Data Protection Policy
1. Data Security Framework
RPTech Software Marketplace is committed to implementing and maintaining a comprehensive data security framework that protects the confidentiality, integrity, and availability of all data entrusted to us by our customers, partners, and users. This Data Protection Policy outlines the measures we take to safeguard data throughout its lifecycle.
Our data security framework is built upon the following core principles:
- Defense in Depth: We employ multiple layers of security controls to protect data at every level of our infrastructure.
- Least Privilege: Access to data is granted on a need-to-know basis with the minimum privileges required to perform job functions.
- Security by Design: Security considerations are integrated into every stage of our software development lifecycle and infrastructure design.
- Continuous Monitoring: We continuously monitor our systems for threats, vulnerabilities, and anomalies using automated tools and manual reviews.
- Incident Preparedness: We maintain comprehensive incident response plans to ensure rapid detection, containment, and resolution of security incidents.
This policy applies to all data processed by RPTech Software Marketplace, including customer data, employee data, business data, and any other sensitive information entrusted to us.
2. Encryption
We employ industry-leading encryption technologies to protect data throughout its lifecycle:
2.1 Data in Transit
All data transmitted between client applications and our servers is encrypted using Transport Layer Security (TLS) 1.3 with 256-bit encryption. This includes:
- All web traffic (HTTPS) between browsers and our web servers
- API communications between client applications and our servers
- Email communications using TLS encryption
- File transfers using SFTP or SCP protocols
- Database connections using encrypted connections
- Internal service-to-service communication within our infrastructure
We enforce TLS 1.2 or higher for all connections and reject connections using deprecated or insecure protocols. Our SSL/TLS certificates are issued by trusted Certificate Authorities and are renewed automatically before expiration.
2.2 Data at Rest
All data stored on our servers is encrypted at rest using AES-256 (Advanced Encryption Standard) encryption. This includes:
- Database storage with column-level encryption for sensitive fields (passwords, payment information, personal identifiers)
- File storage with full-disk encryption
- Backup storage with encryption at rest
- Log files with sensitive data redacted or encrypted
- Temporary files and cache data
- API keys and secrets stored in encrypted vaults
Encryption keys are managed through a secure key management system with regular key rotation. Access to encryption keys is strictly controlled and audited.
3. Backup and Recovery
We maintain a comprehensive backup and recovery program to ensure data availability and business continuity:
- Automated Backups: Full database backups are performed daily at scheduled intervals. Incremental backups are performed every 4 hours for critical data.
- Backup Retention: Daily backups are retained for 30 days. Weekly backups are retained for 12 months. Monthly backups are retained for 7 years for compliance purposes.
- Geographic Redundancy: Backups are stored in geographically separate data centers to protect against regional disasters. A minimum of two geographic regions are used for backup storage.
- Encryption: All backups are encrypted at rest using AES-256 encryption. Backup encryption keys are stored separately from the backup data.
- Integrity Verification: Regular integrity checks are performed on all backups to ensure they can be successfully restored.
- Recovery Testing: Backup restoration tests are performed monthly to verify recovery procedures and measure recovery time objectives (RTO) and recovery point objectives (RPO).
- Recovery Time Objective (RTO): 4 hours for critical systems, 24 hours for non-critical systems.
- Recovery Point Objective (RPO): 4 hours for critical systems, 24 hours for non-critical systems.
4. Access Control
We implement robust access control measures to ensure that only authorized personnel can access data:
- Authentication: Multi-factor authentication (MFA) is required for all administrative access to systems containing customer data. Strong password policies are enforced across all accounts.
- Authorization: Role-based access control (RBAC) is implemented to ensure that personnel have access only to the data and systems necessary for their job functions. Access permissions are reviewed quarterly.
- Privileged Access: Privileged access to production systems is limited to a small number of authorized personnel. All privileged access is logged, monitored, and reviewed.
- Access Logging: All access to customer data is logged with user identity, timestamp, action performed, and source IP address. Access logs are retained for 12 months and are reviewed regularly.
- Access Review: Access permissions are reviewed quarterly. Access is promptly revoked when personnel change roles or leave the organization.
- Physical Security: Data center facilities employ multi-layer physical security including biometric access controls, 24/7 security personnel, CCTV monitoring, and visitor logging.
5. Disaster Recovery
RPTech Software Marketplace maintains a comprehensive disaster recovery plan to ensure business continuity in the event of a major disruption:
- Disaster Recovery Plan: A documented disaster recovery plan is maintained and updated semi-annually. The plan covers all critical business systems and services.
- Failover Systems: Critical systems are deployed in high-availability configurations with automatic failover capabilities.
- Geographic Distribution: Production infrastructure is distributed across multiple geographic regions to protect against regional disasters.
- Communication Plan: A disaster communication plan ensures that all stakeholders are promptly notified during a disaster event.
- Testing: Disaster recovery tests are performed semi-annually to validate recovery procedures and ensure that recovery objectives can be met.
- Third-Party Coordination: We maintain disaster recovery agreements with our key infrastructure providers and vendors to ensure coordinated recovery efforts.
6. Data Retention
We retain data in accordance with applicable legal requirements and our business needs:
| Data Type | Retention Period | Justification |
|---|---|---|
| Customer Account Data | Duration of account + 5 years | Business continuity and legal compliance |
| Transaction Records | 7 years | Tax and financial regulations |
| Support Tickets | 3 years after resolution | Service quality and dispute resolution |
| System Logs | 12 months | Security monitoring and troubleshooting |
| Marketing Data | Until consent withdrawn | Marketing consent management |
| Employee Data | Employment + 7 years | Employment law compliance |
| Backup Data | As per backup retention schedule | Disaster recovery and business continuity |
Data that is no longer required is securely deleted using industry-standard data destruction methods.
7. Compliance
RPTech Software Marketplace complies with applicable data protection regulations and maintains relevant certifications:
7.1 GDPR Compliance
We comply with the General Data Protection Regulation (GDPR) for all data processing activities involving EU/EEA data subjects. Our GDPR compliance measures include:
- Lawful basis for processing identified and documented for all data processing activities
- Data Protection Impact Assessments (DPIAs) conducted for high-risk processing activities
- Technical and organizational measures implemented to ensure data protection by design and by default
- Data subject rights facilitated through our user rights management processes
- Data processing agreements in place with all sub-processors
- Records of processing activities maintained and updated
7.2 CCPA Compliance
We comply with the California Consumer Privacy Act (CCPA) for all data processing activities involving California residents. Our CCPA compliance measures include:
- Disclosure of data collection and processing practices in our Privacy Policy
- Right to know, right to delete, and right to opt-out of sale facilitated for California residents
- Non-discrimination for exercising CCPA rights
- Service provider agreements in place where required
7.3 SOC 2 Compliance
RPTech Software Marketplace maintains SOC 2 Type II compliance for our infrastructure and operations. Our SOC 2 audit covers:
- Security: Logical and physical access controls, system operations, and change management
- Availability: System uptime, disaster recovery, and incident management
- Processing Integrity: System processing completeness, accuracy, and timeliness
- Confidentiality: Encryption, access controls, and data protection measures
- Privacy: Collection, use, retention, and disclosure of personal information
8. Data Processing Agreement
RPTech Software Marketplace provides a Data Processing Agreement (DPA) for customers who require one. The DPA covers:
- Subject matter and duration of processing
- Nature and purpose of processing
- Types of personal data processed
- Categories of data subjects
- Processor obligations and instructions
- Confidentiality of processing personnel
- Security measures for processing
- Sub-processor management
- Data subject rights assistance
- Data breach notification obligations
- Data return and deletion upon termination
- Audit and inspection rights
To request a copy of our standard DPA, please contact us at info@rptech.com.
9. Breach Notification
In the event of a personal data breach, RPTech Software Marketplace will:
- Internal Detection: Our security monitoring systems are designed to detect potential breaches in real-time. We maintain 24/7 security operations center (SOC) monitoring.
- Assessment: Upon detection of a potential breach, our security team will immediately assess the severity and scope of the breach.
- Customer Notification: Affected customers will be notified without undue delay and no later than 72 hours after becoming aware of a breach that is likely to result in a risk to their rights and freedoms.
- Regulatory Notification: Where required by applicable law, we will notify the relevant supervisory authority of the breach within the legally mandated timeframe.
- Remediation: We will take immediate steps to contain the breach, mitigate its effects, and prevent recurrence.
- Documentation: All breaches, regardless of severity, are documented and reviewed to identify lessons learned and improve our security posture.
- Communication: Breach notifications will include the nature of the breach, the data affected, measures taken to address the breach, and recommendations for affected individuals.
10. Data Protection Officer
RPTech Software Marketplace has appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with applicable data protection laws. The DPO is responsible for:
- Monitoring compliance with data protection laws and our internal policies
- Advising on Data Protection Impact Assessments
- Serving as the point of contact for data subjects and supervisory authorities
- Training and awareness programs for data protection
- Managing data breach response and notification processes
- Reviewing and updating data protection policies and procedures
To contact our Data Protection Officer, please email info@rptech.com with "Data Protection Officer" in the subject line.
Questions about this policy?
Contact our legal team for any questions or concerns regarding this document.