Black X Marketing Inc. — Information Security Policy
Effective Date: July 4, 2026
Policy Owner: Black X Marketing Inc.
Applies To: All Black X Marketing Inc. employees, contractors, and any third parties with access to company or client systems and data
1. Purpose
This policy establishes how Black X Marketing Inc. protects the confidentiality, integrity, and availability of its information assets, including client marketing data, campaign accounts, credentials, and internal business systems. It sets expectations for every employee handling company or client information, whether on company devices, client platforms (Google Ads, Meta Ads, Go High Level, Supabase, etc.), or third-party tools.
2. Scope
This policy applies to all employees, contractors, and administrators of Black X Marketing Inc., and covers all systems, devices, and accounts used to conduct company business, including the company website, marketing automation platforms, client ad accounts, and any cloud or SaaS tools storing company or client data.
3. Information Security Principles
Black X Marketing Inc. protects information according to three core principles:onetrust+1
Confidentiality: information is accessible only to authorized personnel
Integrity: information remains accurate, complete, and unaltered except by authorized action
Availability: authorized personnel can access information and systems when needed
4. Access Control
Access to client accounts, internal systems, and sensitive data is granted only on a need-to-know, role-based basis
Multi-Factor Authentication (MFA) is required on all administrative accounts, client ad platforms, and business-critical SaaS tools
Employee access is reviewed at onboarding, upon role change, and immediately revoked upon termination
Shared or generic logins are prohibited; every account must be tied to a named individual
5. Password Management
Password creation, storage, and reset practices follow the Black X Marketing Inc. Administrator Password Policy, including salted hashing, no forced complexity rules, and mandatory MFA for privileged accounts.
6. Data Handling and Protection
Sensitive data (client campaign data, financial information, credentials) must be encrypted in transit and at rest wherever technically supported
Data is only shared with vendors or subcontractors under signed confidentiality or data processing agreements
Company and client data must not be stored on personal devices or personal cloud accounts
Data retention and disposal follow client contract terms and applicable law; data no longer needed is securely deleted
7. Device and Network Security
All company devices used to access client or business systems must have up-to-date operating systems, antivirus/endpoint protection, and disk encryption enabled
Public or unsecured Wi-Fi must not be used to access client accounts or sensitive systems without a VPN
Personal devices used for work (BYOD) must meet the same security standards as company-issued devices
8. Acceptable Use
Company systems, accounts, and devices are to be used only for legitimate business purposes
Employees must not install unauthorized software, browser extensions, or tools on systems with access to client data
Suspicious emails, links, or attachments must be reported immediately, not opened or forwarded
9. Incident Response
Any suspected security incident (compromised account, phishing attempt, data exposure, lost/stolen device) must be reported immediately to Black X Marketing Inc. via email – Contact@blackxmarketing.com
The company will investigate, contain, and remediate incidents promptly, and notify affected clients or regulators as required by law or contractcmitsolutions+1
A record of incidents and remediation steps will be maintained for audit purposes
10. Third-Party and Vendor Risk
Any third-party tool or vendor granted access to company or client data must be vetted for adequate security practices before adoption
Vendor access is limited to what is necessary and reviewed periodically.
11. Employee Responsibilities and Training
All employees must complete security awareness training upon onboarding and periodically thereafter
Employees are responsible for safeguarding their credentials, devices, and any data they access
Violations of this policy may result in disciplinary action, up to and including termination.
12. Policy Review
This policy is reviewed at least annually, or sooner following a security incident, significant technology change, or update to applicable law or client contractual requirements.
