Vendira

Legal

Security

A summary of the technical and organisational measures we apply to customer data. It is a summary, not a specification.

Last updated

1. Technical and organisational measures

MX Hospitality B.V., trading as Vendira applies technical and organisational measures appropriate to the risk, as required by Article 32 of the General Data Protection Regulation. These include:

  • Segregation of customer data, enforced at the data layer.
  • Access control on a need-to-know basis, with authentication required for all non-public functions.
  • Encryption of credentials at rest, and encryption of data in transit using TLS 1.2 or higher.
  • Logging of administrative and authentication events.
  • Regular backups, held within the European Union.
  • Review of access rights and of changes to the service before release.

The measures applied may change as the service develops. Any change will maintain a level of security appropriate to the risk.

2. Data we do not process

We do not request, receive or store:

  • Payment card details. Payments are processed by Stripe on its own hosted pages.
  • Amazon Seller Central account credentials. Access is granted through Amazon's authorisation process and may be withdrawn by you at any time.
  • Amazon buyer identity data. The service does not call Amazon's restricted operations. Free-text fields supplied by Amazon may contain such data incidentally; this is addressed in the Privacy Policy.

3. Incident notification

Where we become aware of a personal data breach we will notify the competent supervisory authority within 72 hours in accordance with Article 33 of the General Data Protection Regulation, and will notify affected data subjects where Article 34 requires it.

Where an incident affects information obtained through Amazon's Selling Partner API, we will notify Amazon within 24 hours, as required by Amazon's Data Protection Policy.

Affected customers will be notified without undue delay at the contact address held on their account.

4. Certifications

We do not hold a SOC 2 report or an ISO 27001 certificate and make no representation that we do.

5. Reporting a vulnerability

Report suspected vulnerabilities to support@vendira.co with sufficient detail to reproduce the issue. When doing so, do not access data belonging to others and do not conduct automated testing against the production service.

6. Further information

Requests for a security questionnaire, a data processing agreement or further detail on the measures summarised above should be sent to support@vendira.co.

This statement should be read with our Privacy Policy and Sub-processors page.