Security Policy
Last Updated: January 2, 2025
Luz Seranoya is committed to protecting the security of its platform, systems, and the data entrusted to us by our users. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and how we respond to security incidents.
1. Scope
This policy applies to all systems, services, and infrastructure operated by Luz Seranoya, including our web platform accessible at luzseranoya.com, associated applications, databases, and communication channels. It applies to all users, staff, contractors, and third parties who interact with our services.
2. Our Security Commitments
We maintain ongoing security practices designed to protect the confidentiality, integrity, and availability of data and services. Our commitments include:
- Implementing and maintaining technical safeguards appropriate to the nature of data we process
- Regularly reviewing and updating our security controls
- Training personnel on security awareness and best practices
- Monitoring systems for anomalous activity and potential threats
- Applying security patches and updates in a timely manner
3. Data Protection Measures
3.1 Encryption
All data transmitted between users and our platform is encrypted using industry-standard Transport Layer Security (TLS) protocols. Sensitive data stored within our systems is encrypted at rest using recognized encryption standards. Encryption keys are managed through secure, access-controlled processes.
3.2 Access Controls
Access to systems and data is restricted on a need-to-know basis. We enforce the principle of least privilege, ensuring that personnel and automated processes are granted only the minimum level of access required to perform their functions. Access rights are reviewed periodically and revoked promptly when no longer required.
3.3 Authentication
Our platform requires authenticated access for all user accounts. We support and encourage the use of strong, unique passwords. Where available, multi-factor authentication is offered as an additional layer of protection. Credentials are stored using secure, one-way hashing algorithms.
3.4 Network Security
Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation practices. We conduct regular vulnerability assessments and penetration testing to identify and remediate weaknesses before they can be exploited.
4. Physical Security
Our services are hosted on infrastructure provided by reputable cloud and data center providers that maintain rigorous physical security controls, including restricted facility access, surveillance systems, and environmental safeguards. Physical access to production environments is limited to authorized personnel only.
5. Software Development Practices
Security is integrated throughout our software development lifecycle. Our practices include:
- Code reviews that include security considerations
- Dependency management and monitoring for known vulnerabilities in third-party libraries
- Separation of development, staging, and production environments
- Use of automated security scanning tools as part of our build and deployment pipelines
- Regular review of application logic for common vulnerability classes
6. Third-Party Services and Integrations
Where we engage third-party service providers who process or have access to data on our behalf, we assess their security posture before engagement and require them to maintain appropriate security standards. We limit the data shared with third parties to what is strictly necessary for the purpose of the integration.
7. Incident Response
7.1 Detection and Response
We maintain procedures for detecting, assessing, and responding to security incidents. Upon identification of a potential security event, our team initiates a structured response process that includes containment, investigation, remediation, and post-incident review.
7.2 User Notification
In the event of a security incident that affects user data or access, we will notify affected users in a timely manner through appropriate communication channels. Notifications will include a description of the incident, the data or services affected, steps we have taken, and recommended actions for users.
7.3 Documentation
All security incidents are documented internally, including the timeline of events, response actions taken, and lessons learned. This documentation informs ongoing improvements to our security practices.
8. User Responsibilities
The security of your account is a shared responsibility. As a user of our platform, you are expected to:
- Use strong, unique passwords for your account and keep them confidential
- Enable multi-factor authentication where it is available
- Log out of your account when using shared or public devices
- Promptly notify us if you suspect unauthorized access to your account
- Refrain from sharing your account credentials with others
- Avoid actions that may compromise the security or stability of the platform
9. Prohibited Activities
Users must not engage in any activity that threatens the security or integrity of our platform or the data of other users. Prohibited activities include but are not limited to:
- Attempting to gain unauthorized access to systems, accounts, or data
- Conducting or facilitating denial-of-service attacks
- Introducing malware, viruses, or other malicious code
- Intercepting or monitoring communications without authorization
- Circumventing authentication or security controls
- Probing, scanning, or testing the vulnerability of our systems without prior written authorization
We reserve the right to suspend or terminate access for any user found to be engaging in prohibited activities and to report such activities to appropriate authorities where warranted.
10. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities discovered in our platform. If you believe you have identified a security issue, please report it to us promptly at help@luzseranoya.com. We ask that you:
- Provide sufficient detail to allow us to reproduce and investigate the issue
- Avoid accessing, modifying, or disclosing data beyond what is necessary to demonstrate the vulnerability
- Refrain from publicly disclosing the vulnerability until we have had a reasonable opportunity to address it
We are committed to acknowledging valid reports and working to resolve confirmed vulnerabilities in a timely manner. We will not pursue legal action against individuals who report vulnerabilities in good faith in accordance with these guidelines.
11. Data Retention and Deletion
We retain data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable obligations. When data is no longer required, it is securely deleted or anonymized in a manner that prevents reconstruction. Users may request deletion of their account data by contacting us at help@luzseranoya.com.
12. Availability and Business Continuity
We maintain backup and recovery procedures designed to minimize data loss and restore service availability in the event of system failure, data corruption, or other disruptions. Backups are performed regularly, stored securely, and tested periodically to verify their integrity and recoverability.
13. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this page and, where appropriate, notify users through the platform or by email. We encourage you to review this policy periodically to stay informed about how we protect your information.
14. Contact Us
If you have questions, concerns, or requests related to this Security Policy or our security practices, please contact us:
Luz Seranoya
Soborna St, 8, Mykolaiv, Mykolaiv Oblast, Ukraine, 54000
Phone: +380577427296
Email: help@luzseranoya.com
Website: luzseranoya.com