Service and Confidentiality Commitment
Doz Technology’s commitment regarding confidentiality, purpose limitation, access control, security measures, incident management and protection of customer information in enterprise IT services.
1. Purpose of This Commitment
As Doz Technology, we commit to handling customer information that we may access during enterprise IT projects, managed services, technical support, security, server, network, cloud, backup and similar activities only to the extent required by the service and in accordance with confidentiality principles.
This page is a general corporate commitment. Project-specific confidentiality, SLA, data-processing, liability and security obligations may be expanded by a separately executed agreement or NDA.
2. Confidentiality and Purpose Limitation
- Not to use customer system, network, user, configuration, document or business information outside the purpose of the service.
- Not to disclose confidential information to unauthorized persons and to limit access based on role and need.
- Not to use customer data for advertising or data-sale purposes.
- To act in accordance with applicable law where disclosure is required by law or requested by an authorized authority.
3. Access Control and Credentials
Where remote or on-site technical access is required, named accounts, least privilege, MFA, secure connections and logging are preferred where practicable. Passwords, private keys and similar secrets should not be shared through ordinary email or plaintext messaging channels.
4. Technical and Organizational Security Measures
- To evaluate access control, firewall, endpoint security and logging controls appropriate to the project and risk level.
- To manage patching, updates, configuration and change processes in a controlled manner.
- Where backup is in scope, to define backup and recovery objectives according to project requirements and plan restore tests where practicable.
- Not to present RAID, snapshots, HA or a single security product by itself as backup, disaster recovery or absolute security.
5. Personnel and Supplier Confidentiality
Confidentiality and access-limitation principles apply to personnel and, where used, subcontractors/suppliers who need access to information for service delivery. When selecting third-party providers, security, access and data-protection requirements are evaluated according to the nature of the service.
6. Incident Management
In the event of an information-security incident or suspected unauthorized access, the objective is to determine the scope, contain the impact, preserve relevant records and carry out notification/coordination processes required by contract and applicable law. The scope and timing of incident notifications depend on the nature of the incident and applicable legal and contractual obligations.
7. Data Retention, Return and Deletion
Information and access obtained for the service are retained according to the nature of the service and statutory retention obligations. When the service ends, customer access rights are disabled or handed over and project data is deleted/destroyed in accordance with the relevant agreement, instructions and applicable law.
8. Service Boundaries and Customer Responsibilities
Security and business continuity require shared responsibility. Customers are expected to identify authorized users, provide required licenses, communicate critical changes, support user awareness and fulfil responsibilities assigned to them in the agreement. Doz Technology’s responsibility is limited by the written service scope and applicable law.
Contact
You may contact us with questions or requests concerning this notice.