Security Policy

Last Updated: 6 December 2024

Nicepeu is committed to maintaining the security, integrity, and confidentiality of all data processed through our platform. This Security Policy describes the technical and organisational measures we implement to protect our systems, infrastructure, and the information entrusted to us by our users.

By accessing or using our services, you acknowledge that you have read and understood this policy. We encourage all users to review this document periodically, as it may be updated to reflect changes in our security practices.

1. Scope

This policy applies to all digital services, platforms, systems, and infrastructure operated by Nicepeu, including our website at nicepeu.info, associated subdomains, internal tools, and any third-party integrations used in the delivery of our services.

It covers all data processed, transmitted, or stored within our environment, including but not limited to user account information, usage data, communication records, and educational content.

2. Information Security Principles

Our security programme is guided by three core principles:

  • Confidentiality: Information is accessible only to those authorised to access it.
  • Integrity: Data is accurate, complete, and protected against unauthorised modification.
  • Availability: Systems and data are accessible to authorised users when required.

These principles inform all decisions related to system design, access management, data handling, and incident response.

3. Access Control

3.1 User Authentication

Access to our platform requires user authentication through secure login mechanisms. We support and encourage the use of strong, unique passwords. Where applicable, multi-factor authentication options are made available to users to provide an additional layer of account protection.

3.2 Internal Access Management

Access to internal systems and sensitive data by our staff is governed by the principle of least privilege. Employees are granted access only to the systems and data necessary to perform their specific job functions. Access rights are reviewed regularly and revoked promptly upon role changes or departure.

3.3 Administrative Controls

Administrative access to production systems is restricted to a limited number of authorised personnel. All administrative actions are logged and subject to periodic audit. Remote access to internal infrastructure requires secure, authenticated connections.

4. Data Encryption

4.1 Data in Transit

All data transmitted between users and our platform is encrypted using industry-standard Transport Layer Security (TLS) protocols. We enforce secure connections and do not permit unencrypted data transmission over public networks.

4.2 Data at Rest

Sensitive data stored within our systems is encrypted using strong encryption standards. Encryption keys are managed securely and rotated on a defined schedule. Access to encryption keys is strictly controlled and audited.

5. Infrastructure Security

5.1 Network Security

Our infrastructure is protected by multiple layers of network security controls, including firewalls, intrusion detection systems, and network segmentation. Traffic to and from our systems is monitored continuously for anomalous behaviour.

5.2 Server and System Hardening

All servers and systems are configured according to security hardening guidelines. Unnecessary services, ports, and software are disabled or removed. Operating systems and software components are kept up to date with security patches applied promptly following release.

5.3 Cloud and Hosting Security

Where cloud infrastructure is used, we select providers that maintain recognised security certifications and comply with established industry standards. We configure cloud environments in accordance with security best practices and conduct regular reviews of our cloud security posture.

6. Vulnerability Management

6.1 Security Assessments

We conduct regular security assessments of our systems, including vulnerability scans and periodic penetration testing. Identified vulnerabilities are prioritised and remediated according to their severity and potential impact.

6.2 Patch Management

A structured patch management process ensures that security updates are evaluated, tested, and applied in a timely manner. Critical security patches are prioritised for immediate deployment. We maintain an inventory of all software components and monitor for known vulnerabilities.

6.3 Responsible Disclosure

We welcome responsible disclosure of security vulnerabilities from external researchers and users. If you discover a potential security issue affecting our platform, please contact us directly at contact@nicepeu.info. We ask that you refrain from publicly disclosing the issue until we have had a reasonable opportunity to investigate and address it.

7. Incident Response

7.1 Detection and Response

We maintain an incident response programme designed to detect, contain, and remediate security incidents in a timely manner. Our systems are monitored continuously, and alerts are reviewed by qualified personnel. Upon detection of a security incident, a defined response procedure is initiated immediately.

7.2 Notification

In the event of a security incident that may affect user data, we will notify affected users and relevant parties in accordance with applicable requirements and without undue delay. Notifications will include information about the nature of the incident, the data potentially affected, and the steps being taken in response.

7.3 Post-Incident Review

Following any significant security incident, we conduct a thorough review to identify root causes, assess the effectiveness of our response, and implement improvements to prevent recurrence. Lessons learned are incorporated into our security programme.

8. Third-Party Security

We carefully evaluate the security practices of third-party service providers before engaging them. Providers who process data on our behalf are required to maintain appropriate security standards. We conduct periodic reviews of third-party security arrangements and ensure that contractual obligations regarding data protection and security are in place.

9. Physical Security

Physical access to facilities where our systems and data are hosted is controlled and restricted to authorised personnel. Data centres and hosting facilities used by Nicepeu maintain physical security controls including access logging, surveillance, and environmental protections against fire, flooding, and power disruption.

10. Employee Security Practices

All employees and contractors with access to our systems are required to adhere to our internal security policies and procedures. Security awareness training is provided on a regular basis to ensure that staff remain informed about current threats and best practices. Background checks are conducted for personnel in roles with access to sensitive systems or data, where permitted.

11. Data Retention and Disposal

Data is retained only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable obligations. When data is no longer required, it is disposed of securely using methods appropriate to the sensitivity of the information. Storage media containing sensitive data is sanitised or destroyed before disposal or repurposing.

12. Business Continuity and Backup

We maintain backup procedures to ensure that data can be recovered in the event of loss or corruption. Backups are performed regularly, stored securely, and tested periodically to verify their integrity and restorability. Our business continuity arrangements are designed to minimise disruption to services in the event of an unexpected incident.

13. Logging and Monitoring

Security-relevant events across our infrastructure are logged and retained for a defined period. Logs are protected against unauthorised modification and are reviewed as part of our ongoing security monitoring activities. Monitoring systems are configured to alert on conditions that may indicate a security threat or anomaly.

14. User Responsibilities

Users of our platform share responsibility for maintaining the security of their accounts and interactions with our services. We ask that users:

  • Use strong, unique passwords for their accounts and do not share credentials with others.
  • Enable multi-factor authentication where available.
  • Report any suspected unauthorised access to their account promptly.
  • Keep their devices and software up to date with security patches.
  • Exercise caution when clicking links or opening attachments received by email or other communications.
  • Refrain from attempting to access systems, data, or accounts for which they are not authorised.

15. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this document and, where appropriate, provide notice through our platform or by other means. We encourage users to review this policy periodically.

16. Contact

If you have any questions, concerns, or requests relating to this Security Policy or our security practices, please contact us:

Contact Method Details
Company Nicepeu
Email contact@nicepeu.info
Phone +353 46 955 7077
Address Waterford Airport, Unit 5, Gulfstream Avenue, Waterford, Ireland
Website nicepeu.info