The company handles client information and professional documents on a need-to-know basis and in accordance with the engagement scope and applicable regulatory and professional obligations.
1. Information Covered
This includes financial, accounting, and tax information, contracts and records, employee, customer, and supplier data, correspondence, analytical results, and any information designated by the client or whose nature requires confidentiality.
2. Restrict Access
Access is limited to team members and service providers who need the information to perform authorized tasks, with permissions defined according to role and responsibility.
3. Receipt & Transfer of Documents
Appropriate methods for exchanging documents are agreed based on their sensitivity. Highly sensitive data should not be sent through the general contact form or applications not approved for the project.
4. Retention & Backup
Files are retained in environments appropriate to their nature with access controls, and backups are used where operationally necessary. Retention periods vary according to the contract and applicable regulatory and professional requirements.
5. Supporting Parties
When a technical or professional service provider is engaged, disclosure is limited to what is necessary, with appropriate confidentiality and protection obligations considered according to the relationship and nature of the data.
6. Mandatory Disclosure
Disclosure may be made where required by law or an order from a competent authority, or to protect the company's rights and defend claims, limited to the required extent whenever possible.
7. Incident Handling
If unauthorized access or data loss is suspected, the incident is assessed and appropriate containment, remediation, and notification steps are taken in accordance with applicable regulatory and contractual requirements.
8. Client Responsibilities
- Identify the individuals authorized to communicate and exchange files.
- Provide the company with accurate, current data limited to what is necessary for the service.
- Remove or redact unnecessary data before sending whenever possible.
- Report any incorrect transmission or suspected security issue immediately.
9. Reporting a Security Matter
To report an information-confidentiality matter, use the email info@almasartp.com with a brief description without including additional sensitive data.
