Data Protection and Device Security
Data Protection and Storage
- Employees, contractors, and third parties must not store client data on local devices unless necessary for the completion of a specific task or deliverable.
- Where data exports are required, they will be logged as part of HubSpot's internal security logs.
- All data exports are deleted from local storage once the required task or deliverable is completed. Regular audits are performed to ensure this takes place.
Data Sharing Protocol
- Deeply Digital employees will not ask clients to send or share data via email.
- Employees will encourage clients to either import data to HubSpot directly or share via a suitable shared file system.
- Clients who choose to send data via email do so at their own risk.
Device and Physical Security
- All devices used to access client systems must be kept up-to-date with the latest software releases.
- Laptops must be password protected.
- Personal mobile devices should not be used to access client data.
- Employees, contractors, and third parties must avoid using public Wi-Fi to access client data.
- Physical access to the office is restricted to authorized personnel. Visitor access is only allowed when accompanied by an authorized person.