
Introduction
Wicked Design Company, LLC is committed to protecting the privacy and security of its clients' and customers' data. This security policy outlines the measures we take to ensure compliance with the Payment Card Industry Data Security Standard (PCI-DSS) and the California Consumer Privacy Act (CCPA).
PCI-DSS Compliance
Wicked Design Company, LLC maintains compliance with the PCI-DSS by implementing the following measures:
-
We use secure payment processing services that are PCI-DSS compliant.
-
We encrypt all credit card data during transmission and storage.
-
We limit access to credit card data to authorized personnel only.
-
We regularly test our security systems and procedures to ensure ongoing compliance.
CCPA Compliance
Wicked Design Company, LLC is committed to protecting the personal information of our California-based customers and clients. We comply with the CCPA by implementing the following measures:
-
We inform customers of their rights under the CCPA and provide a means for them to exercise those rights.
-
We do not sell personal information.
-
We implement reasonable security measures to protect personal information from unauthorized access or disclosure.
Security Measures
In addition to the specific measures outlined above, Wicked Design Company, LLC implements the following security measures to protect the confidentiality, integrity, and availability of our customers' and clients' data:
-
We use firewalls and intrusion detection/prevention systems to protect our network from unauthorized access or attacks.
-
We use strong encryption to protect data during transmission and storage.
-
We implement access controls to ensure that only authorized personnel have access to sensitive data.
-
We monitor and log all system activity to detect and respond to security incidents in a timely manner.
-
We conduct regular security audits and risk assessments to identify and mitigate potential security threats.
Conclusion
Wicked Design Company, LLC is committed to protecting the privacy and security of our customers' and clients' data. We comply with the PCI-DSS and CCPA to ensure that our data protection practices meet the highest standards of security and privacy. This security policy will be reviewed and updated on a regular basis to reflect changes in laws, regulations, or industry best practices.
