Information Security Policy

Sigma Capital Jakub Jasiński

⬇ Download PDF
Document version1.0
Effective date2026-09-03
Next review2027-09-03
Policy ownerOwner / Managing Director

1. Purpose and scope

This policy defines how Sigmapack protects the confidentiality, integrity and availability of the information it processes, including personal data of customers and data obtained through connected e-commerce platforms.

The policy applies to all systems, applications, devices and third-party services used to operate our online retail business, and to every person acting on our behalf, including owners, employees and contractors. It covers our internal order management application, the databases supporting it, connected marketplace and logistics integrations, and the workstations and devices used to access them.

2. Governance and responsibilities

Sigmapack is a small organization. Accountability for information security rests with the Owner / Managing Director, who approves this policy, allocates resources for security measures, and reviews the policy at planned intervals.

3. Data classification and handling

We classify information into three levels and handle it accordingly:

We do not store payment card data. Payments are processed by the marketplace or payment provider; our systems never receive or retain full card numbers, CVV codes or bank credentials.

4. Access control

5. Credential and secret management

6. Encryption and network security

7. System and application security

8. Logging and monitoring

9. Backup and recovery

10. Third-party and vendor management

We rely on external providers for hosting, payment processing, marketplace integration, fiscal document issuance and logistics. Before granting a provider access to our data we assess whether it offers adequate security and privacy safeguards.

11. Incident response

When a security incident is suspected or confirmed, we follow these steps:

12. Data retention and deletion

13. Privacy and data subject rights

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR). Processing is limited to what is necessary for order fulfilment, customer service, accounting and legal compliance.

14. Awareness and training

15. Policy review

This policy is reviewed at least annually, and additionally after a significant security incident, a material change to our systems or integrations, or a change in applicable law. Updates are approved by the policy owner, and the version and effective date at the top of this document are updated accordingly.

16. Contact

Questions regarding this policy, security concerns, or requests relating to personal data should be directed to: jakub@sigmapack.pl.