Live seminars on website layout principles — study from home, apply immediately

Security Policy

Last updated: 18 April 2025

Prizekindle is committed to maintaining the security and integrity of all information processed through our platform. This Security Policy describes the measures we take to protect our systems, data, and users. By using our services, you acknowledge and agree to the practices described in this document.


1. Scope

This policy applies to all systems, infrastructure, services, and data managed or operated by Prizekindle, including our website at prizekindle.pro, our seminar platform, and any associated tools or services made available to registered users and visitors.


2. Data Protection Principles

We apply the following core principles when handling personal and operational data:

Minimisation: We collect only the data that is strictly necessary for the delivery of our services.

Purpose limitation: Data is used solely for the purposes for which it was collected and is not repurposed without appropriate notice or consent.

Integrity: We take steps to ensure that data held within our systems remains accurate, consistent, and protected against unauthorised alteration.

Accountability: We maintain internal records of data processing activities and assign responsibility for security compliance across our organisation.


3. Infrastructure Security

3.1 Hosting and Network

Our platform is hosted on infrastructure that employs physical and logical access controls, redundant network configurations, and continuous availability monitoring. Hosting environments are selected based on their demonstrated security standards and operational reliability.

3.2 Encryption in Transit

All communication between users and our platform is encrypted using industry-standard Transport Layer Security (TLS). Unencrypted connections are not accepted. We regularly review and update our TLS configuration to align with current best practices.

3.3 Encryption at Rest

Sensitive data stored within our systems is encrypted at rest using recognised encryption standards. Encryption keys are managed through access-controlled key management processes and are rotated on a defined schedule.

3.4 Firewalls and Access Controls

Network-level firewalls and application-layer controls are used to restrict access to our systems. Administrative access to infrastructure is limited to authorised personnel and requires multi-factor authentication.


4. Application Security

4.1 Secure Development Practices

Our development process incorporates security considerations at each stage, including design review, code review, and testing prior to deployment. We follow established guidelines for secure software development and apply patches and updates in a timely manner.

4.2 Vulnerability Management

We conduct periodic assessments of our platform to identify and address potential security vulnerabilities. Critical vulnerabilities are prioritised and remediated promptly. We also maintain a process for receiving and evaluating externally reported security concerns.

4.3 Dependency Management

Third-party libraries and components used within our platform are reviewed for known vulnerabilities and updated regularly. Deprecated or unmaintained dependencies are replaced as part of our ongoing security maintenance.


5. Access Management

5.1 User Accounts

Each user account is protected by authentication credentials. We encourage users to select strong, unique passwords and to avoid sharing their credentials with others. Where available, multi-factor authentication is strongly recommended.

5.2 Internal Access

Access to systems and data by our staff is granted on a least-privilege basis. Employees and contractors are given access only to the systems and data required for their specific role. Access rights are reviewed periodically and revoked promptly when no longer required.

5.3 Third-Party Access

Where third-party service providers require access to our systems or data, such access is governed by contractual agreements that include appropriate security obligations. Third-party access is limited in scope and duration.


6. Monitoring and Logging

Our systems generate logs of security-relevant events, including authentication attempts, administrative actions, and system errors. These logs are retained for a defined period and reviewed as part of our ongoing security monitoring activities. Automated alerting is in place to flag anomalous or potentially harmful behaviour.


7. Incident Response

7.1 Detection and Containment

We maintain procedures for detecting, classifying, and containing security incidents. Upon identification of a potential incident, our team acts to limit the impact and prevent further exposure as quickly as possible.

7.2 Investigation and Recovery

Following containment, we conduct an investigation to determine the nature, scope, and root cause of the incident. Recovery steps are taken to restore normal operations and to implement measures that reduce the likelihood of recurrence.

7.3 Notification

In the event of a security incident that affects user data, we will notify affected users in a timely manner, providing information about what occurred and the steps being taken in response, in accordance with our obligations under applicable data protection requirements.


8. Physical Security

Our operational premises are protected by physical access controls. Access to areas where sensitive equipment or data may be present is restricted to authorised individuals. We also ensure that third-party data centre facilities used to host our platform maintain appropriate physical security standards.


9. Business Continuity and Backup

We maintain backup procedures to ensure that critical data can be recovered in the event of loss or corruption. Backups are stored securely and tested periodically to verify their integrity and reliability. We also maintain business continuity plans to support the restoration of services following a significant disruption.


10. Employee Awareness and Training

All staff members with access to our systems receive guidance on security responsibilities and expectations. We provide ongoing awareness training to help our team recognise and respond appropriately to security risks, including phishing attempts and social engineering techniques.


11. Reporting a Security Concern

If you believe you have identified a security vulnerability or have concerns about the security of our platform, we encourage you to contact us directly. Please do not publicly disclose potential vulnerabilities before giving us the opportunity to investigate and respond.

You can reach our team by email at contact@prizekindle.pro or by post at 81 Ponsford Rd, Bristol BS4 2UT, United Kingdom. We aim to acknowledge all security reports promptly and will keep you informed of our progress where appropriate.


12. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date shown at the top of this page. We encourage you to review this policy periodically to stay informed about how we protect the security of our platform and your information.


13. Contact

For any questions or concerns relating to this Security Policy, please contact us using the details below:

Prizekindle

81 Ponsford Rd, Bristol BS4 2UT, United Kingdom

Email: contact@prizekindle.pro

Phone: +44 1274 480831