Terms and Policies

1. Purpose

This Security Policy describes the technical and organizational measures implemented by Workganizer to protect the confidentiality, integrity, and availability of data processed through the Workganizer platform.

This policy is intended to provide transparency to customers, partners, and enterprise stakeholders regarding our security posture.

2. Scope

This policy applies to:

  • Workganizer web application
  • Desktop applications
  • Mobile applications
  • Supporting infrastructure and services

It covers all systems used to store, process, or transmit customer and user data.

3. Security Principles

Workganizer’s security program is based on the following principles:

  • Least privilege access
  • Defense in depth
  • Data minimization
  • Security by design
  • Continuous monitoring and improvement
4. Data Protection Measures
4.1 Data Encryption
  • Data is encrypted in transit using HTTPS/TLS
  • Data is encrypted at rest using industry-standard encryption mechanisms
  • Encryption keys are managed securely and access is restricted.
4.2 Access Control
  • Role-based access control (RBAC) is enforced
  • Access is limited to authorized personnel only
  • Administrative access is restricted and logged
  • Access rights are reviewed periodically
4.3 Authentication & Account Security
  • Secure authentication mechanisms are used
  • Passwords are stored using strong hashing algorithms
  • Account access may be restricted or suspended in case of suspicious activity
5. Monitoring & Logging
  • System activity is logged for security and operational purposes
  • Logs are monitored for unauthorized access or anomalies
  • Logging data is protected against unauthorized modification
  • Logs are retained only for operational and security purposes.
6. Infrastructure & Hosting Security
  • Production systems are logically isolated from development and testing environments
  • Network protections are in place to prevent unauthorized access
  • Regular system updates and security patches are applied

Workganizer does not publicly disclose infrastructure architecture or provider details for security reasons.

7. Incident Response

Workganizer maintains an incident response process to address security events promptly.

In the event of a confirmed data breach:

  • The issue is investigated without delay
  • Appropriate containment and remediation actions are taken
  • Affected customers are notified in accordance with applicable legal requirements
8. Data Retention & Deletion
  • Data retention follows documented retention rules defined in the Privacy Policy
  • Data is deleted or anonymized once retention periods expire
  • Secure deletion methods are applied where applicable
9. Third-Party Security
  • Third-party services are assessed for security and reliability
  • Data shared with third parties is limited to what is necessary
  • Third parties process data under their own security and privacy obligations
10. Employee & Contractor Security
  • Access to systems is limited to personnel with a legitimate business need
  • Personnel are required to follow confidentiality obligations
  • Access is revoked promptly upon role change or termination
11. Vulnerability Management
  • Reasonable measures are taken to identify and address security vulnerabilities
  • Security updates are applied as appropriate
  • Responsible vulnerability disclosure is encouraged

Vulnerability Reporting

Security issues may be reported to: security@workganizer.com

12. Limitations

No system is completely secure. While Workganizer applies industry-standard security measures, absolute security cannot be guaranteed.

Customers remain responsible for:

  • Secure use of the Service
  • Account credentials
  • Lawful configuration of features
13. Changes to This Policy

This Security Policy may be updated to reflect improvements or changes to security practices. Material changes will be communicated through the Service or website.

14. Contact

For security-related questions or concerns: security@workganizer.com