Policies

Information Security Policy

Effective Date: August 4, 2026
Policy Owner: Black X Marketing Inc.
Applies To: All Black X Marketing Inc. employees, contractors, vendors, and third parties with authorized access to company or client systems, devices, accounts, or data.

Purpose

This Information Security Policy establishes how Black X Marketing Inc. protects the confidentiality, integrity, and availability of information assets.

This includes client marketing data, campaign data, ad accounts, customer relationship management data, automation systems, credentials, financial information, internal business records, website data, and company technology systems.

Scope

This policy applies to all company and client systems, including:

  • Company websites and hosting environments
  • Google Ads, Meta Ads, and other advertising platforms
  • CRM and marketing automation platforms
  • Cloud infrastructure and databases
  • Internal communication and project-management systems
  • SaaS tools, APIs, software integrations, and automation workflows
  • Company-owned and approved personal devices used for business
  • Client data and client-provided credentials

Information Security Principles

Black X Marketing Inc. protects information using the following principles:

Confidentiality: Information is accessible only to authorized personnel.

Integrity: Information remains accurate, complete, and changed only through authorized action.

Availability: Authorized personnel can access necessary systems and information when needed for legitimate business purposes.

Access Control

  • Access to client accounts, internal systems, and sensitive information is granted only on a need-to-know and role-based basis.
  • MFA is required for administrative accounts, client advertising platforms, and business-critical SaaS tools where available.
  • Access is reviewed during onboarding, upon role changes, and when responsibilities change.
  • Access must be removed immediately when an employee or contractor leaves Black X Marketing Inc. or no longer requires access.
  • Shared or generic account credentials are prohibited.
  • Each account must be associated with a named, authorized individual.

Password Management

Password creation, storage, reset, MFA, and administrator credential practices must comply with the Black X Marketing Inc. Website Administrator Password Policy.

Data Handling and Protection

  • Sensitive company and client information must be encrypted in transit and at rest wherever technically supported.
  • Company and client information may only be shared with vendors, subcontractors, or partners that have a legitimate business need and appropriate confidentiality or data-protection obligations.
  • Company and client data must not be stored in unmanaged personal cloud-storage accounts or unauthorized personal systems.
  • Sensitive information must not be transmitted through insecure channels when a secure alternative is available.
  • Data retention and disposal must follow client contract terms, operational needs, and applicable law.
  • Information that is no longer required must be securely deleted or destroyed.

Device and Network Security

  • Devices used to access company or client systems must have current operating systems, security updates, endpoint protection, and disk encryption enabled where technically supported.
  • Public or unsecured Wi-Fi must not be used to access sensitive company or client systems without a VPN or comparable secure connection.
  • Personal devices used for business must meet the applicable security standards of company-managed devices.
  • Lost, stolen, compromised, or suspected-compromised devices must be reported immediately.

Acceptable Use

  • Company systems, accounts, software, and devices may be used only for legitimate business purposes.
  • Employees and contractors must not install unauthorized software, browser extensions, plug-ins, or tools on systems that have access to company or client data.
  • Suspicious emails, messages, links, attachments, login prompts, or files must be reported promptly and must not be opened, executed, or forwarded.
  • Credentials, API keys, access tokens, and client logins must never be shared through unsecured channels.

Incident Response

  • Any suspected security incident must be reported immediately to Black X Marketing Inc.
  • Security incidents include compromised credentials, phishing attacks, malware, ransomware, unauthorized access, data exposure, misconfigured systems, lost or stolen devices, and suspicious account activity.
  • Black X Marketing Inc. will investigate, contain, remediate, document, and, where required, notify affected clients, vendors, individuals, insurers, or regulators.
  • Incident records and remediation actions will be retained for appropriate audit, compliance, and improvement purposes.

Third-Party and Vendor Risk

  • Vendors, software tools, platforms, and contractors receiving company or client data must be evaluated for reasonable security practices before adoption or engagement.
  • Vendor access must be limited to the least privilege necessary for the intended service.
  • Vendor access must be reviewed periodically and removed when no longer needed.
  • Vendors that materially fail to meet required security or confidentiality standards may be restricted, suspended, or terminated.

Employee Responsibilities and Training

  • Employees and contractors must complete security awareness training during onboarding and periodically thereafter.
  • Personnel are responsible for safeguarding credentials, devices, and information in their possession or control.
  • Personnel must promptly report actual or suspected policy violations or security incidents.
  • Violations of this policy may result in disciplinary action, up to and including termination of employment or contract.

Review

This policy will be reviewed at least annually, and sooner after a security incident, significant technology change, material business change, or update to applicable law or client obligations.