Hoppa í aðalefni

Datatech Security Policy

Purpose and scope

The Datatech security policy is the cornerstone of information security management at the company and provides the framework for all further work in this field.

Responsibility

The managing director is responsible for this policy. Employees, contractors and other third parties who carry out work of any kind for Datatech are responsible for acting in accordance with this security policy.

Datatech employees working on a customer's premises follow the customer's security policy where requested, provided it does not conflict with Datatech's own security policy.

The security committee is responsible for reviewing this policy at least once a year. All Datatech employees sign a confidentiality undertaking and are strictly prohibited from disclosing any information about Datatech's data, business dealings or customers.

Image and reputation

A company's reputation is among its most valuable assets. Datatech has undertaken to safeguard the security of its customers' data.

Security policy

  • To be a leading provider of data security and data backup
  • To make accurate information available in a secure manner
  • To ensure that technological innovation does not compromise security
  • To uphold sound business practices and data protection
  • To operate effective access-control systems
  • To keep employees' access privileges to a minimum

Objectives of the security management system

The system is designed to protect the security of customer information in respect of its confidentiality, integrity and availability. Datatech complies with the laws and regulations governing information security management. Employees and contractors are bound to protect data against destruction, loss and unauthorised access.

Datatech promotes security awareness among its employees. A systematic risk assessment is carried out each year to determine the measures required. This policy shall conform to ÍST ISO/IEC 27001.

This policy was approved on 1 November 2024.