Company Policies

The principles that guide every team at Kriko. From how we hire and protect data to how we uphold quality and sustainability.

Data Security and Protection Policy

Data Classification

a. Sensitive Data

The Company identifies and classifies sensitive data.

Appropriate security measures are implemented to protect sensitive data against unauthorised access, disclosure, alteration or loss.

b. Personal Data

The Company processes and protects personal data in accordance with applicable data protection and privacy laws.

All required consents, authorisations and legal grounds are obtained for the collection, use, processing and sharing of personal data.

c. Commercial and Internal Business Data

The Company protects the confidentiality, integrity and availability of commercial and internal business data.

Appropriate measures are implemented to safeguard trade secrets, business strategies and other critical Company information.

Data Security and Access Controls

a. Data Encryption

The Company uses appropriate encryption methods to protect sensitive data.

Encryption technologies are applied to data both in transit and at rest.

b. Authorisation and Access Controls

Access to data is restricted through authorisation controls and role-based access policies.

Users are granted access only to the data required to perform their duties.

c. Monitoring and Logging

The Company monitors its systems and regularly reviews system logs.

Logs are maintained to detect suspicious or unauthorised activities and to support investigations where necessary.

Data Backup and Recovery

a. Data Backup

The Company performs regular backups of its data.

Backup procedures and schedules are designed to support the prompt recovery of data in the event of data loss.

b. Disaster Recovery

The Company develops disaster recovery plans to prepare for emergencies and major disruptions.

Data centre backups, business continuity plans and disaster recovery tests are implemented to support operational resilience.

Data Breaches and Incident Management

a. Data Breach Notification

When a data breach is identified, the Company acts promptly and effectively to notify the relevant parties where required.

Appropriate containment, corrective and preventive measures are implemented following a breach.

b. Incident Management

The Company maintains an effective incident management process for responding to security incidents and data breaches.

Incidents are investigated, corrective actions are taken, and improvement measures are implemented to prevent recurrence.

Data Disposal and Retention Periods

a. Data Disposal Policy

The Company complies with its established data retention periods and disposal procedures.

Data that is no longer required for legal, regulatory, contractual or business purposes is securely deleted or destroyed on a regular basis.

b. Data Retention Periods

The Company ensures that data is retained in accordance with applicable legal and regulatory requirements.

Data retention periods and related requirements are defined, documented and monitored.

Track the digital heartbeat with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.