Security
1. Our approach
We aim to protect business and personal information through appropriate administrative, technical and organisational safeguards proportionate to the nature of the information and services involved.
2. Access and confidentiality
Access to business information should be limited to authorised personnel who need it to perform their assigned responsibilities. Confidential information should be handled according to applicable client instructions, confidentiality obligations and written agreements.
3. Security awareness
Where relevant to an assignment, team members may receive security, privacy, confidentiality, cybersecurity awareness or industry-specific training appropriate to their role. Training does not mean that BehindDesk is a cybersecurity certification body or that every engagement is automatically compliant with a particular regulatory framework.
4. Healthcare information
For healthcare work, additional safeguards and contractual requirements may apply depending on the client, information involved and services performed. Where applicable, the parties should establish appropriate data-processing, confidentiality and business-associate arrangements before protected or regulated information is accessed.
5. Credentials and client systems
Clients should provide individual, role-appropriate access wherever possible and should not share passwords unnecessarily. Access should be removed or adjusted when a role ends or responsibilities change.
6. Secure communication
Do not send passwords, payment credentials, protected health information or other highly sensitive information through ordinary website forms or unsecured email unless an approved secure method has been specifically provided.
7. Incident response
If we become aware of a suspected security or privacy incident involving information handled by BehindDesk, we will take reasonable steps to assess and contain the issue and will communicate with affected clients or individuals as required by applicable law and contract.
8. Client responsibility
No website or technology environment is completely risk-free. Clients are responsible for maintaining appropriate security controls within their own systems, including multi-factor authentication, endpoint security, user access management, backups and secure configuration.
9. Contact
For security concerns, contact hello@behinddeskglobal.com. If you believe you have discovered a security issue affecting the website, please provide enough information for us to investigate without including unnecessary sensitive data.
Back to BehindDesk Global