Aristotu
HomeLegalData & Security Policy

Data & Security Policy

Last updated: 2025-01-01
·By Platform Admin

DATA AND SECURITY POLICY

EFFECTIVE DATE: January 1, 2025

1. DATA GOVERNANCE FRAMEWORK

This policy governs how all data processed through the platform is collected, stored, transmitted, accessed, and deleted. It applies to all users, administrators, and third-party integrations.

2. DATA CLASSIFICATION

2.1 USER DATA: account credentials, profile information, preferences, and usage history

2.2 FINANCIAL DATA: transaction records, payment references, subscription details

2.3 CONTENT DATA: user-generated documents, manuals, and intellectual work product

2.4 SYSTEM DATA: logs, audit trails, performance metrics, and error records

2.5 ADMINISTRATIVE DATA: admin configurations, system settings, and role assignments

3. DATA COLLECTION

3.1 We collect only the minimum data necessary to provide our services (data minimization principle).

3.2 Data is collected through direct user input, automated system processes, and third-party integrations.

3.3 No unauthorized data collection occurs without user knowledge.

4. DATA STORAGE AND RETENTION

4.1 Data is stored on secure, encrypted infrastructure.

4.2 Financial transaction records are retained for a minimum of 7 years for audit purposes.

4.3 Account data is retained while the account is active and for up to 2 years following closure, unless required longer by law.

4.4 Content data is retained while the account is active. Deleted content is purged within 30 days.

5. DATA SECURITY CONTROLS

5.1 ENCRYPTION

  • Data in transit is encrypted using TLS 1.2 or higher
  • Sensitive data at rest is encrypted using AES-256 or equivalent

5.2 ACCESS CONTROLS

  • Role-based access control (RBAC) restricts data access to authorized personnel only
  • Administrative access requires multi-factor authentication
  • Access logs are maintained for all sensitive data access events

5.3 AUDIT LOGGING

  • All administrative actions, financial events, and permission changes are logged
  • Logs are tamper-resistant and reviewed periodically
  • Log data is retained for a minimum of 1 year

5.4 VULNERABILITY MANAGEMENT

  • Security assessments are conducted periodically
  • Critical vulnerabilities are patched within 72 hours of identification
  • Responsible disclosure of vulnerabilities is welcomed and rewarded

6. INCIDENT RESPONSE

6.1 Data breach incidents are investigated immediately upon detection.

6.2 Affected users will be notified as required by applicable law.

6.3 Regulatory authorities will be notified where required.

7. THIRD-PARTY DATA PROCESSORS

7.1 Third parties who process data on behalf of the Platform Owner are bound by data processing agreements.

7.2 Only processors who meet our security standards are engaged.

7.3 The Platform Owner remains responsible for compliance with this policy regardless of third-party involvement.

8. USER RIGHTS

Users may submit data access, correction, or deletion requests to the Platform Owner. Requests will be processed within 30 days, subject to legal obligations.