Security
1. Data Handling & Storage
  • Sensitive Data: Only in-house employees at ContentJet can access sensitive data, including scripts, video content, and client information.

  • Storage Platforms: All content is stored on internal-only Monday.com boards, which are accessible only to authorized internal users.

  • Content Protection: Content will be stored with clear access control policies in place to prevent unauthorized access. Use of other access restrictions may be implemented for added security.

2. Access Control
  • Employee Access: Access to client data and content is restricted to in-house employees at ContentJet who need it for their work. Role-based access control (RBAC) will be implemented to ensure that employees only access the data required for their specific role.

  • External Collaborators: External creators and collaborators must sign confidentiality and data protection agreements to ensure they understand the importance of securing any content they handle.

  • Tools & Platforms: Monday.com will be the primary platform for managing content and tasks, with restricted access based on roles. Any third-party tools used for collaboration or storage will also be reviewed for security compliance.

3. GDPR Compliance
  • Data Privacy: As ContentJet follows GDPR regulations, all personal data (such as client or creator information) will be handled with care, and proper consent will be obtained before storing or processing any personal data.

  • Data Retention: Personal data will only be retained for as long as necessary to fulfill its purpose, after which it will be securely deleted or anonymized in compliance with GDPR.

  • Third-Party Data Transfers: If any personal data is shared with third-party services (e.g., external storage platforms), contracts ensuring compliance with GDPR will be in place.

4. Incident Response and Data Breach
  • Incident Response Plan: In the event of a data breach or unauthorized access, ContentJet will have a response plan in place, including notifying relevant authorities and affected individuals as per GDPR requirements.

  • Backups: Regular backups of critical content and data will be performed to ensure quick recovery in case of any data loss or breach.

5. Security Awareness and Training
  • Employee Training: All in-house employees at ContentJet will undergo regular training on data protection practices, secure handling of client information, and adherence to GDPR rules.

  • External Collaborator Onboarding: External collaborators will be trained on security best practices, including how to protect client content, how to securely share files, and the importance of confidentiality.