Gaia Workspace

Security

We take the security and privacy of customer data seriously. Our systems use industry-standard security measures, including encrypted communications, access controls, strong authentication practices, regular software updates, and trusted cloud infrastructure providers. Access to customer data is restricted to authorized personnel, and we strive to follow recognized security and privacy best practices appropriate for the size and nature of our business.

Security

Information Security Policy

Overview

We are committed to protecting the confidentiality, integrity, and availability of our customers' information. While we are a small organization, we implement practical security measures to safeguard data and reduce security risks.

Access Control

Access to company systems and customer data is granted only to authorized personnel.

User accounts are assigned based on business needs.

Access is removed when an employee or contractor no longer requires it.

Strong passwords and multi-factor authentication (MFA) are used where available.

Data Protection

Data is encrypted in transit using HTTPS/TLS.

Sensitive data is stored using industry-standard security measures provided by our technology vendors and cloud service providers.

Access to customer data is limited to personnel who require it to perform their job duties.

Infrastructure Security

Our systems are hosted by reputable cloud service providers that maintain their own physical and network security controls in Canada or Germnay based on client’s operation site.

Firewalls, endpoint protection, and security monitoring tools are used where appropriate.

Software and systems are regularly updated to address known security vulnerabilities.

Security Monitoring and Incident Response

We monitor our systems for unusual activity and security issues.

Security incidents are investigated promptly.

If a security event impacts customer data, affected customers will be notified in accordance with applicable legal and contractual requirements.

Employee Awareness

Employees and contractors are expected to follow security best practices.

Security and privacy responsibilities are communicated during onboarding and reinforced as needed.

Privacy and Data Handling

Customer information is used only for legitimate business purposes.

We collect and retain only the information necessary to provide our services.

Customer data is handled confidentially and protected against unauthorized access.

Upon request and subject to contractual and legal requirements, customer data may be returned or deleted.

Third-Party Providers

We rely on trusted third-party service providers for certain business operations and infrastructure services.

We make reasonable efforts to select providers with appropriate security and privacy practices.

Business Continuity

Critical business data is backed up using the capabilities provided by our service providers.

We maintain processes to support recovery from unexpected outages or disruptions.

Policy Review

This policy is reviewed periodically and updated as our business, technology, and security requirements evolve.