Skip to main content

INFORMATION SECURITY POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this Information Security Policy is to establish a comprehensive framework for protecting information assets processed by ECOMMIGO GROUP Sp. z o.o.

The Company recognizes that information security is critical to maintaining customer trust, protecting personal and business information, ensuring operational continuity, and meeting legal and contractual obligations.

This policy defines the minimum security requirements applicable to all personnel, systems, services and information processed by the Company.


2. Scope

This policy applies to:

  • Members of the Management Board
  • Employees
  • Contractors
  • Consultants
  • Service providers
  • Third parties authorized to access Company systems

The policy covers all information assets including:

  • Cloud infrastructure
  • Software applications
  • Databases
  • Source code repositories
  • Communication systems
  • Internal documentation
  • Customer information
  • Business information

3. Information Security Objectives

The Company maintains security controls designed to protect:

Confidentiality

Information shall only be accessible to authorized individuals with a legitimate business need.

Integrity

Information shall be protected from unauthorized modification, deletion or corruption.

Availability

Systems and information shall remain available to authorized users whenever required for business operations.


4. Organizational Controls

The Company maintains organizational controls including:

  • Defined security responsibilities
  • Controlled onboarding procedures
  • Controlled offboarding procedures
  • Security-related internal processes
  • Vendor assessment procedures
  • Incident management procedures

Management is responsible for ensuring adequate protection of information assets.


5. Technical Controls

The Company implements technical security measures including:

  • Multi-Factor Authentication (MFA)
  • Strong password policies
  • Access control mechanisms
  • Encrypted communications using TLS
  • Firewall protections
  • Endpoint security solutions
  • Infrastructure monitoring
  • Security event logging
  • Backup and recovery systems
  • Secure cloud hosting environments

Security controls are periodically reviewed and updated where necessary.


6. Access Control

Access to systems and information is granted according to the Principle of Least Privilege.

Users receive only the permissions necessary to perform their responsibilities.

Access rights are:

  • Approved before activation
  • Reviewed periodically
  • Revoked immediately when no longer required

Administrative access is restricted to authorized personnel.


7. Security Awareness

Personnel are expected to:

  • Maintain confidentiality of credentials
  • Protect Company information
  • Follow security procedures
  • Report suspicious activities
  • Comply with Company policies

8. Incident Management

Security incidents are handled according to documented internal procedures.

The Company maintains processes for:

  • Detection
  • Assessment
  • Containment
  • Eradication
  • Recovery
  • Post-incident review

9. Backup and Recovery

Critical information is protected through backup procedures designed to support recovery and business continuity.

Backup processes are reviewed periodically.


10. Policy Review

This policy shall be reviewed annually or whenever significant organizational, legal or technological changes occur.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board