1.
Data Handling & Storage
Only in-house employees at ContentJet can access sensitive data, including scripts, video content, and client information. All content is stored on internal-only Monday.com boards, which are accessible only to authorized internal users. Content will be stored with clear access control policies in place to prevent unauthorized access.
2.
Access Control
Access to client data and content is restricted to in-house employees who need it for their work. Role-based access control (RBAC) will be implemented to ensure employees only access data required for their specific role.
External creators and collaborators must sign confidentiality and data protection agreements. Monday.com will be the primary platform for managing content and tasks, with restricted access based on roles.
3.
GDPR Compliance
As ContentJet follows GDPR regulations, all personal data will be handled with care, and proper consent will be obtained before storing or processing any personal data.
Personal data will only be retained for as long as necessary to fulfill its purpose, after which it will be securely deleted or anonymized. If any personal data is shared with third-party services, contracts ensuring compliance with GDPR will be in place.
4.
Incident Response and Data Breach
In the event of a data breach or unauthorized access, ContentJet will have a response plan in place, including notifying relevant authorities and affected individuals as per GDPR requirements. Regular backups of critical content and data will be performed to ensure quick recovery.
5.
Security Awareness and Training
All in-house employees will undergo regular training on data protection practices, secure handling of client information, and adherence to GDPR rules.
External collaborators will be trained on security best practices, including how to protect client content and the importance of confidentiality.