AirBadge LLC Data Security Policy

1. Programs and Policies

a. Security Program.

AirBadge maintains and enforces a security program that addresses the management of security and the security controls employed by AirBadge. The security program includes:

  1. documented policies that AirBadge formally approves, internally publishes, communicates to appropriate personnel and reviews at least annually;
  2. documented, clear assignment of responsibility and authority for security program activities;
  3. policies covering, as applicable, acceptable computer use, information classification, cryptographic controls, access control, removable media, and remote access; and
  4. regular testing of the key controls, systems and procedures.

b. Privacy Program.

AirBadge maintains and enforces a privacy program and related policies that address how data is collected, used and shared.

2. Risk and Asset Management

a. Risk Management.

AirBadge performs risk assessments and implements and maintains controls for risk identification, analysis, monitoring, reporting, and corrective action.

b. Asset Management.

AirBadge maintains and enforces an asset management program that appropriately classifies and controls hardware and software assets throughout their life cycle.

3. Worker Education

a. Representatives.

All AirBadge employees, agents, and contractors (collectively “Representatives”) acknowledge their information security and privacy responsibilities under AirBadge’s policies.

b. Worker Controls.

For Representatives who will create, process, receive, access, transmit or store (“Handle” or “Handling”) data, AirBadge:

  1. conducts security and privacy training;
  2. implements disciplinary processes for violations of information security or privacy requirements; and
  3. upon termination or applicable role change, promptly removes or updates Worker access rights and requires the return or destruction of data.

4. Network and Operations Management

a. Policies and Procedures.

AirBadge implements policies and procedures for network and operations management. Such policies and procedures address: hardening, change control, segregation of duties, separation of development and production environments, technical architecture management, network security, virus protection, media controls, protection of information in transit, data integrity, encryption, audit logs, and network segregation.

b. Vulnerability Assessments.

AirBadge performs periodic vulnerability assessments and testing on systems and applications that Handle data.

5. Access Control

a. Access Control.

AirBadge implements access controls designed to maintain the confidentiality of data. Such controls include:

  1. authorization processes for physical, privileged, and logical access to facilities, systems, networks, wireless networks, operating systems, mobile devices, system utilities, and other locations containing data; and
  2. granting access only if it is logged, strictly controlled, and needed for a Worker or third party to perform their job function.

b. Authentication.

AirBadge authenticates each Representative’s identity through appropriate authentication credentials such as strong passwords, token devices, or biometrics.

6. Information Security Incident Management

a. Incident Management Program.

AirBadge implements an information security incident management program that addresses management of information security incidents including a loss, theft, misuse of or unauthorized access, disclosure or destruction of any data (“Incident”).

b. Incident Reporting.

AirBadge will promptly, and no less than within 48 hours, notify Customer of any Incident affecting customer data.

c. Response.

AirBadge agrees to partner with Customer to respond to the Incident. Response may include: identifying key partners, investigating the Incident, providing regular updates, and determining notice obligations. Except as may be required by law, AirBadge may not notify Customer’s affected customers about an Incident without first consulting Customer.