VENDOR AND THIRD-PARTY SECURITY POLICY
ECOMMIGO GROUP Sp. z o.o.
KRS: 0001218018
NIP: 7011295379
ul. Ludna 2, 00-406 Warsaw, Poland
Version: 1.0
Effective Date: 16 June 2026
1. Purpose
The purpose of this Vendor and Third-Party Security Policy is to establish requirements for the selection, evaluation, onboarding, monitoring and management of third-party vendors, service providers and business partners that may have access to Company systems, information or customer data.
The Company recognizes that third-party relationships may introduce operational, security, privacy and compliance risks and therefore require appropriate oversight.
2. Scope
This policy applies to:
- Cloud service providers
- Infrastructure providers
- Software vendors
- Contractors
- Consultants
- Development partners
- Hosting providers
- Data processing partners
- External support providers
The policy applies whenever a third party may access Company information, systems or services.
3. Vendor Security Principles
The Company seeks to engage vendors that demonstrate appropriate levels of security, reliability and operational maturity.
Third parties should maintain reasonable safeguards designed to protect:
- Confidentiality
- Integrity
- Availability
- Privacy
The level of review performed may vary according to the nature and risk of the relationship.
4. Vendor Assessment
Before engaging a vendor, the Company may evaluate factors including:
- Security practices
- Reputation
- Service reliability
- Compliance obligations
- Data protection measures
- Technical capabilities
- Business continuity capabilities
The depth of assessment is determined based on the level of risk presented.
5. Data Processing Requirements
Where vendors process personal data or confidential information on behalf of the Company, appropriate contractual protections shall be implemented whenever required.
The Company seeks to ensure that vendors:
- Process information only for authorized purposes
- Restrict access to authorized personnel
- Maintain adequate security controls
- Report security incidents promptly
- Protect customer information
6. Access Management
Third-party access shall be limited to the minimum level necessary to perform approved activities.
Access shall:
- Be approved before activation
- Be restricted to authorized individuals
- Be reviewed periodically
- Be removed when no longer required
The Principle of Least Privilege shall be applied whenever practical.
7. Security Incident Notification
Vendors are expected to notify the Company without undue delay when security incidents may impact:
- Company systems
- Customer information
- Business operations
- Service availability
The Company may request additional information necessary to assess and mitigate risks.
8. Monitoring and Review
The Company may periodically review vendor relationships to ensure continued alignment with business, security and compliance requirements.
Reviews may consider:
- Service performance
- Security posture
- Operational reliability
- Incident history
- Compliance requirements
Corrective actions may be requested where deficiencies are identified.
9. Termination of Relationships
Upon termination of a vendor relationship, reasonable efforts shall be made to ensure:
- Access is removed
- Credentials are revoked
- Company information is returned or deleted where appropriate
- Outstanding security obligations are fulfilled
10. Continuous Improvement
The Company continuously seeks to improve vendor risk management practices and may update requirements as business needs evolve.
11. Policy Review
This policy shall be reviewed annually or following significant legal, operational or technological changes.
Approval
Prepared and approved by:
Mateusz Michał Śliwka
President of the Management Board