Security Statement
Updated · Version 2
This is the public summary of how we protect the data behind brandslabeg.com. The detailed incident procedure is an internal document.
1. Where the data lives
The website, its database and its file storage run on Cloudflare's platform in the European Union. Mail is delivered through Resend and Google. No data is kept on office computers beyond the mailboxes.
2. How it is protected
- Every connection is encrypted in transit.
- Email addresses, contact details and other sensitive fields are encrypted at rest; the system searches them by a one-way hash.
- Access is by role. The owner signs in with a one-time code sent to a known mailbox. Staff sign in with their card and its PIN, on a device the system remembers; five wrong PINs lock that card. Sessions expire after inactivity.
- Every form is protected by an anti-abuse check and by rate limits.
- Records are kept in a ledger whose entries are chained, so any tampering shows.
- Backups are taken daily and kept for thirty-five days.
- The systems are monitored, and their quotas are watched so a failure cannot run silently.
3. What we keep to a minimum
We collect only what a request needs. No phone numbers asked of customers, no payment data, no identity documents, no advertising trackers.
4. If something goes wrong
If a breach affects personal data, we notify the Personal Data Protection Centre within 72 hours of becoming aware of it, and the affected people within three working days after that, with what happened and what we did.
5. Reporting a weakness
If you find a security weakness, write to security@brandslabeg.com. Tell us what you found and how to reproduce it. Do not access or change data that is not yours. We reply, fix, and thank you; we do not pursue good-faith reports.
6. Changes
Each version carries a date and a version number.
The English text governs if the two languages ever differ.