1. Introduction and Glossary Data security and technological infrastructure are a priority for E-goi. This Security Policy describes the principles and practices that E-goi adopts to protect the information of Visitors, Clients and Contacts, ensuring compliance with applicable regulations and industry best practices. The main terms used in this document are defined and explained in detail in the Glossary (attached to this agreement). It is recommended to consult it for a better understanding of the concepts and definitions applied here. 2. Scope and Application This policy applies to: Technological infrastructure used to operate the E-goi Service. Personal and business data stored, processed or transmitted by the Service. Employees, partners and suppliers. 3. Security Principles E-goi adopts the following security principles: Confidentiality: Ensure that data is accessible only by authorised individuals. Integrity: Protect data against unauthorised alterations. Availability: Ensure that the Service is continuously available to the Client. 4. Personal Data Protection E-goi processes personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable legislation, under our Personal Data Processing Agreement (attached to this Agreement). 5. Infrastructure and Application Security E-goi adopts a proactive approach to protect the infrastructure and application of the E-goi Service and Site: 5.1. Infrastructure Secure data centres: E-goi's servers are located in a data centre in Portugal (European Union), managed by IPT (Infraestructuras de Portugal), with recognised security certifications like ISO/IEC 27001 and ISO9001. Redundancy and backups: E-goi implements regular redundancy and backups (on-site and off-site) to ensure Service continuity and disaster recovery. 5.2. Application Secure development: E-goi uses secure development practices (OWASP, SSDLC) to minimise vulnerabilities. Regular testing: E-goi conducts penetration tests and security audits periodically. Bug Bounty Program: E-goi maintains a public Bug Bounty program that encourages responsible disclosure of vulnerabilities and potential security concerns, promoting collaboration with the community to continuously enhance the security of E-goi systems. Encryption: Data in transit: E-goi provides SSL/TLS encryption (TLS 1.2 or higher) to protect all traffic between Clients and their servers, ensuring confidentiality and integrity in communications. Data at rest: Sensitive data is protected by hashing algorithms like SHA-512 with salt. For full encryption, E-goi offers the service of file system encryption on dedicated servers with LUKS encryption, using advanced standards like AES-256 to ensure maximum security. 6. Access and Identities Strong authentication: All access to the E-goi Service can have multi-factor authentication (MFA). Permission segregation: The permission functionalities in the E-goi Service give the Client the possibility to implement the principle of least privilege for the individuals granted access, ensuring that each access is made only to the necessary areas of the Service. Access deactivation: The Service is no longer available to inactive Clients or those who do not comply with the Terms of Use (attached to this Agreement). 7. Resilience and Disaster Recovery Contingency plans: E-goi maintains and regularly tests disaster recovery (DRP) and business continuity (BCP) plans. RPO/RTO: E-goi ensures recovery times (RTO) and maximum data loss (RPO) in line with the SLA contracted with the Client. 8. Monitoring and Incident Response Continuous monitoring: E-goi uses intrusion detection and prevention systems (IDS/IPS) and real-time monitoring tools. Incident management: E-goi has a dedicated team to quickly respond to security incidents, notifying the Client as needed and in accordance with the legislation. Vulnerability and leak reports: In accordance with E-goi's obligations under GDPR, CNPD, and other regulatory entities, E-goi provides detailed reports on incident responses and security vulnerabilities. If applicable, or if there is a prior agreement with the Client, these reports are also provided to the Client. 9. Responsibilities in Incident Response A "security incident" is considered any unexpected event or set of events that compromise or have the potential to compromise the confidentiality, integrity, availability, or authenticity of the data or the Service provided by E-goi. This includes, but is not limited to: Unauthorized access: Successful attempts to access data or systems without proper authorization. Data disclosure: Accidental or unauthorized exposure of confidential or personal information. Cyber attacks: Actions such as phishing, malware, ransomware, DDoS, or exploitation of vulnerabilities in systems. Data loss or corruption: Resulting from technical failures, human errors, or malicious acts. Service interruptions: Any events that prevent the normal operation of the Service provided or used. Security policy violations: Non-compliance with established practices or rules to protect data and the Service. The identification and management of security incidents will be handled according to the procedures described in this clause, ensuring a coordinated and effective response between the parties. Client's Responsibility: The Client commits to: Implement and maintain appropriate technical and organisational measures to protect the data processed through the use of the E-goi Service. Immediately notify E-goi of any security incidents that may affect the confidentiality, integrity, or availability of the data in the Service. Provide relevant information and actively collaborate in the investigation and mitigation of the impacts of the incident. E-goi's Responsibility: E-goi commits to: Notify the Client of any identified security incidents that may affect their data or the Service. Provide detailed information about the situation and collaborate to contain and resolve the incident. Appoint a dedicated support team to handle critical incidents and provide necessary support to the Client. Incident Response: Both parties should act in a coordinated manner to investigate, contain, mitigate, and correct the impacts of security incidents, ensuring data protection and Service continuity. Communication: The parties commit to maintaining clear, agile, and efficient communication throughout the incident response process, using email, SMS, or other previously agreed channels. Collaboration and Risk Mitigation: Both parties agree to proactively collaborate to: Minimise risks resulting from security incidents. Implement continuous improvements in processes and security measures to prevent future occurrences. 10. Education and Awareness All E-goi employees receive ongoing training on: Good information security practices. Compliance with GDPR and other applicable regulations. Internal policies for the use of systems and data. 11. Anti-Spam and Secure Communication Policy E-goi strictly applies its Acceptable Use Policy (attached to this Agreement), ensuring that: The sending of messages through the Service complies with applicable laws. All Contacts used by the Client have given their explicit consent for communication. Unsubscribes by Contacts are processed immediately and automatically. An active response to spam or abuse complaints from third parties (ESP, Contacts) 12. Reviews and Updates E-goi may change this Policy at any time by publishing the latest version on the E-goi Site. E-goi will notify the Client via RSS about any changes to this Policy as soon as possible. The Client will have the opportunity, in case of objection, to terminate the Agreement within thirty (30) days after that notification. Unless the Client closes the Service, the new Policy will take effect immediately after the publication date indicated in the new Policy, as applicable, and will apply with the continuation or new use of the Service. E-goi's Security Policy is regularly reviewed to reflect: Changes in applicable legislation. New technical or operational requirements. Evolution of threats and vulnerabilities. 13. Contact For questions or queries about this Policy, the Client can contact E-goi via: https://www.e-goi.com/contacts Widget help in the Client's E-goi account DPO (Data Privacy): dpo@e-goi.com CISO (Information Security): ciso@e-goi.com Anything else about this Security Policy: privacy@e-goi.com