Hoppa í aðalefni

Datatech Security Policy

Purpose and scope

The Datatech security policy is the cornerstone of information security management at the company and provides the framework for all further work in this field. It covers all of Datatech's activities, both data recovery in the company's laboratory and hosted services such as Skýjadrif, and applies to every employee, contractor and sub-processor.

Responsibility

The managing director is responsible for this policy. Employees, contractors and other third parties who carry out work of any kind for Datatech are responsible for acting in accordance with this security policy.

Datatech employees working on a customer's premises follow the customer's security policy where requested, provided it does not conflict with Datatech's own security policy.

The security committee is responsible for reviewing this policy at least once a year. All Datatech employees sign a confidentiality undertaking and are strictly prohibited from disclosing any information about Datatech's data, business dealings or customers.

Image and reputation

A company's reputation is among its most valuable assets. Datatech has undertaken to safeguard the security of its customers' data.

Hosted service: Skýjadrif

Skýjadrif is Datatech's cloud storage at afrit.datatech.is. Customer data is hosted in Amsterdam, within the European Economic Area.

All traffic to the service runs over an encrypted connection, and the storage refuses both non-TLS connections and writes that are not encrypted. An unencrypted file therefore cannot reach the storage, not even through a code path somebody forgot. Two-factor authentication is mandatory on every account: it is a condition in every single database access rule, not a setting that can be switched off.

Files are versioned and locked for 14 days from the moment they are uploaded. The production system's access key is not permitted to break that lock, so neither our own mistake nor a key in the wrong hands can delete data inside that window.

Staff have no access to the contents of customer storage in normal operation. Where access is opened it is written to an event log the customer reads themselves. Entries in that log cannot be altered or deleted afterwards, not even with the system key. The only thing that may be cleared from them is the identity of a user who has already been deleted, so that a request for erasure of personal data can be met.

Security breaches

If a security breach affects a customer's data we notify them without undue delay and no later than 72 hours after we become aware of it. The notification states what we know at that point about its scope and what we have done.

Where the customer is a controller of personal data, the notification is what lets them meet their own reporting duty under Act no. 90/2018 and Regulation (EU) 2016/679. Sub-processors are listed in the privacy policy and changes to them are notified in advance.

Security policy

  • To be a leading provider of data security and data backup
  • To make accurate information available in a secure manner
  • To ensure that technological innovation does not compromise security
  • To uphold sound business practices and data protection
  • To operate effective access-control systems
  • To keep employees' access privileges to a minimum
  • To make security the default in hosted services, not an option

Objectives of the security management system

The system is designed to protect the security of customer information in respect of its confidentiality, integrity and availability. Datatech complies with the laws and regulations governing information security management. Employees and contractors are bound to protect data against destruction, loss and unauthorised access.

Datatech promotes security awareness among its employees. A systematic risk assessment is carried out each year to determine the measures required. This policy shall conform to ÍST ISO/IEC 27001.

This policy was approved on 1 November 2024 and last reviewed on 30 August 2026, when hosted services were added to its scope.

Security Policy | Datatech