Dealquora
Dealquora
Online across Australia
+61 2 9838 4415

Security Policy

Last Updated: July 6, 2024


Dealquora is committed to protecting the security of information processed through its platform. This Security Policy describes the technical and organisational measures we apply to safeguard data and maintain the integrity, availability, and confidentiality of our services.

1. Scope

This policy applies to all systems, infrastructure, personnel, and third-party integrations involved in the operation of Dealquora's online platform and associated services. It covers all data processed on behalf of users, participants, and clients.

2. Information Security Principles

Our security programme is built on three foundational principles:

3. Data Transmission Security

All data transmitted between users and our platform is encrypted in transit using industry-standard Transport Layer Security (TLS). Unencrypted connections are not permitted for any service endpoint that handles personal or session data.

4. Data Storage Security

Data stored within our systems is protected through the following measures:

5. Access Control

5.1 User Access

User accounts are protected by credential-based authentication. Users are responsible for maintaining the confidentiality of their login credentials. We support session management controls including automatic session expiry after periods of inactivity.

5.2 Administrative Access

Internal access to production systems is restricted to authorised personnel on a need-to-know basis. Administrative access is subject to multi-factor authentication and is logged for audit purposes. Privileges are reviewed periodically and revoked upon role change or departure.

5.3 Third-Party Access

Where third-party service providers require access to systems or data, such access is governed by contractual obligations, limited in scope, and subject to the same security standards applied internally.

6. Network and Infrastructure Security

7. Application Security

Security considerations are integrated into our development lifecycle. Measures include:

8. Vulnerability Management

We maintain an ongoing programme to identify, assess, and remediate security vulnerabilities. This includes monitoring of security advisories relevant to our technology stack and prompt application of patches to address identified risks. Critical vulnerabilities are prioritised for immediate remediation.

9. Security Monitoring and Logging

System and application events are logged to support security monitoring, incident detection, and forensic investigation. Logs are retained for a defined period and protected against unauthorised modification. Automated alerting is in place for events that indicate potential security incidents.

10. Incident Response

We maintain an incident response process to address security events in a timely and structured manner. Upon detection of a security incident, our response includes:

  1. Containment of the incident to limit impact
  2. Investigation to determine scope and root cause
  3. Remediation of the underlying issue
  4. Notification to affected parties where required
  5. Post-incident review to improve future response

Affected users will be notified of incidents that materially affect their data in accordance with our Privacy Policy and applicable obligations.

11. Business Continuity and Availability

We maintain backup procedures to ensure data can be recovered in the event of system failure or data loss. Backups are performed regularly, stored securely, and tested periodically to verify recoverability. Our infrastructure is designed with redundancy to support service continuity.

12. Personnel Security

Staff with access to systems or data are subject to security awareness training. Security responsibilities are communicated as part of onboarding and reinforced through ongoing guidance. Access rights are managed throughout the employment lifecycle and promptly revoked upon termination.

13. Physical Security

Our services are delivered through cloud infrastructure hosted in facilities that maintain physical access controls, environmental protections, and operational security measures appropriate for data centre environments.

14. Third-Party and Supply Chain Security

We evaluate the security posture of third-party providers before engagement and on an ongoing basis. Providers are required to maintain security standards consistent with this policy. Data processing agreements are established with providers who handle personal data on our behalf.

15. Responsible Disclosure

If you discover a potential security vulnerability in our platform or services, we encourage responsible disclosure. Please report findings to us at support@dealquora.info with sufficient detail to allow us to assess and reproduce the issue. We will acknowledge receipt and work to address confirmed vulnerabilities promptly. We ask that you refrain from exploiting any vulnerability or disclosing it publicly before we have had reasonable opportunity to respond.

16. Policy Review

This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our systems, practices, or the threat environment. Continued use of our services following any update constitutes acceptance of the revised policy.

17. Contact

For questions or concerns regarding this Security Policy, please contact us:

Dealquora
Sturt St, Ballarat Central VIC 3350, Australia
Email: support@dealquora.info
Phone: +61 2 9838 4415