Security
Access Management Policy
Last updated 25 June 2026
This Access Management Policy explains how HeroPerks controls, manages, and monitors access to systems, data, and services to protect personal data and maintain platform security.
1. Purpose
The purpose of this policy is to ensure that access to systems and data is restricted to authorised individuals only, appropriate to each user’s role, managed securely and consistently, and regularly reviewed and updated.
2. Scope
This policy applies to employees and contractors, business partners with system access, third-party service providers, and internal systems and external platforms used by HeroPerks.
3. Access Principles
Least Privilege — users are given the minimum level of access required to perform their role.
Need to Know — access to data is granted only where necessary for specific tasks.
Role-Based Access — permissions are assigned based on job responsibilities.
4. User Access Management
Access Provisioning — access is granted based on role and business need, requests must be approved by an authorised person, and access is provided using secure credentials.
Access Changes — access rights are updated when roles or responsibilities change, and permissions are adjusted promptly to reflect new requirements.
Access Removal — access is revoked immediately when no longer required, including employee departures, contract endings, or role changes.
5. Authentication and Security
We use appropriate measures to ensure secure access, including strong password requirements, multi-factor authentication (where applicable), secure login systems, and session controls and timeouts. Users are responsible for keeping login credentials confidential.
6. Monitoring and Logging
Access to systems may be logged and monitored, logs are reviewed where necessary to detect unauthorised activity, and any suspicious behaviour is investigated promptly.
7. Third-Party Access
Where third parties require access, access is limited to what is necessary, agreements are in place to ensure data protection compliance, and security standards must be met before access is granted.
8. Data Protection
Access controls are designed to support our wider data protection obligations, including protecting personal data from unauthorised access, supporting confidentiality and integrity of data, and aligning with our Privacy Policy and Data Handling Policy.
9. Incident Management
If unauthorised access or a security issue is identified, immediate action will be taken to secure systems, access may be suspended or restricted, the incident will be investigated, and relevant parties will be notified where required.
10. Responsibilities
All users with access to HeroPerks systems must use access responsibly, keep credentials secure, and report any suspicious activity immediately. Management is responsible for approving access requests, ensuring appropriate access levels, and supporting regular reviews.
11. Policy Review
This policy is reviewed at least annually, or when systems, risks, or legal requirements change. Access rights are subject to periodic review to ensure continued appropriateness and compliance.
12. Contact Us
If you have any questions about this policy, please contact: [email protected]
Legal responsibility for the content on this page sits with Employees Global Ltd.