Data Classification and Encryption Policy
1. Policy Purpose
This policy defines information classification and data encryption requirements within Weblo TTS.
2. Data Classification Levels
- Public - data intended for disclosure.
- Internal - operational data with limited access.
- Confidential - business and technical data requiring protection.
- Strictly Confidential - highest-sensitivity data, including tokens and secrets.
3. Data Labeling and Handling
Data owners are responsible for classification, labeling, and applying suitable safeguards throughout processing.
4. Encryption in Transit
Data transmission uses TLS 1.2+ and up-to-date secure cryptographic configurations.
5. Encryption at Rest
Confidential and strictly confidential data is encrypted at database, volume, or object storage level.
6. Cryptographic Key Management
Keys are stored in dedicated secrets management systems, rotated, and made available only to authorized entities.
7. Exceptions and Risk Acceptance
Policy exceptions require formal risk acceptance, time limitations, and a mitigation plan.
8. Audit and Compliance
Compliance is subject to periodic review and corrective actions where needed.
Document Approval
This document has been approved by the Management Board of TIME4IT Sp. z o.o.
Version: 1.0
Approval date: 22 June 2026
Contact
For questions regarding this document, security or privacy:
TIME4IT Sp. z o.o.ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]