Data Protection Policy
Last updated: July 2026
Overview
This Data Protection Policy describes the technical and organisational security measures Chemizon ("we," "us," or "our") implements to protect personal data processed through our platform and services (the "Service"). It supplements our Privacy Policy and Terms of Service.
We reserve the right to modify these measures at any time, provided that any modification does not materially reduce the overall level of protection afforded to personal data. This policy applies to all data processed by Chemizon on behalf of users and customers.
If you have questions about our data protection practices, please contact us.
1. Access Control
Measures to prevent unauthorised persons from gaining access to data processing systems.
1.1 Infrastructure and Hosting
The Service is hosted with third-party cloud infrastructure providers operating multi-tenant environments. We select providers that maintain recognised security certifications including SOC 2 Type II and ISO 27001. Contractual data processing agreements are in place with all infrastructure providers to ensure data is handled in accordance with applicable law and our security requirements.
1.2 Physical and Environmental Security
Physical access to the underlying infrastructure is managed by our cloud providers, who are responsible for physical security controls including secure facilities, environmental controls (power, cooling, fire suppression), and restricted physical access to data centre hardware. We rely on our providers' audited controls for physical and environmental security.
1.3 Authentication
All access to non-public data requires user authentication. We enforce strong password policies and support multi-factor authentication (MFA). API access is controlled via API keys or OAuth 2.0 authorisation flows. Passwords are stored using industry-standard hashing algorithms and are never stored in plaintext.
1.4 Authorisation
Data is accessible only through controlled application interfaces. Our authorisation system validates each request against the requesting user's permissions and the attributes of the requested dataset. Users can only access data they are explicitly permitted to view or modify. Role assignments are reviewed at least every six months.
1.5 Least Privilege
Internal access to production systems and customer data is granted on a "just-in-time" basis and limited to the minimum necessary for the task at hand. All access requests are logged and subject to approval. Elevated access rights are time-bound and automatically revoked upon expiry.
2. Network and Application Security
Measures to prevent unauthorised use of data processing and communication systems.
2.1 Network Controls
Our infrastructure is deployed within isolated Virtual Private Cloud (VPC) environments. Network access is controlled through security groups and firewall rules that restrict traffic to authorised protocols, ports, and sources only. Unnecessary network services are disabled.
2.2 Intrusion Detection and Prevention
We deploy a Web Application Firewall (WAF) to monitor, filter, and block malicious traffic directed at internet-facing services. Network traffic is continuously monitored for anomalous patterns and known attack signatures.
2.3 Vulnerability Management
We conduct regular static code analysis and security reviews of our codebase to identify vulnerabilities and enforce secure coding practices. Dependencies are monitored for known security vulnerabilities and patched promptly.
2.4 Penetration Testing
We engage independent, recognised security providers to conduct penetration testing at least annually. Testing covers our external attack surface including web applications, APIs, and network infrastructure. Identified findings are triaged and remediated according to severity.
3. Transmission Control
Measures to ensure personal data cannot be read, copied, altered, or removed without authorisation during transfer.
3.1 Encryption in Transit
All data transmitted between users and the Service is encrypted using HTTPS (TLS 1.2 or higher). Unencrypted HTTP connections are automatically redirected to HTTPS. Internal service-to-service communication is also encrypted in transit where technically feasible.
3.2 Encryption at Rest
Data stored in our databases and file storage is encrypted at rest using industry-standard encryption algorithms (AES-256 or equivalent). Encryption keys are managed by our infrastructure providers using hardware security modules (HSMs) and are rotated periodically.
3.3 Sensitive Data Handling
Particularly sensitive data types (such as authentication credentials and session tokens) are additionally protected in memory and are never logged in plaintext. Password fields are hashed using adaptive algorithms (e.g., bcrypt) before storage.
4. Input Control and Audit Logging
Measures to ensure it is possible to verify and establish whether and by whom personal data has been entered, modified, or removed.
4.1 Logging
We maintain comprehensive audit logs of system activity, including authentication events, access to sensitive data, administrative actions, and application errors. Logs are retained for a period sufficient to support security investigations and regulatory requirements, and are protected against unauthorised modification.
4.2 Monitoring and Alerting
Automated alerting is configured to notify our security team of anomalous or suspicious activity, including repeated authentication failures, unusual data access patterns, and infrastructure anomalies. Alerts are triaged and investigated promptly.
5. Incident Response
Measures to ensure personal data is protected in the event of a security incident or breach.
5.1 Incident Management
We maintain a formal security incident response process. Security events are documented with descriptions, timelines, affected systems, and remediation steps. Each incident is investigated to determine root cause and prevent recurrence.
5.2 Breach Notification
In the event of a confirmed personal data breach that poses a risk to affected individuals, we will notify impacted users or customers without undue delay, and in any event within the timeframes required by applicable data protection law (e.g., 72 hours under GDPR where required). Notifications will describe the nature of the breach, the data affected, the steps taken to address it, and recommended actions for affected individuals.
5.3 Regulatory Notification
Where required by applicable law, we will also notify the relevant supervisory authority of a personal data breach within the legally mandated timeframe, providing all information required under applicable regulations.
6. Availability and Resilience
Measures to ensure personal data is protected against accidental destruction or loss.
6.1 Infrastructure Availability
Our infrastructure is designed for high availability. We target a minimum uptime of 99.9% for core platform services. Our cloud providers maintain N+1 redundancy for critical infrastructure components including power, networking, and cooling systems.
6.2 Fault Tolerance and Redundancy
The Service is deployed across multiple availability zones to eliminate single points of failure. Critical components are designed to automatically failover in the event of a zone-level outage, minimising disruption to users.
6.3 Backups
Production databases are backed up regularly using automated, encrypted backup procedures. Backup integrity is tested periodically to ensure data can be restored successfully. Backups are retained for a period consistent with our data retention obligations and disaster recovery requirements.
6.4 Disaster Recovery
We maintain disaster recovery procedures that define recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical systems. These procedures are tested and reviewed regularly to ensure they remain effective.
7. Vendor and Third-Party Management
We conduct due diligence on all third-party service providers that process personal data on our behalf, including reviewing their security certifications, policies, and controls. All sub-processors are bound by data processing agreements that require them to implement appropriate technical and organisational measures consistent with this policy and applicable data protection law.
We limit the personal data shared with sub-processors to the minimum necessary for them to perform their functions. Sub-processor relationships are reviewed periodically and terminated where a provider no longer meets our standards.
8. Staff Obligations and Training
All Chemizon personnel with access to personal data are required to maintain the confidentiality of that data. This obligation is embedded in employment contracts and contractor agreements. We provide data protection and security awareness training to all relevant staff and require personnel handling personal data to adhere to our internal information security policies.
Access to personal data is granted on a need-to-know basis and revoked promptly upon change of role or departure.
9. Data Minimisation and Retention
We collect and process only the personal data necessary for the purposes described in our Privacy Policy. Personal data is retained only for as long as required to fulfil those purposes or to comply with legal obligations, after which it is securely deleted or anonymised.
Upon receiving a validated account deletion request, personal data is removed from our active systems within 30 days, subject to any legal obligation to retain certain records for a longer period.
10. Privacy by Design and Default
We integrate data protection considerations into the design and development of new features and services from the outset. Privacy impact assessments are conducted for processing activities that may present a higher risk to individuals. Our default settings are configured to process only the data strictly necessary for the intended purpose.
11. International Data Transfers
Where personal data is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we ensure that appropriate safeguards are in place as required by applicable data protection law. These safeguards may include Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms. Details of specific safeguards can be provided upon request by contacting us.
12. Updates to This Policy
We may update this Data Protection Policy from time to time as our practices evolve, as technology changes, or as required by applicable law. We will notify users of material changes by updating the "last updated" date at the top of this page and, where appropriate, by providing additional notice. We encourage you to review this page periodically.
Contact Us
If you have questions about this Data Protection Policy, wish to raise a concern about our security practices, or would like to request further information about the safeguards we have in place, please contact us and we will respond within one business day.