Data Loss Prevention Strategy

Last updated: March 23, 2026 — Effective Date: March 23, 2026

1. Purpose

This Data Loss Prevention (DLP) Strategy establishes the policies, procedures, and technical controls that Gemhubx ("we," "us," "our") employs to prevent unauthorized access, use, disclosure, modification, or destruction of data across all systems and services. The objective of this strategy is to safeguard the confidentiality, integrity, and availability of all data entrusted to us by our merchants, their customers, and our business partners.

This strategy applies to all forms of data—whether stored electronically, transmitted across networks, or maintained in physical form—and governs the behavior of all personnel, contractors, and automated systems that interact with Gemhubx data assets.

2. Scope

This DLP Strategy applies to:

3. Data Classification

All data processed by Gemhubx is classified into one of the following four levels. Each level dictates the minimum security controls required for handling, storage, transmission, and disposal.

Classification Description Examples Handling Requirements
Critical Data whose compromise would cause severe operational or legal impact Shopify API keys, OAuth access tokens, database credentials, encryption keys, SSH private keys, environment secrets AES-256 encryption at rest; TLS 1.2+ in transit; access restricted to essential systems only; never logged in plaintext; rotated regularly
Confidential Personally identifiable information and sensitive business data Customer PII (names, emails, phone numbers, addresses), order data, payment information, merchant account details, store configuration Encrypted at rest and in transit; access limited to authorized personnel; subject to GDPR/CCPA rights; retention limits enforced; audit-logged
Internal Business operational data not intended for public disclosure Product catalogs, supplier pricing, wholesale costs, business analytics, internal communications, system architecture documentation Protected by access controls; shared only on need-to-know basis; not exposed to public-facing interfaces; standard backup procedures
Public Data intended for or already available to the general public Marketing materials, published legal policies, public-facing website content, app store listing, support documentation No special handling required; integrity controls to prevent unauthorized modification; version-controlled where applicable

4. Encryption Standards

4.1 Data in Transit

4.2 Data at Rest

4.3 Key Management

5. Access Control

5.1 Role-Based Access Control (RBAC)

Access to Gemhubx systems and data is governed by role-based access control. Each role is granted the minimum permissions necessary to perform its function:

5.2 Principle of Least Privilege

All access grants follow the principle of least privilege. Users and systems are given only the minimum access rights required to perform their authorized tasks. Elevated permissions are granted on a temporary, time-limited basis and are revoked when no longer needed.

5.3 Authentication Requirements

5.4 Session Management

6. Network Security

7. Endpoint Protection

8. Data Backup and Recovery

8.1 Backup Schedule

8.2 Backup Security

8.3 Retention and Testing

8.4 Recovery Objectives

9. Monitoring and Detection

10. Data Retention and Disposal

Data is retained only for as long as necessary to fulfill its purpose or as required by law. The following table outlines our retention schedule:

Data Type Retention Period Disposal Method
Active merchant accounts While account is active and app is installed N/A (active use)
Post-uninstall merchant data 30 days after uninstallation Permanent deletion from database and file storage
GDPR redaction requests Processed within 48 hours of receipt Targeted deletion or anonymization of specified PII
Order and transaction records 7 years (tax and legal compliance) Anonymized after retention period; originals securely deleted
Encrypted backups 90 days Secure deletion from backup storage (cryptographic erasure)
User sessions 24 hours of inactivity Automatic purge from session store
Application logs 90 days Automatic rotation and secure deletion
Server access logs 90 days Automatic rotation and secure deletion
Cloudflare analytics data As per Cloudflare's retention policy Managed by Cloudflare
Support correspondence 3 years after last interaction Secure deletion from email and ticketing systems

When data reaches the end of its retention period, it is permanently deleted or irreversibly anonymized. Deletion is verified and logged. Encrypted data may be disposed of through cryptographic erasure (destruction of the encryption key).

11. Incident Response

Gemhubx maintains a Security Incident Response Policy to address data loss events, security breaches, and other incidents. The full policy is available in our Security Policy.

Our incident response framework follows four phases:

  1. Detection and Identification: Automated monitoring systems and manual review processes identify potential security incidents. All personnel are trained to recognize and report suspected incidents immediately.
  2. Containment: Upon confirmation of an incident, immediate steps are taken to contain the threat and prevent further data loss. This may include isolating affected systems, revoking compromised credentials, and blocking malicious IP addresses.
  3. Eradication and Recovery: The root cause is identified and eliminated. Affected systems are restored from verified clean backups. All compromised credentials are rotated. Systems are verified clean before being returned to service.
  4. Post-Incident Review: A thorough post-mortem analysis is conducted within 72 hours of incident resolution. Findings are documented, lessons learned are incorporated into policies and procedures, and preventive measures are implemented to reduce the likelihood of recurrence.

In the event of a data breach affecting personal data, we will notify affected individuals and relevant supervisory authorities within the timeframes required by applicable law (72 hours under GDPR).

12. Employee and Personnel Security

13. Third-Party Risk Management

Our current sub-processors include:

14. Compliance

Gemhubx maintains compliance with the following regulations and industry standards:

15. Policy Review

16. Contact

For questions, concerns, or reports related to data loss prevention, data security, or this strategy, please contact:

Gemhubx Security Team
Email: [email protected]
Website: https://gemhubapp.com

To report a security vulnerability or suspected data breach, please email [email protected] immediately. Include as much detail as possible to aid in investigation.