Black X Marketing Inc. — Information Security Policy

Effective Date: July 4, 2026
Policy Owner: Black X Marketing Inc.
Applies To: All Black X Marketing Inc. employees, contractors, and any third parties with access to company or client systems and data

1. Purpose

This policy establishes how Black X Marketing Inc. protects the confidentiality, integrity, and availability of its information assets, including client marketing data, campaign accounts, credentials, and internal business systems. It sets expectations for every employee handling company or client information, whether on company devices, client platforms (Google Ads, Meta Ads, Go High Level, Supabase, etc.), or third-party tools.

2. Scope

This policy applies to all employees, contractors, and administrators of Black X Marketing Inc., and covers all systems, devices, and accounts used to conduct company business, including the company website, marketing automation platforms, client ad accounts, and any cloud or SaaS tools storing company or client data.

3. Information Security Principles

Black X Marketing Inc. protects information according to three core principles:onetrust+1

  • Confidentiality: information is accessible only to authorized personnel

  • Integrity: information remains accurate, complete, and unaltered except by authorized action

  • Availability: authorized personnel can access information and systems when needed

4. Access Control

  • Access to client accounts, internal systems, and sensitive data is granted only on a need-to-know, role-based basis

  • Multi-Factor Authentication (MFA) is required on all administrative accounts, client ad platforms, and business-critical SaaS tools

  • Employee access is reviewed at onboarding, upon role change, and immediately revoked upon termination

  • Shared or generic logins are prohibited; every account must be tied to a named individual

5. Password Management

Password creation, storage, and reset practices follow the Black X Marketing Inc. Administrator Password Policy, including salted hashing, no forced complexity rules, and mandatory MFA for privileged accounts.

6. Data Handling and Protection

  • Sensitive data (client campaign data, financial information, credentials) must be encrypted in transit and at rest wherever technically supported

  • Data is only shared with vendors or subcontractors under signed confidentiality or data processing agreements

  • Company and client data must not be stored on personal devices or personal cloud accounts

  • Data retention and disposal follow client contract terms and applicable law; data no longer needed is securely deleted

7. Device and Network Security

  • All company devices used to access client or business systems must have up-to-date operating systems, antivirus/endpoint protection, and disk encryption enabled

  • Public or unsecured Wi-Fi must not be used to access client accounts or sensitive systems without a VPN

  • Personal devices used for work (BYOD) must meet the same security standards as company-issued devices

8. Acceptable Use

  • Company systems, accounts, and devices are to be used only for legitimate business purposes

  • Employees must not install unauthorized software, browser extensions, or tools on systems with access to client data

  • Suspicious emails, links, or attachments must be reported immediately, not opened or forwarded

9. Incident Response

  • Any suspected security incident (compromised account, phishing attempt, data exposure, lost/stolen device) must be reported immediately to Black X Marketing Inc. via email – Contact@blackxmarketing.com

  • The company will investigate, contain, and remediate incidents promptly, and notify affected clients or regulators as required by law or contractcmitsolutions+1

  • A record of incidents and remediation steps will be maintained for audit purposes

10. Third-Party and Vendor Risk

  • Any third-party tool or vendor granted access to company or client data must be vetted for adequate security practices before adoption

  • Vendor access is limited to what is necessary and reviewed periodically.

11. Employee Responsibilities and Training

  • All employees must complete security awareness training upon onboarding and periodically thereafter

  • Employees are responsible for safeguarding their credentials, devices, and any data they access

  • Violations of this policy may result in disciplinary action, up to and including termination.

12. Policy Review

This policy is reviewed at least annually, or sooner following a security incident, significant technology change, or update to applicable law or client contractual requirements.