Elevis

Data Protection and Security Policy

Owner: ELEVIS LTD · Effective 11 August 2026

Report suspected vulnerabilities privately to security@elevis.co.uk. Do not include passwords, health records or exploit another person’s account.

Principles

Elevis uses data minimisation, purpose limitation, least privilege, defence in depth and secure defaults. Web and desktop clients are treated as untrusted; the API enforces authentication, ownership, permissions, validation, rate limits and audit controls.

Protective controls

People and suppliers

Access is limited to trained people with an operational need and reviewed when duties change. Suppliers are assessed for purpose, security, data location and contract terms. Production secrets belong in protected configuration and are rotated through controlled procedures when exposure is suspected.

Incidents

Security events are triaged, contained, investigated and recorded. Elevis assesses impact on confidentiality, integrity, availability and people’s rights. Reportable personal-data breaches are notified to the ICO within the applicable deadline where required, and affected people are informed without undue delay where high risk requires it. Evidence is preserved and corrective actions tracked.

Assurance

Security is reviewed during design, code review, deployment and periodic risk assessment. Automated scans supplement rather than replace manual review. Exceptions require an owner, reason, compensating control and expiry date.