Help
App openenPlan een gesprek

Sensitive PII

Handling of sensitive personal data.

Engelse versie wordt getoond

This policy defines how Cortena handles sensitive data and personally identifiable information (PII).

1. Purpose

To ensure sensitive data is handled securely and consistently across the company.

2. Scope

Applies to all Cortena team members, contractors, systems, and processes that potentially handle customer data.

3. Definitions

PII: information that can identify a person (for example name, email address).

Sensitive data: financial documents, invoice details, bank transaction references, credentials, and other confidential business data.

4. Policy requirements

4.1 Minimize

Only collect and process what is necessary to deliver the service.

4.2 Protect

  • Encrypt data in transit and at rest
  • Restrict access via RBAC and least privilege
  • Require secure internal access methods for privileged systems (for example VPN). See Access control and Security.

4.3 Avoid insecure handling

  • No sharing sensitive data in public channels
  • No copying customer data into unmanaged tools
  • No storing secrets in code, config, or logs

4.4 Approved sub-processors only

Sensitive data may be processed only by approved sub-processors governed by contract. See Sub-processors.

5. Exceptions

Exceptions require explicit approval by CTO or CEO and must be documented and added to the list of sub-processors.

6. Contact

compliance@cortena.ai · dpo@cortena.ai