Security Policy
These documents form part of KFN Media's legal framework and may be updated periodically.
Purpose
KFN Media is committed to protecting the confidentiality, integrity, and availability of information, systems, and services. This Security Policy outlines the measures we take to safeguard client data, business information, and digital infrastructure against unauthorized access, disclosure, alteration, and destruction.
Scope
This Security Policy applies to all services, websites, cloud infrastructure, software, applications, and systems operated or managed by KFN Media.
Security Principles
We implement appropriate technical and organisational measures designed to protect information throughout its lifecycle. Our security approach is based on the principles of confidentiality, integrity, availability, accountability, and continuous improvement.
Access Control
Access to systems and data is granted only to authorised personnel who require access to perform their duties. Access permissions are reviewed regularly and removed when no longer required. Strong authentication methods are used wherever practical.
Data Protection
Sensitive information is protected using appropriate security measures, including encryption where applicable, secure transmission protocols, restricted access, and secure storage practices.
Infrastructure Security
Our infrastructure is designed with security in mind and may include firewalls, network monitoring, secure cloud environments, vulnerability management, and regular software updates to reduce security risks.
Monitoring and Logging
We may monitor systems and maintain security logs to detect unauthorised access, investigate incidents, improve security, and comply with legal obligations.
Third-Party Providers
We work with carefully selected third-party providers for services such as cloud hosting, communications, analytics, and payment processing. While we choose reputable providers, their infrastructure and services remain subject to their own security practices and terms.
Employee and Contractor Responsibilities
Personnel with access to systems or client information are expected to maintain confidentiality, follow internal security procedures, and report suspected security incidents without delay.
Incident Response
If a security incident is identified, we will investigate the issue, take reasonable steps to contain and resolve the incident, restore affected services where possible, and comply with applicable legal notification requirements.
Business Continuity
We implement reasonable measures to support service continuity, including backups, recovery procedures, and operational planning where appropriate. However, uninterrupted availability cannot be guaranteed.
Client Responsibilities
Clients are responsible for maintaining the security of their own accounts, passwords, devices, and internal systems. Clients should promptly notify KFN Media of any suspected unauthorised access or security concerns relating to our services.
Security Limitations
Although KFN Media applies appropriate technical and organisational safeguards, no online service, software, network, or electronic storage system can be guaranteed to be completely secure. Users acknowledge that all internet-based services carry inherent security risks.
Compliance
Our security practices are designed to support compliance with applicable laws and regulations, including the General Data Protection Regulation (GDPR), where applicable. Security measures are reviewed and updated as our services and technology evolve.
Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our services, technology, legal obligations, or security practices. The latest version will always be available on our website.
Contact
For questions regarding this Security Policy or to report a security concern, please contact KFN Media through our contact page.