Information Classification Framework

Information shall be classified according to its sensitivity and business impact.

Public Information

Information approved for public disclosure.

Examples:

  • Marketing materials
  • Public website content
  • Press releases
  • Public documentation

Unauthorized disclosure presents minimal risk.


Internal Information

Information intended for internal business use.

Examples:

  • Internal procedures
  • Internal communications
  • Operational documentation
  • Project information

Access should be limited to authorized personnel.


Confidential Information

Information requiring enhanced protection.

Examples:

  • Customer information
  • Business contracts
  • Financial information
  • Commercial data
  • Security documentation
  • Product roadmaps

Unauthorized disclosure could result in financial, legal or reputational harm.


Restricted Information

Information requiring the highest level of protection.

Examples:

  • Authentication credentials
  • Encryption keys
  • Administrative access information
  • Security incident information
  • Critical infrastructure configurations

Access must be strictly controlled and monitored.


4. Information Handling Requirements

Personnel shall handle information according to its classification level.

The Company requires:

  • Appropriate access controls
  • Secure transmission methods
  • Secure storage methods
  • Protection against unauthorized disclosure
  • Secure disposal procedures

Higher classification levels require stronger safeguards.


5. Encryption Requirements

The Company uses encryption to protect information during storage and transmission.

Encryption controls may include:

  • TLS encryption
  • HTTPS communications
  • Encrypted cloud services
  • Encrypted storage solutions
  • Secure authentication mechanisms

Encryption is applied where appropriate based on risk and operational requirements.


6. Data in Transit

Information transmitted across networks shall be protected using secure communication protocols whenever appropriate.

Examples include:

  • HTTPS
  • TLS-secured services
  • Secure APIs
  • Encrypted communication channels

The use of insecure transmission methods should be avoided whenever possible.


7. Data at Rest

Sensitive information stored within Company systems should be protected using appropriate security controls.

Protection mechanisms may include:

  • Encryption
  • Access restrictions
  • Authentication controls
  • Backup protections
  • Infrastructure security controls

Storage environments are selected with consideration for security and reliability.


8. Access Control Integration

Information classification levels influence access decisions.

Access to confidential and restricted information shall be limited to authorized individuals with a legitimate business need.

The Company applies the Principle of Least Privilege when granting access.


9. Data Retention and Disposal

Information shall be retained only for as long as necessary to satisfy:

  • Business requirements
  • Contractual obligations
  • Legal requirements
  • Security requirements

When information is no longer required, it shall be securely deleted, destroyed or anonymized.


10. Responsibilities

Personnel are responsible for:

  • Classifying information appropriately
  • Protecting sensitive information
  • Following security procedures
  • Reporting suspected data exposure events

Management is responsible for ensuring adequate controls are maintained.


11. Compliance

Failure to comply with this policy may result in disciplinary action, termination of access privileges or termination of cooperation.

The Company may periodically review compliance with this policy.


12. Policy Review

This policy shall be reviewed annually or following significant legal, organizational or technological changes.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board