Skip to main content

VENDOR AND THIRD-PARTY SECURITY POLICY

ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland

Version: 1.0
Effective Date: 16 June 2026


1. Purpose

The purpose of this Vendor and Third-Party Security Policy is to establish requirements for the selection, evaluation, onboarding, monitoring and management of third-party vendors, service providers and business partners that may have access to Company systems, information or customer data.

The Company recognizes that third-party relationships may introduce operational, security, privacy and compliance risks and therefore require appropriate oversight.


2. Scope

This policy applies to:

  • Cloud service providers
  • Infrastructure providers
  • Software vendors
  • Contractors
  • Consultants
  • Development partners
  • Hosting providers
  • Data processing partners
  • External support providers

The policy applies whenever a third party may access Company information, systems or services.


3. Vendor Security Principles

The Company seeks to engage vendors that demonstrate appropriate levels of security, reliability and operational maturity.

Third parties should maintain reasonable safeguards designed to protect:

  • Confidentiality
  • Integrity
  • Availability
  • Privacy

The level of review performed may vary according to the nature and risk of the relationship.


4. Vendor Assessment

Before engaging a vendor, the Company may evaluate factors including:

  • Security practices
  • Reputation
  • Service reliability
  • Compliance obligations
  • Data protection measures
  • Technical capabilities
  • Business continuity capabilities

The depth of assessment is determined based on the level of risk presented.


5. Data Processing Requirements

Where vendors process personal data or confidential information on behalf of the Company, appropriate contractual protections shall be implemented whenever required.

The Company seeks to ensure that vendors:

  • Process information only for authorized purposes
  • Restrict access to authorized personnel
  • Maintain adequate security controls
  • Report security incidents promptly
  • Protect customer information

6. Access Management

Third-party access shall be limited to the minimum level necessary to perform approved activities.

Access shall:

  • Be approved before activation
  • Be restricted to authorized individuals
  • Be reviewed periodically
  • Be removed when no longer required

The Principle of Least Privilege shall be applied whenever practical.


7. Security Incident Notification

Vendors are expected to notify the Company without undue delay when security incidents may impact:

  • Company systems
  • Customer information
  • Business operations
  • Service availability

The Company may request additional information necessary to assess and mitigate risks.


8. Monitoring and Review

The Company may periodically review vendor relationships to ensure continued alignment with business, security and compliance requirements.

Reviews may consider:

  • Service performance
  • Security posture
  • Operational reliability
  • Incident history
  • Compliance requirements

Corrective actions may be requested where deficiencies are identified.


9. Termination of Relationships

Upon termination of a vendor relationship, reasonable efforts shall be made to ensure:

  • Access is removed
  • Credentials are revoked
  • Company information is returned or deleted where appropriate
  • Outstanding security obligations are fulfilled

10. Continuous Improvement

The Company continuously seeks to improve vendor risk management practices and may update requirements as business needs evolve.


11. Policy Review

This policy shall be reviewed annually or following significant legal, operational or technological changes.


Approval

Prepared and approved by:

Mateusz Michał Śliwka
President of the Management Board