Information Security Policy

Company: [RECKON DIGITAL]  |  Version: 1.0  |  Owner: [Thomas Mouflard  |  Effective: [10/08/2025]  |  Next Review: [10/08/2026]

1. Purpose

This policy establishes administrative, technical, and physical safeguards to protect personal information and other confidential data handled by [Company Name] (“Company”) in connection with marketing and lead-generation services in the United States.

2. Scope

This policy applies to all employees, contractors, and third parties who access Company systems or data, including endpoints, servers, cloud environments, applications, data pipelines, and SaaS tools used to collect, store, or transmit personal information (“PI”).

3. Definitions

4. Roles & Responsibilities

6. Risk Management

7. Data Classification

Classify and label data in systems/repositories:

Default to Confidential if unsure.

8. Access Control & Identity

9. Encryption & Key Management

10. Network & Infrastructure Security

11. Application Security & SDLC

12. Vendor & Partner Management

13. Monitoring, Logging & Alerting

14. Data Minimization, Retention & Disposal

15. Physical & Remote Security

16. Records Management

17. Security Awareness & Training

18. Incident Response & Breach Notification

Breach Notification

If a breach of unencrypted PI is confirmed, notify affected individuals and, when required, regulators/AGs/consumer reporting agencies without unreasonable delay, consistent with applicable state breach-notification laws and any contractual requirements. Notices will describe the incident, types of data, actions taken, steps individuals can take, and our contact information. If a vendor is involved, require immediate notification and coordination.

19. Business Continuity & Disaster Recovery

20. Privacy Controls

21. Audits & Continuous Improvement

22. Policy Exceptions

Exceptions must be risk-assessed, time-bound, documented, and approved by the Security Lead and Executive Sponsor.

23. Enforcement

Violations may result in disciplinary action up to and including termination and could expose individuals and the Company to legal or contractual liability.

Appendices