Security Policy
1. Our commitment
DEFFINTECH PCC treats the confidentiality, integrity and availability of your data as a core responsibility. We apply appropriate technical and organizational measures under Article 32 of the GDPR, proportionate to the risks of our processing, and review them as the Platform evolves.
2. Technical measures
- Encryption in transit: all traffic to the Platform is served over HTTPS/TLS, and payment pages are protected end-to-end by our payment provider.
- Credential protection: passwords are never stored in plain text — they are stored as salted one-way hashes (bcrypt). Authentication uses stateless, signed tokens with expiry.
- Access control: the application enforces role-based authorization, and administrative and database access follow the principle of least privilege.
- Payment isolation: card data is handled by Stripe (PCI-DSS compliant); we do not store full card numbers on our systems.
- Input validation & hardening: server-side validation, secure session handling and standard protections against common web vulnerabilities.
- Backups & recovery: the database is backed up so the service can be restored after an incident.
- Monitoring: server and security logs are kept for a limited period to detect and investigate abuse.
3. Organizational measures
- Access to personal data is restricted to those who need it to operate the service, under confidentiality obligations.
- Service providers (processors) are engaged under data-processing agreements consistent with the GDPR.
- Changes to the Platform follow secure development practices, including code review and testing before release.
4. Data-breach handling
We maintain an incident-response process. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the GDPR. Where the breach is likely to result in a high risk to you, we will also inform affected individuals in accordance with Article 34.
5. Reporting a vulnerability (responsible disclosure)
If you discover a security vulnerability, please report it privately to security@deffintech.com with enough detail to reproduce it. Please do not access or modify other users’ data, disrupt the service, or publicly disclose the issue before we have had a reasonable opportunity to remediate it. We appreciate and will acknowledge good-faith reports.
6. Your part in security
Use a strong, unique password, keep your device and browser up to date, and never share your login. Contact us immediately at the address above if you believe your account has been compromised.
7. Contact
DEFFINTECH PCC — Anoixeos 23 & Grigoriou E’, 13451 Kamatero, Attica, Greece · security@deffintech.com.
This statement describes our current practices and is provided for information; it is not a warranty and is not a substitute for individual legal advice.