Information Security Policy

This policy aims to protect WECONNECT’s information from internal and external threats, ensuring the confidentiality, integrity, and availability of data for both clients and business operations.

The policy applies to all employees, partners, and external suppliers who have access to WECONNECT’s information systems, data, and infrastructure.

Through its management, WECONNECT is committed to adhering to the following fundamental principles of information security:

  • Confidentiality: Client and company data is accessible only to authorized individuals.
  • Integrity: Information remains accurate and complete, preventing unauthorized modifications.
  • Availability: Information and systems are accessible when needed.

The company adopts a continuous risk management process, including regular identification and assessment of threats related to information security.

Employee Responsibilities:

  • Comply with the prescribed security procedures.
  • Promptly report any security incidents or suspicious activities.
  • Participate in training programs related to information security.

This policy fully complies with the ISO 27001:2022 standard, the General Data Protection Regulation (GDPR), and other applicable data security laws.

The policy will be reviewed annually or whenever significant business changes occur to ensure the continuous improvement of the Information Security Management System (ISMS), as committed by the company’s management.

The company provides ongoing training to employees, keeping them informed about security procedures and current threats in the field of information security.

This policy has been approved by WECONNECT’s management and is communicated to all employees and partners for immediate implementation and compliance.

Amazon SP-API and Restricted Data Security Controls

For integrations using Amazon Selling Partner API (SP-API), WeConnect processes Amazon Information only for approved seller integration use cases, including ERP synchronization, merchant-fulfilled order processing, shipping, accounting, tax posting and reconciliation.

Access to Amazon Information, including personally identifiable information where applicable, is restricted to authorized personnel based on job role and business need. Individual user accounts are used for access to systems handling Amazon Information. Shared accounts are not permitted for administrative access. Access rights are reviewed periodically and removed when no longer required.

Amazon Information is protected using encryption in transit. Where Amazon Information is stored in WeConnect systems, it is protected using encryption at rest where applicable and access-controlled storage. Backups containing Amazon Information are encrypted and access-controlled.

API credentials, refresh tokens, access tokens, passwords and other secrets are stored securely and are not hard-coded in application source code or committed to source code repositories. Access to secrets is restricted to authorized personnel only.

Production systems handling Amazon Information are protected by firewalls, restricted network access rules, secure authentication and monitoring. Public access to production databases and internal services is not allowed. Only required application endpoints are exposed.

We maintain logging and monitoring for systems handling Amazon Information, including authentication, administrative access, application errors and relevant security events. Logs are reviewed during security investigations and monitored for suspicious activity.

Amazon personally identifiable information is not used for routine development or testing. Test environments use test, fabricated, masked or anonymized data wherever possible. If production data is required for troubleshooting, access is limited, approved and logged based on business need.

We follow a change management process for systems handling Amazon Information. Changes are documented, reviewed, tested and approved before production deployment. Application code and dependencies are reviewed before release, and identified security issues are prioritized and remediated based on severity.

We maintain an incident response process for security incidents involving Amazon Information. The process includes identification, containment, investigation, remediation, escalation and notification procedures.

Marianna Diamantopoulou

Manager and Legal Representative

02.09.2024