Security & Privacy Policy
Applies to: 42 Support, 42 Ekonomi
Security is fundamental to how we build and operate our Services.
- protecting Customer Data using appropriate technical and organisational measures;
- continuously improving our security practices;
- limiting access to Customer Data;
- monitoring our systems for security issues;
- maintaining backup and recovery procedures;
- notifying Customers of qualifying personal data breaches as required by law.
No Internet-connected system can be guaranteed to be completely secure.
This summary is provided for convenience only. The legally binding terms are set out below.
Purpose
This Security & Privacy Policy describes the principles and practices used by 42 Scandinavia AB to protect the confidentiality, integrity and availability of the Services and Customer Data.
This document provides an overview only.
Additional contractual obligations are contained in:
Security Principles
42 Scandinavia designs and operates its Services according to the following principles:
- least privilege;
- defence in depth;
- secure by default;
- privacy by design;
- privacy by default;
- continuous improvement;
- risk-based decision making.
Data Ownership
Customer Data always belongs to the Customer.
42 Scandinavia does not acquire ownership rights in Customer Data.
Customer Data is processed only:
- to provide the Services;
- to provide support;
- to maintain security;
- to comply with applicable law.
We do not sell Customer Data.
Authentication
Access to administrative systems is restricted to authorised personnel.
Customers are responsible for maintaining the confidentiality of their account credentials.
Customers should use strong passwords and enable additional authentication mechanisms where available.
Access Control
Access to Customer Data is limited to personnel who require access for legitimate business purposes.
Access rights are reviewed periodically.
Administrative access is granted according to the principle of least privilege.
Infrastructure
The Services are hosted using managed cloud infrastructure provided through Lovable and its underlying infrastructure providers where applicable.
Infrastructure providers are responsible for physical security of their facilities.
42 Scandinavia remains responsible for application security and protection of Customer Data under applicable agreements.
Encryption
Communications between users and the Services are protected using industry-standard transport encryption (TLS).
Sensitive information should never be transmitted through insecure channels.
Encryption methods may evolve over time as industry standards change.
Monitoring
42 Scandinavia monitors the Services for:
- availability;
- operational health;
- security events;
- abnormal behaviour;
- unauthorised access attempts.
Monitoring is intended to protect both Customers and the Services.
Vulnerability Management
Security vulnerabilities are assessed according to risk.
Where appropriate, vulnerabilities are:
- prioritised;
- mitigated;
- monitored;
- remediated.
Critical vulnerabilities are addressed with high priority.
Incident Response
42 Scandinavia maintains procedures for responding to:
- security incidents;
- operational incidents;
- service disruptions;
- suspected unauthorised access;
- Personal Data breaches.
Incidents are investigated, documented and resolved according to their severity.
Personal Data Breaches
Where required by GDPR, Customers will be notified without undue delay following confirmation of a Personal Data breach affecting Customer Data.
Notifications will include available information necessary to assist Customers in meeting their own legal obligations.
Business Continuity
42 Scandinavia maintains backup and recovery procedures intended to reduce the impact of unexpected events.
Backup retention periods are described in the Backup & Disaster Recovery Policy.
Customer Responsibilities
Customers are responsible for:
- protecting account credentials;
- managing authorised users;
- exporting data where appropriate;
- complying with applicable laws;
- ensuring that Personal Data uploaded to the Services may lawfully be processed.
Responsible Disclosure
42 Scandinavia appreciates responsible reporting of security vulnerabilities.
Anyone who discovers a potential security issue is encouraged to report it to: magnus.backlund@42scandinavia.se
Reports should include sufficient information to reproduce the issue where possible.
42 Scandinavia requests that researchers:
- act in good faith;
- avoid unnecessary disruption;
- avoid accessing Customer Data;
- allow reasonable time for remediation before public disclosure.
Security Improvements
Security practices evolve continuously.
42 Scandinavia may improve technical and organisational security measures without prior notice where such improvements do not materially reduce Customer protections.
Contact
Security questions may be directed to:
42 Scandinavia AB
Organisation No. 556827-3204
P O Hallmans gata 3
SE-112 06 Stockholm
Sweden
Document History
| Version | Date | Description |
|---|---|---|
| 1.0 | Publication | Initial release |
