INFORMATION SECURITY POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this Information Security Policy is to establish a comprehensive framework for protecting information assets processed by ECOMMIGO GROUP Sp. z o.o.
The Company recognizes that information security is critical to maintaining customer trust, protecting personal and business information, ensuring operational continuity, and meeting legal and contractual obligations.
This policy defines the minimum security requirements applicable to all personnel, systems, services and information processed by the Company.
2. Scope
This policy applies to:
- Members of the Management Board
- Employees
- Contractors
- Consultants
- Service providers
- Third parties authorized to access Company systems
The policy covers all information assets including:
- Cloud infrastructure
- Software applications
- Databases
- Source code repositories
- Communication systems
- Internal documentation
- Customer information
- Business information
3. Information Security Objectives
The Company maintains security controls designed to protect:
Confidentiality
Information shall only be accessible to authorized individuals with a legitimate business need.
Integrity
Information shall be protected from unauthorized modification, deletion or corruption.
Availability
Systems and information shall remain available to authorized users whenever required for business operations.
4. Organizational Controls
The Company maintains organizational controls including:
- Defined security responsibilities
- Controlled onboarding procedures
- Controlled offboarding procedures
- Security-related internal processes
- Vendor assessment procedures
- Incident management procedures
Management is responsible for ensuring adequate protection of information assets.
5. Technical Controls
The Company implements technical security measures including:
- Multi-Factor Authentication (MFA)
- Strong password policies
- Access control mechanisms
- Encrypted communications using TLS
- Firewall protections
- Endpoint security solutions
- Infrastructure monitoring
- Security event logging
- Backup and recovery systems
- Secure cloud hosting environments
Security controls are periodically reviewed and updated where necessary.
6. Access Control
Access to systems and information is granted according to the Principle of Least Privilege.
Users receive only the permissions necessary to perform their responsibilities.
Access rights are:
- Approved before activation
- Reviewed periodically
- Revoked immediately when no longer required
Administrative access is restricted to authorized personnel.
7. Security Awareness
Personnel are expected to:
- Maintain confidentiality of credentials
- Protect Company information
- Follow security procedures
- Report suspicious activities
- Comply with Company policies
8. Incident Management
Security incidents are handled according to documented internal procedures.
The Company maintains processes for:
- Detection
- Assessment
- Containment
- Eradication
- Recovery
- Post-incident review
9. Backup and Recovery
Critical information is protected through backup procedures designed to support recovery and business continuity.
Backup processes are reviewed periodically.
10. Policy Review
This policy shall be reviewed annually or whenever significant organizational, legal or technological changes occur.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board