DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027
This policy states how DNZ Consulting LLC protects information. It covers company data, merchant data, and personal data.
1. Scope and ownership
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
2. Objectives
Keep information confidential. Only authorized people see it.
Keep information correct. Nobody changes it without authority.
Keep information available. Authorized people can reach it when they need it.
Meet our legal and contractual duties.
3. Supporting policies
These documents form the security program together with this policy:
Encrypt all data in transit. Use TLS 1.2 or higher.
Encrypt all data at rest on every device and in every database.
Give each account the least privilege that the work needs.
Protect every account with multi-factor authentication where the service offers it.
Store every secret, key, and token in an encrypted keystore. Never store a secret in source code.
Keep source code in private repositories unless the code is meant to be public.
Patch operating systems and dependencies. See the vulnerability procedure.
Log administrative actions and keep the logs.
5. Suppliers
We assess a supplier before we send them any personal data. We check their security
statement and their privacy terms. We sign a data processing agreement when the
supplier processes personal data for us.
6. People
Every person who works for the company reads this policy before they get access.
They read it again each year. Access ends on the same day that the work ends.
7. Breaking this policy
A breach of this policy ends the person's access. It can also end the contract.
8. Review
The Managing Member reviews this policy one time each year, and after any incident.