This Security & Incident Response Policy (the “Policy”) outlines the security measures, incident handling procedures, and operational safeguards implemented by Sellable Marketing Agency (the “Company”, “SMA”, “we”, “us”, or “our”) in relation to the use of our website, client dashboard, staff systems, digital platforms, and associated services.
This Policy applies to all clients, staff members, contractors, authorised users, and any individual accessing our systems or services.
1. Purpose
The purpose of this Policy is to:
- Protect client and company information;
- Maintain the confidentiality, integrity, and availability of systems and data;
- Establish procedures for identifying, managing, and responding to security incidents;
- Reduce operational, legal, and reputational risks; and
- Ensure responsible use of company platforms and digital infrastructure.
2. Scope of the Policy
This Policy applies to client dashboards and portals, staff dashboards and internal systems, websites and web applications, cloud storage platforms, communication systems, integrated third-party tools and software, uploaded files and digital assets, and all users granted authorised access to company systems.
3. Security Measures
We implement commercially reasonable administrative, technical, and organisational safeguards designed to protect information and digital infrastructure from unauthorised access, misuse, disclosure, alteration, or destruction. These safeguards may include:
- Encrypted connections (SSL/TLS);
- Password protection and authentication controls;
- Role-based access permissions;
- Restricted staff access to client information;
- Security monitoring and logging;
- Malware and threat detection measures;
- Routine software and security updates;
- Secure hosting infrastructure;
- Backup procedures; and
- Internal confidentiality obligations for staff and contractors.
Whilst we take reasonable measures to protect systems and data, no digital platform, transmission method, or storage system can be guaranteed to be completely secure or uninterrupted.
4. User Security Responsibilities
Users of our systems and dashboards are responsible for maintaining the confidentiality of login credentials, using strong and secure passwords, restricting unauthorised access to their accounts, ensuring devices used to access our platforms are adequately secured, immediately reporting suspected unauthorised access or suspicious activity, and avoiding the upload or transmission of malicious, unlawful, or harmful content.
Users must not:
- Attempt to gain unauthorised access to platforms or accounts;
- Circumvent security controls;
- Share login credentials with unauthorised persons;
- Introduce malware, harmful code, or malicious files; or
- Interfere with the operation, integrity, or security of company systems.
We reserve the right to suspend or terminate access where security risks or policy breaches are identified.
5. Third-Party Services
Our services may rely on third-party providers, including but not limited to cloud hosting providers, CRM platforms, payment processors, communication systems, analytics services, and automation or artificial intelligence tools.
Whilst we take reasonable care in selecting reputable providers, we are not responsible for outages, breaches, vulnerabilities, delays, or failures originating from third-party systems outside our direct control. Use of third-party services may also be subject to the respective provider’s terms and privacy policies.
6. Security Incidents
A "Security Incident" may include, but is not limited to, unauthorised access to systems or accounts, data breaches or suspected data breaches, malware or ransomware attacks, loss or exposure of confidential information, service disruptions caused by malicious activity, credential compromise, or any event that materially impacts the confidentiality, integrity, or availability of systems or data.
7. Incident Response Procedure
Where a Security Incident is identified or reasonably suspected, we may take appropriate actions including:
- Identification and assessment
- investigating the nature and scope of the incident; determining affected systems, accounts, or data; and assessing operational and security risks.
- Containment
- restricting or suspending access to affected systems, resetting credentials or permissions, isolating compromised infrastructure, and applying temporary security controls.
- Remediation
- removing malicious content or unauthorised access, implementing security patches or fixes, restoring systems from backups where appropriate, and strengthening safeguards to reduce recurrence risk.
- Notification
- Where legally required or operationally appropriate, affected users or clients may be notified of material incidents within a reasonable timeframe. Notification timelines may vary depending on the nature of the incident, verification requirements, legal obligations, and ongoing investigations.
8. Service Interruptions
To protect systems, users, and data, we reserve the right to temporarily suspend systems or dashboard access, disable compromised accounts, perform emergency maintenance, restrict functionality, or remove harmful content or files.
Such actions may occur without prior notice where immediate intervention is reasonably necessary for security or operational protection.
9. Data Backup and Recovery
We may perform periodic backups of certain systems and data for operational continuity purposes. However, backup frequency and retention periods may vary; backups are not guaranteed to be complete, current, or error-free, and clients remain responsible for maintaining independent copies of critical files, records, and data.
We shall not be liable for loss, corruption, or unavailability of data resulting from system failures, user actions, third-party service failures, cybersecurity incidents, or events outside our reasonable control.
10. Limitation of Liability
To the fullest extent permitted by applicable law, we disclaim liability for indirect or consequential losses, loss of profits, revenue, or business opportunities, data loss or corruption, downtime or service interruption, unauthorised access caused by user negligence, or security incidents arising from third-party services, force majeure events, or circumstances beyond our reasonable control.
All services, dashboards, systems, and platforms are provided on an "as available" and "as is" basis without guarantees of uninterrupted or error-free operation.
11. Confidentiality
Any confidential information accessed through our systems shall be treated as confidential and must not be disclosed, copied, distributed, or misused without proper authorisation. Staff members, contractors, and authorised personnel may only access client information where operationally necessary for service delivery, support, administration, or security purposes.
12. Reporting Security Concerns
Users who become aware of suspicious activity, potential vulnerabilities, unauthorised access, or security concerns should promptly report the matter to us via email at:
Email: hello@sellablemarketing.com
13. Policy Updates
We reserve the right to amend, modify, or update this Policy at any time to reflect operational changes, legal requirements, technological developments, or security improvements.
Updated versions will become effective upon publication on our website or systems unless otherwise stated.