Security Policy

Policy Overview

This Security Policy describes the appropriate technical and organizational security measures ETA Sync applies to protect systems and customer data, with a focus on controlled access, data minimization, and secure operation within a managed cloud environment.

System Architecture and Security Controls

ETA Sync is hosted on a managed cloud infrastructure environment. Access to the system is restricted to authorized users and controlled entry points. Infrastructure security is managed by the hosting provider, while ETA Sync enforces application-level access controls and data handling safeguards.

Data Protection and Retention Practices

ETA Sync applies data minimization and short-term retention by design, in alignment with core GDPR principles, processing only the minimum information required for active shipment tracking. Shipment data represents the current operational dataset only; new uploads replace existing records, and historical shipment data is not retained.

Data is protected through encryption in transit and at rest, with automated backups supporting recovery. ETA Sync explicitly excludes the collection and storage of financial shipment data, payment information, consumer personal data, and government-issued identifiers.

Authentication and Access Control

ETA Sync operates on a managed cloud platform that provides controlled entry points and restricted access to production systems. Access to the application is limited to authenticated users and enforced through application-level authentication and authorization mechanisms.

Role-based access controls ensure that users can access only the data and functionality permitted for their role. Development and administrative access is restricted to authorized personnel only.

Network Security

ETA Sync operates within a managed cloud environment that provides network isolation and controlled access to production systems. External access is restricted to defined entry points, and network traffic is subject to platform-level security controls.

Direct administrative access to servers is not publicly exposed and is limited to authorized personnel through managed access mechanisms provided by the hosting platform.

Incident Handling and Ongoing Security Practices

ETA Sync applies reasonable operational measures to identify, assess, and respond to security incidents. System activity and logs are reviewed as part of normal operations to support detection and investigation of issues.

Security-related fixes, updates, and dependency patches are applied as part of ongoing maintenance to address identified risks and maintain system integrity. These practices are designed to support the availability and security of the platform in line with its operational scope.

Compliance and Security Alignment

ETA Sync is designed in alignment with commonly accepted data protection and information security principles, including data minimization, controlled access, and limited retention. The platform applies security practices consistent with its operational scope and does not claim formal certification against specific regulatory or security standards.

Contact

For security-related inquiries, please contact support@etasync.com.