Security
Organisational Security Policy
Last updated 25 June 2026
At HeroPerks, we are committed to protecting personal data, systems, and services through strong organisational security practices. This policy outlines how we manage security across our organisation to ensure the confidentiality, integrity, and availability of information.
1. Purpose
The purpose of this policy is to protect personal and business data from unauthorised access, loss, or misuse, ensure secure handling of information across all operations, support compliance with UK data protection laws including UK GDPR, and maintain trust with users, partners, and stakeholders.
2. Our Security Approach
We follow a risk-based approach to security, meaning security measures are proportionate to the level of risk, we regularly assess threats and vulnerabilities, and we continuously improve our systems and processes. UK data protection law requires organisations to implement appropriate technical and organisational measures to protect personal data.
3. Key Security Principles
Confidentiality — access to data is restricted to authorised individuals only.
Integrity — data is accurate, complete, and protected from unauthorised changes.
Availability — systems and data remain accessible when needed, including recovery after incidents.
4. Organisational Controls
We implement organisational measures including clearly defined roles and responsibilities for data protection, internal policies covering data handling, access management, and security, staff training and awareness on data protection and security practices, and confidentiality obligations for employees, contractors, and partners.
5. Access Control
We ensure that access to systems is role-based and limited to what is necessary, permissions are regularly reviewed, and access is removed promptly when no longer required. This aligns with our Access Management Policy.
6. Technical Security Measures
We use appropriate technical controls such as secure hosting environments, encryption where appropriate, authentication and password controls, and system monitoring and updates. These measures are designed to protect against unauthorised access, loss, or damage to data.
7. Risk Management
We regularly assess risks relating to data processing activities, system vulnerabilities, and external threats. This helps us ensure our security measures remain appropriate and effective.
8. Incident and Breach Management
We have procedures in place to detect and respond to security incidents, contain and investigate breaches, and notify relevant parties where required. This aligns with our Breach Management processes.
9. Third-Party Security
Where we work with external providers, we ensure they meet appropriate security standards, data processing agreements are in place, and access is limited and controlled. We remain responsible for protecting data even when it is processed by third parties.
10. Testing and Continuous Improvement
We regularly review and update our security measures, test systems and controls where appropriate, and improve processes based on risks, incidents, and changes. UK GDPR requires organisations to regularly test and evaluate security effectiveness.
11. Responsibilities
All individuals within HeroPerks must follow security policies and procedures, protect access credentials, and report any security concerns or incidents immediately. Management is responsible for ensuring appropriate security controls are in place, maintaining compliance with legal requirements, supporting ongoing improvements, and aligning its security practices with recognised frameworks and industry best practices where appropriate.
12. Policy Review
This policy is reviewed at least annually, or when there are changes to systems, risks, or legal requirements.
13. Contact Us
If you have any questions about this Organisational Security Policy, please contact: [email protected]
Legal responsibility for the content on this page sits with Employees Global Ltd.