HeroPerks

Return

Security

Access Management Policy

Last updated 25 June 2026

This Access Management Policy explains how HeroPerks controls, manages, and monitors access to systems, data, and services to protect personal data and maintain platform security.

1. Purpose

The purpose of this policy is to ensure that access to systems and data is restricted to authorised individuals only, appropriate to each user’s role, managed securely and consistently, and regularly reviewed and updated.

2. Scope

This policy applies to employees and contractors, business partners with system access, third-party service providers, and internal systems and external platforms used by HeroPerks.

3. Access Principles

Least Privilege — users are given the minimum level of access required to perform their role.

Need to Know — access to data is granted only where necessary for specific tasks.

Role-Based Access — permissions are assigned based on job responsibilities.

4. User Access Management

Access Provisioning — access is granted based on role and business need, requests must be approved by an authorised person, and access is provided using secure credentials.

Access Changes — access rights are updated when roles or responsibilities change, and permissions are adjusted promptly to reflect new requirements.

Access Removal — access is revoked immediately when no longer required, including employee departures, contract endings, or role changes.

5. Authentication and Security

We use appropriate measures to ensure secure access, including strong password requirements, multi-factor authentication (where applicable), secure login systems, and session controls and timeouts. Users are responsible for keeping login credentials confidential.

6. Monitoring and Logging

Access to systems may be logged and monitored, logs are reviewed where necessary to detect unauthorised activity, and any suspicious behaviour is investigated promptly.

7. Third-Party Access

Where third parties require access, access is limited to what is necessary, agreements are in place to ensure data protection compliance, and security standards must be met before access is granted.

8. Data Protection

Access controls are designed to support our wider data protection obligations, including protecting personal data from unauthorised access, supporting confidentiality and integrity of data, and aligning with our Privacy Policy and Data Handling Policy.

9. Incident Management

If unauthorised access or a security issue is identified, immediate action will be taken to secure systems, access may be suspended or restricted, the incident will be investigated, and relevant parties will be notified where required.

10. Responsibilities

All users with access to HeroPerks systems must use access responsibly, keep credentials secure, and report any suspicious activity immediately. Management is responsible for approving access requests, ensuring appropriate access levels, and supporting regular reviews.

11. Policy Review

This policy is reviewed at least annually, or when systems, risks, or legal requirements change. Access rights are subject to periodic review to ensure continued appropriateness and compliance.

12. Contact Us

If you have any questions about this policy, please contact: [email protected]


Legal responsibility for the content on this page sits with Employees Global Ltd.