DNZ Consulting LLC
Policies and compliance · NY registration 7798491
← All policies

Data Classification and Encryption Policy

DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027

This policy sorts information into levels. It states how to handle each level and how to encrypt it.

1. Scope and ownership

This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.

The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.

2. Classification levels

LevelWhat it coversHandling rule
RestrictedPersonal data, buyer contact data, access tokens, API keys, credentials, financial recordsEncrypt at rest and in transit. Access by named person only. Never send by plain email. Never place in source code.
ConfidentialMerchant business data, order data, pricing, source code, contractsEncrypt in transit. Store in a private repository or a private bucket. Share only with a business need.
InternalInternal notes, drafts, configuration that holds no secretKeep inside company systems. Do not publish.
PublicPublished policies, marketing pages, public documentationNo restriction.

3. Encryption in transit

4. Encryption at rest

5. Labelling

Store Restricted data in a location that only holds Restricted data. Name the location clearly. Do not mix levels in one folder.

6. Deleting data

7. Review

The Managing Member reviews this policy one time each year.