Data Security Policy
At Lorann LLC, our commitment to safeguarding the data and information of our clients, employees, and partners is unwavering. This policy outlines our approach to managing data security risks.
Protecting data with defense-in-depth architecture
This policy is applicable to all individuals, including employees, contractors, and third parties, who access Lorann LLC's data and information systems.
Data within Lorann's is categorized into three levels: Confidential information that could cause harm if disclosed; Internal Use Only information not intended for public dissemination; and Public information authorized for public release.
Access Control
Data access is granted based on the principle of least privilege. Employees are provided access only to the data and systems necessary for their job functions, and access permissions are reviewed regularly.
Encryption
Industry-standard encryption methods are employed to encrypt data in transit and at rest. This ensures that even if data is intercepted, it cannot be read without the proper decryption keys.
Physical Security
Access to premises housing data infrastructure is controlled and monitored. Physical records containing sensitive information are disposed of using secure destruction methods.
Network Security
Our network is safeguarded through firewalls, intrusion detection and prevention systems, and continuous monitoring. Regular vulnerability assessments and penetration testing are conducted.
Employee Training
All staff receive regular training to familiarize them with data protection responsibilities, recognize potential security threats, and follow proper data handling procedures.
Roles & Responsibilities
All employees are accountable for adhering to this policy and protecting the data they handle. The IT Department is tasked with ensuring the operational security of all IT systems.
Data Retention & Disposal
Data is retained only as long as necessary for business purposes or as required by law. When data is no longer needed, it is securely deleted using methods that prevent recovery.
Incident Response
our team has documented incident response procedures to detect, report, and investigate personal data breaches. Notification procedures follow GDPR and CCPA requirements.
Compliance & Review
This policy undergoes annual review and is updated in response to significant business or regulatory changes. Non-compliance may result in disciplinary action.
Questions about this policy?
Contact our team at privacy@lorannllc.com or call +1 561-459-4111
