Security Policy
Policy Overview
This Security Policy describes the appropriate technical and organizational security measures
ETA Sync applies to protect systems and customer data, with a focus on controlled access,
data minimization, and secure operation within a managed cloud environment.
System Architecture and Security Controls
ETA Sync is hosted on a managed cloud infrastructure environment. Access to the system
is restricted to authorized users and controlled entry points. Infrastructure security
is managed by the hosting provider, while ETA Sync enforces application-level access
controls and data handling safeguards.
Data Protection and Retention Practices
ETA Sync applies data minimization and short-term retention by design,
in alignment with core GDPR principles, processing only the minimum information required
for active shipment tracking. Shipment data represents the current operational dataset
only; new uploads replace existing records, and historical shipment data is not retained.
Data is protected through encryption in transit and at rest, with automated backups
supporting recovery. ETA Sync explicitly excludes the collection and storage of financial
shipment data, payment information, consumer personal data, and government-issued
identifiers.
Authentication and Access Control
ETA Sync operates on a managed cloud platform that provides controlled entry points and
restricted access to production systems. Access to the application is limited to
authenticated users and enforced through application-level authentication and
authorization mechanisms.
Role-based access controls ensure that users can access only the data and functionality
permitted for their role. Development and administrative access is restricted to
authorized personnel only.
Network Security
ETA Sync operates within a managed cloud environment that provides network isolation and
controlled access to production systems. External access is restricted to defined entry
points, and network traffic is subject to platform-level security controls.
Direct administrative access to servers is not publicly exposed and is limited to
authorized personnel through managed access mechanisms provided by the hosting platform.
Incident Handling and Ongoing Security Practices
ETA Sync applies reasonable operational measures to identify, assess, and respond to
security incidents. System activity and logs are reviewed as part of normal operations
to support detection and investigation of issues.
Security-related fixes, updates, and dependency patches are applied as part of ongoing
maintenance to address identified risks and maintain system integrity. These practices
are designed to support the availability and security of the platform in line with its
operational scope.
Compliance and Security Alignment
ETA Sync is designed in alignment with commonly accepted data protection and information
security principles, including data minimization, controlled access, and limited
retention. The platform applies security practices consistent with its operational scope
and does not claim formal certification against specific regulatory or security standards.
Contact
For security-related inquiries, please contact
support@etasync.com.