Company Policies

The principles that guide every team at Kriko. From how we hire and protect data to how we uphold quality and sustainability.

Information Technology Use and Access Policy

General Principles

a. Authorisation and Access Controls

The Company implements appropriate controls to manage and authorise access to its information technology systems.

Each employee’s access rights are determined according to their role, responsibilities and business requirements.

b. User Authentication

The Company maintains a secure user authentication process.

Employees must access their accounts and verify their identities using strong passwords and other authentication methods required by the Company.

c. Data Backup and Recovery

The Company performs regular data backups and maintains appropriate recovery plans.

Necessary measures are implemented to restore data promptly in the event of data loss.

Internet Use

a. Acceptable Use

The Company promotes the use of internet access primarily for legitimate business purposes.

Employees are expected to use the internet in accordance with the Company’s acceptable use requirements.

b. Security and Threat Protection

The Company provides employees with training and guidance on internet security risks.

Up-to-date antivirus and security software is used to protect systems and devices against malware and other cyber threats.

Email Use

a. Acceptable Use

The Company ensures that business email accounts are used securely, responsibly and effectively.

Limited personal use of Company email may be permitted, provided that it remains appropriate and does not interfere with business activities or breach Company policies.

b. Data Security

The Company implements appropriate controls to ensure that sensitive information is shared securely by email.

Encryption and other security measures are applied where necessary to prevent data leakage and unauthorised disclosure.

Use of Devices and Hardware

a. User Responsibilities

Employees must use Company-provided devices and hardware appropriately, securely and solely for authorised purposes.

Each user is responsible for protecting the security, integrity and physical condition of the devices assigned to them.

b. Updates and Software Management

The Company ensures that devices are protected with up-to-date software and security patches.

Appropriate measures are implemented to ensure that only properly licensed and authorised software is used and to prevent unauthorised software downloads.

Employees must not download or install software without prior approval from Company management or without a valid licence. Any unauthorised or unlicensed software installation may result in disciplinary action and other applicable consequences.

Mobile Device Use

a. Acceptable Use

The Company promotes the appropriate use of mobile devices for legitimate business purposes.

Mobile device use is monitored and managed in accordance with the Company’s acceptable use and security requirements.

b. Data Security

The Company implements appropriate measures to protect data accessed, processed or stored on mobile devices.

These measures may include data encryption, remote wiping capabilities, access controls and other relevant security safeguards.

Track the digital heartbeat with Kriko

Subscribe to receive curated insights, news, and ideas shaping the digital landscape.