WEPROCESS LTD
Company number: 12829178
Confidentiality and Information Security Policy
1. Introduction
We are committed to protecting the confidentiality, privacy and security of the information entrusted to us.
In the course of providing our services, we may receive, access, use, store and process confidential, sensitive, personal and commercially sensitive information. We recognise the importance of handling such information responsibly and maintaining appropriate safeguards to protect it from unauthorised access, misuse, loss, disclosure, alteration or destruction.
This policy explains our general approach to confidentiality and information security.
2. Scope
This policy applies to all information handled by us in connection with our services, including information received from clients, customers, service users, professional contacts, business partners and other third parties.
It applies to information in all formats, including:
- electronic records
- digital documents
- emails and communications
- uploaded files
- written records
- operational and administrative data
3. Our Commitment to Confidentiality
We treat confidential and sensitive information with care and discretion.
We are committed to:
- using information only where there is a legitimate business or service-related reason to do so
- limiting access to information to those who need it for authorised purposes
- taking reasonable steps to preserve the confidentiality of information we handle
- preventing unauthorised or inappropriate disclosure of information
- complying with applicable legal and regulatory obligations relating to confidentiality, privacy and data protection
Information provided to us will be treated as confidential where it is confidential by nature, marked as confidential, or where it would reasonably be understood to be confidential.
4. Access to Information
Access to confidential and sensitive information is restricted to authorised persons who require access for legitimate business, operational, administrative, legal, compliance or support purposes.
We take steps designed to ensure that:
- access is granted on a need-to-know basis
- access rights are kept under review
- information is not made available more widely than necessary
- unauthorised access is prevented as far as reasonably possible
5. Information Security Measures
We maintain appropriate technical and organisational measures designed to protect the confidentiality, integrity and availability of the information we hold.
These measures may include, where appropriate:
- secure systems and controlled access arrangements
- authentication and account security measures
- permissions management
- secure methods of storing and transmitting information
- monitoring and review of security practices
- physical, technical and administrative safeguards
- procedures designed to reduce the risk of accidental or unlawful loss, destruction, misuse or disclosure
We regularly review our approach to information security and seek to improve our safeguards where appropriate.
6. Use of Third Parties
Where third-party service providers are used to support our operations or service delivery, we take reasonable steps to ensure that they are appropriate for the services they provide and that confidentiality and information security considerations are taken into account.
Where appropriate, we expect third parties handling information on our behalf to do so in accordance with applicable legal, contractual and confidentiality requirements.
7. Retention of Information
We do not retain information in identifiable form for longer than is necessary for the purposes for which it is processed, unless a longer retention period is required or justified by law, regulation, contractual obligation, legitimate business need, dispute management or the establishment, exercise or defence of legal claims.
When information is no longer required, we may delete, securely dispose of, anonymise or otherwise limit its continued use, as appropriate.
8. Personnel Responsibilities
All persons authorised to handle information on our behalf are expected to do so responsibly and in accordance with applicable confidentiality, privacy and security requirements.
This includes expectations that information will:
- be accessed only where necessary
- be handled securely
- not be disclosed improperly
- be protected against accidental loss or misuse
- be escalated appropriately where any concern arises
9. Data Incidents and Breach Response
We take suspected information security incidents and personal data breaches seriously.
Where we become aware of an actual or suspected incident affecting confidential or sensitive information, we will take steps considered appropriate in the circumstances to:
- assess the nature and extent of the issue
- contain and investigate the incident
- take corrective action where needed
- maintain appropriate records
- consider whether any notification obligations arise under applicable law or regulation
10. Compliance and Review
We keep our confidentiality and information security practices under review and may update this policy from time to time to reflect legal, regulatory, operational or technological developments.
11. Contact
If you have any questions about this policy or about how information is handled, please contact us at: