Privacy Policy

How we collect and use information

Introduction

This Information Security Policy serves as the basis for the Information Security Management System (ISMS), respecting the international standard ISO/IEC 27001:2022, community standards and specific national legislation and recommendations in ​​information security.

LTPLabs assumes in this policy its commitment with:

  • ISO 27001 requirements and their integration of the ISMS requirements in the organization's processes;
  • Applicable regulations and laws related with information security;
  • Continual improvement of its ISMS. 

Audience

LTPLabs’ Information Security Policy is aimed at all LTPLabs’ interested parties.

All interested parties must know and act in accordance with LTPLabs’ Information Security Policy and with other documents related to Information Security, as applicable and appropriate.

Information Value

Information can take different forms (be it printed or written on paper, stored electronically, transmitted by mail or electronic means, among others), and must be adequately protected, regardless of its medium, use or support.

Access to information is an important aspect of LTPLabs’ functioning, depending on the availability of infrastructures and information systems and the efficiency of the service provided to its customers. Security in the treatment and transmission of information is thus a vital factor in maintaining its efficiency.

Any interruption of service, leakage of information to unauthorized entities or unauthorized modification of data, can lead to a loss of confidence and/or violate obligations to interested parties.

Information security is a fundamental prerequisite for the success of the services provided by LTPlabs and it is the responsibility of all employees, suppliers or other entities, to proactively contribute to the protection or sharing of sensitive information by any means, including verbally.

Importance of Information Security

Information security should be applied at all stages of the ISMS and the control of the insertion, collection, processing, storage, transfer, relationship, research, and destruction of information operations are an integral part of the LTPlabs information system.

The threats to information security are constantly evolving, which implies the continuous adaptation of security measures to keep up with technological, legislative and / or social changes.

Information Security Model

The LTPlabs information security model is committed to:

  • Confidentiality: guarantee that the information is accessible only by people duly authorized for the purpose;
  • Integrity: safeguarding the accuracy of information and processing methods;
  • Availability: guarantee that authorized users have access to information whenever necessary.

Objectives of Information Security

The objectives of LTPLabs with the implementation of ISO 27001 are:

  • Ensure the confidentiality, integrity and availability of information, services and infrastructures;
  • Obtain and maintain an ISO/IEC 27001 certification;
  • Ensure that processes and policies comply with the requirements of relevant stakeholder laws or regulations;
  • Raise awareness and make the concern with information security in LTPLabs’s team a day-to-day practice;
  • Keep the number of incidents low.

Responsibility in Information Security

Top management is committed to meeting the applicable information security requirements and continuously improving the ISMS.

The Head of Security and its backup lead the management and coordination structure for the implementation of the ISMS.

All employees and other stakeholders are responsible for following ISMS rules and practices.