Security Policy
Last Updated: March 14, 2025
Sterlingly is committed to protecting the security of your personal information and maintaining the integrity of our online education platform. This Security Policy outlines the measures we implement to safeguard your data and ensure a secure learning environment.
Information Security Framework
We maintain a comprehensive information security program designed to protect the confidentiality, integrity, and availability of all data processed through our platform. Our security framework is built on industry-standard practices and continuously updated to address emerging threats.
Administrative Safeguards
- Regular security awareness training for all personnel
- Defined roles and responsibilities for data protection
- Background verification procedures for staff with data access
- Incident response and breach notification protocols
- Regular security policy reviews and updates
Technical Safeguards
- Encryption of data in transit using industry-standard protocols
- Encryption of sensitive data at rest
- Secure authentication mechanisms and password policies
- Regular security assessments and vulnerability scanning
- Automated monitoring and intrusion detection systems
- Secure software development practices
- Regular security patches and system updates
Physical Safeguards
- Secure data center facilities with restricted access
- Environmental controls and disaster recovery measures
- Secure disposal procedures for hardware and media
Data Protection Measures
Access Controls
We implement strict access control measures to ensure that personal information is accessible only to authorized personnel who require it to perform their job functions. Access rights are granted based on the principle of least privilege and are regularly reviewed.
Authentication and Authorization
Our platform employs secure authentication mechanisms to verify user identities. We encourage users to:
- Create strong, unique passwords
- Enable multi-factor authentication where available
- Keep login credentials confidential
- Log out after completing sessions on shared devices
Data Encryption
We use encryption technologies to protect data during transmission and storage. All communications between your browser and our servers are encrypted using secure socket layer technology.
Network Security
Our network infrastructure is protected by multiple layers of security controls including firewalls, intrusion detection and prevention systems, and network segmentation. We continuously monitor network traffic for suspicious activity and potential security incidents.
Application Security
We follow secure coding practices and conduct regular security testing of our applications, including:
- Code reviews and static analysis
- Dynamic application security testing
- Penetration testing by qualified security professionals
- Vulnerability assessments and remediation
Third-Party Security
When we engage third-party service providers who may process or have access to user data, we require them to maintain security standards comparable to our own. We conduct due diligence reviews and include appropriate security requirements in our agreements with vendors.
Incident Response
Security Incident Management
We maintain an incident response plan to address potential security breaches or data incidents. Our response procedures include:
- Immediate containment and investigation of incidents
- Assessment of impact and affected data
- Notification to affected users as required by applicable law
- Remediation and preventive measures
- Post-incident review and improvement
Breach Notification
In the event of a data breach that affects your personal information, we will notify you in accordance with applicable legal requirements. Notifications will include information about the nature of the breach, the data involved, and steps you can take to protect yourself.
User Responsibilities
While we implement robust security measures, users also play an important role in maintaining security:
- Maintain the confidentiality of your account credentials
- Use secure networks when accessing our platform
- Keep your devices and software updated
- Report suspicious activity or potential security issues promptly
- Review and understand our security recommendations
Payment Security
All payment transactions are processed through secure, encrypted connections. We do not store complete credit card information on our servers. Payment processing is handled by certified payment service providers that comply with payment card industry data security standards.
Data Backup and Recovery
We maintain regular backups of platform data to ensure business continuity and data recovery in the event of system failures or disasters. Backup data is stored securely and encrypted to maintain confidentiality.
Security Audits and Compliance
We conduct regular internal security audits and assessments to evaluate the effectiveness of our security controls. We also engage independent third parties to perform security audits and penetration testing on a periodic basis.
Continuous Improvement
Information security is an ongoing process. We continuously monitor the threat landscape, review our security practices, and implement improvements to address new risks and vulnerabilities. Our security program evolves to incorporate new technologies and best practices.
Security Training
All personnel with access to user data receive regular security awareness training covering topics such as:
- Data protection principles and requirements
- Recognizing and reporting security threats
- Secure handling of sensitive information
- Incident response procedures
Reporting Security Issues
If you discover a security vulnerability or have concerns about the security of our platform, please report it to us immediately. We take all security reports seriously and will investigate them promptly.
To report a security issue, contact us at:
Email: [email protected]
Phone: +353526131383
When reporting a security issue, please provide as much detail as possible to help us understand and address the concern effectively.
Limitations
While we implement comprehensive security measures, no system can be completely secure. We cannot guarantee absolute security of data transmitted over the internet or stored electronically. Users acknowledge that they provide information at their own risk.
Changes to This Policy
We may update this Security Policy periodically to reflect changes in our security practices or legal requirements. We will post the updated policy on our website with a revised effective date. We encourage you to review this policy regularly to stay informed about how we protect your information.
Contact Information
If you have questions or concerns about our security practices, please contact us:
Sterlingly
26 The Rise, meadowvale, Arklow, Co. Wicklow, Y14 P024, Ireland
Phone: +353526131383
Email: [email protected]