1. Purpose
This Security Policy outlines the technical, organizational, and governance measures adopted by ZedWed ("Platform," "App," "we," "our," or "us") to support the protection of personal data, platform systems, and related business operations.
The purpose of this Policy is to describe the security measures, responsibilities, and control areas used to help protect the confidentiality, integrity, and availability of personal data and platform services, subject to applicable law, technical limitations, and operational realities.
This Policy should be read together with our Privacy Policy, Data Retention and Deletion Policy, Terms of Service, Cookie Policy, and other applicable platform policies.
2. Scope
This Policy applies to:
- personal data processed through the Platform, including higher-risk or sensitive categories of data such as government identification data, verification-related data, liveness-related information, messages, payment-related records, and sensitive profile attributes;
- employees, contractors, service providers, and other authorized persons who may access personal data or Platform systems; and
- systems, databases, cloud services, applications, storage layers, networks, and operational processes used to collect, store, transmit, secure, or dispose of Platform data.
3. Security Governance and Compliance
We aim to maintain security measures that are appropriate to the nature of the Platform, the categories of data processed, the risks involved, and applicable legal obligations.
This may include:
- maintaining internal security, confidentiality, and access-control requirements;
- implementing data protection and information-security procedures appropriate to our operations;
- maintaining contractual and operational controls with relevant service providers where appropriate;
- reviewing legal and regulatory obligations relevant to data security, privacy, breach response, and cross-border processing; and
- updating security practices as the Platform, threat environment, and legal requirements evolve.
Where registration, notification, governance, reporting, or other compliance steps are required by applicable law, we will address such obligations in accordance with that law.
4. Organizational Security Measures
We may implement organizational controls such as:
- confidentiality obligations for employees, contractors, and service providers with relevant access;
- role-based and least-privilege access practices;
- onboarding and offboarding controls for system access;
- periodic training or awareness measures on security, fraud prevention, privacy, and cyber hygiene;
- internal escalation processes for security concerns, misuse, incidents, and suspicious activity; and
- disciplinary or contractual consequences for unauthorized access, misuse, or non-compliance.
5. Technical and Operational Security Measures
We may use a combination of technical and operational safeguards designed to reduce security risk and support platform integrity.
a) Encryption and Secure Transmission
We use security measures intended to help protect data in transit, including transport-layer protections where appropriate. We may also use secure storage controls, encryption, signed access mechanisms, or similar protections for certain data at rest or for sensitive storage and retrieval operations, where appropriate to the service and technical environment.
We do not state in this Policy that every category of data in every system is encrypted in exactly the same way at all times.
b) Access Control and Authentication
We use access-management practices intended to limit access to authorized persons and systems only. These may include role-based access controls, credential protections, restricted administrative access, authentication checks, session controls, verification workflows, and auditability measures.
Administrative or privileged access may be subject to enhanced controls, including additional authentication, review, logging, or approval measures where appropriate.
c) Application Security Controls
The Platform may use application-level security controls such as secure session handling, CSRF protections, rate limiting, authentication safeguards, verification gating, content sanitization, size controls, and abuse-prevention mechanisms.
Certain stored content, such as user messages or verification-related information, may also be subject to additional protection measures appropriate to their use and sensitivity.
d) Infrastructure, Network, and Environment Controls
We may use layered infrastructure and network protections, cloud-service safeguards, environment separation, monitoring controls, patching practices, vulnerability-management processes, and service hardening measures designed to reduce operational and security risk.
e) Logging, Monitoring, and Abuse Detection
We may maintain logs, security events, technical diagnostics, and monitoring signals to help detect suspicious activity, unauthorized access, fraud, abuse, platform misuse, system failures, or policy violations.
Such monitoring may support incident investigation, account protection, service improvement, evidence preservation, legal compliance, and enforcement of platform policies.
6. Protection of Higher-Risk and Sensitive Data
Because the Platform may process higher-risk or sensitive information, including identity documents, liveness-related data, messages, payment-related records, and sensitive profile attributes, we may apply heightened handling controls where appropriate.
These may include restricted access, secure storage practices, workflow separation, verification controls, logging, reviewer limitations, or other protections proportionate to the sensitivity and legal risk of the data involved.
7. Third-Party and Vendor Security Management
The Platform may rely on third-party cloud, infrastructure, storage, communications, analytics, AI, verification, payment, messaging, and other service providers.
To help manage related risk, we may use measures such as:
- due diligence before onboarding relevant vendors;
- contractual protections, confidentiality obligations, or data-processing terms where appropriate;
- access restrictions and need-based access design;
- review of provider roles in handling personal or sensitive data; and
- periodic reassessment where operationally or legally appropriate.
Use of third-party providers does not eliminate all risk, and their services remain subject to technical, contractual, operational, and legal realities.
8. Data Retention, Disposal, and Storage Controls
We retain and dispose of data in accordance with operational, legal, security, and business requirements. Retention periods may differ depending on the type of data, legal obligations, fraud-prevention needs, backup practices, dispute handling, and safety requirements.
For detailed retention and deletion rules, please refer to our Data Retention and Deletion Policy.
When data is no longer required, we may delete, anonymize, de-identify, or otherwise retire it from active use, subject to legal obligations, technical limitations, and backup or archival processes.
9. User Security Support and Related Rights
Users may contact us with security-related concerns, account compromise reports, privacy requests, or suspected misuse.
Where applicable, users may also exercise rights described in our Privacy Policy, subject to verification, legal limitations, fraud-prevention requirements, and safety considerations.
For questions or reports relating to security or data protection, contact **help@zedwed.ai**.
10. Incident Response and Breach Handling
We may maintain incident-response procedures designed to support the identification, containment, investigation, remediation, documentation, and follow-up of suspected security incidents, misuse events, or data breaches.
Depending on the circumstances, our response may include:
- access restriction or account protection measures;
- technical containment and investigation;
- evidence preservation and internal escalation;
- coordination with relevant vendors or service providers;
- remedial or corrective action; and
- notification to affected users, regulators, law enforcement, or other parties where required or appropriate under applicable law.
We do not guarantee that every incident can be prevented, detected immediately, or resolved without impact.
11. Business Continuity and Resilience
We may use backups, recovery procedures, service-recovery planning, and operational resilience measures intended to support continuity of critical functions and restoration following outages, incidents, or technical failures.
Such measures are designed to reduce disruption, but do not guarantee uninterrupted availability, zero data loss, or recovery within any specific timeframe unless expressly stated elsewhere in binding service terms.
12. Monitoring, Review, and Policy Updates
We may review and update this Policy periodically to reflect changes in technology, law, business operations, threat conditions, vendor arrangements, or platform architecture.
We may also conduct internal reviews, security assessments, audit-related checks, training updates, or control improvements where appropriate.
13. Enforcement
This Policy is binding on relevant employees, contractors, and service providers to the extent applicable to their roles and responsibilities.
Unauthorized access, misuse of systems or data, failure to follow applicable security procedures, or breach of confidentiality or security obligations may result in disciplinary action, contractual enforcement, suspension of access, legal escalation, or other appropriate measures.
14. Contact Us
If you have questions about this Security Policy or wish to report a security-related concern, please contact **help@zedwed.ai**.