GDPR Response

Confidentiality, Integrity and Availability

Following the principle of data protection by design, IIZUKA Case Manager includes comprehensive, industry standard confidentiality, integrity and availability features.

All application network traffic transmitted over untrusted networks is encrypted using TLSv1.2+ or IPSEC, configured to current industry recommendations for key and cipher strength.

All network traffic is restricted to those ports and protocols required for the correct operation of the system and monitored by an intrusion detection system for signs of malicious activity. All user traffic passes through a web application firewall / DDoS mitigation service.

Customer data is encrypted at rest using AES.

All data processing activities take place in ISO27001 certified facilities with robust physical and environmental security.

All application data is continuously replicated across multiple geographically separated hosting facilities to ensure continuity in the event of significant disruption to one facility. Our Recovery Time Objective is 4 hours and our Recovery Point Objective is 90 minutes. Our backup restoration process is automatically tested monthly to ensure we can meet this. Backups are retained for 30 days.

Within the application, a comprehensive configurable RBAC and record level data security model enforces the need-to-know principle between users.

Secure user authentication through SAML2 integration with your corporate directory (e.g. Entra ID) is supported for single-sign-on.

Lawful Basis For Processing

IIZUKA processes your personal data under contract. Only data directly entered by the customer, by IIZUKA support staff under the direction of the customer, or required to ensure the security of the platform (under the 'legitimate need' basis) will be stored.

All customer data is destroyed upon contract termination and is not shared with any third parties except for those sub-contractors directly responsible, under contract, for hosting the application.

Individual Rights

Case Manager provides a flexible case action and metadata system for client and case records that allows modelling of client consent and other data protection rights and restrictions in line with the organisation's internal standards.

A case and client delete function allows individuals to exercise their right to erasure, and the bulk deletion feature allows historical data to be removed in line with the customer's data retention policies.

Configurable reports allow client and case history to be extracted in a variety of formats to satisfy data portability and disclosure requirements. At the end of contract, the entire database can be provided in a standard machine-readable format for input into an alternative system.

Transfers Outside EU

Application data processing and storage is primarily located within the UK however some supporting functions may be remotely performed from outside of the EU. In these cases, written data processing agreements exist that meet the requirements of the GDPR with respect to transfers outside of the EU.

Data Processing Auditing

The application maintains a searchable, filterable audit trail of all data manipulation performed by users allowing all actions to be attributable.

Certifications

IIZUKA maintains independently audited certifications in several standards that demonstrate our commitment development and operation of a secure service. Our ISO 27001 and 9001 manuals describes our organisational policies, procedures and controls around data security including physical security, secure development practices and security vetting of employees. Both of these standards require us to implement a process for continual monitoring and improvement of our security and quality.

We also hold the Cyber Essentials Plus certification which shows that we have the controls in place to detect and prevent the most common cyber attacks against our infrastructure.

At least annually, a penetration test is performed against our application by a CREST certified organisation to detect vulnerabilities that may be present.

Previous
Previous

Environmental Policy

Next
Next

Cloud security principles