Security Policy
Last updated: September 8, 2025
Choiceventureflow is committed to protecting the security of information processed through our platform. This Security Policy describes the measures we take to safeguard data, maintain system integrity, and respond to security incidents. By using our services, you acknowledge the practices described in this document.
1. Scope
This policy applies to all systems, infrastructure, applications, and data managed or operated by Choiceventureflow in connection with the delivery of our technical translation services. It covers internal operations, client-facing platforms, and third-party integrations where Choiceventureflow acts as a data controller or processor.
2. Information We Protect
We apply security controls to the following categories of information:
- Account credentials and authentication data
- Client-submitted documents and translation materials
- Communication records between clients and specialists
- Billing and payment information
- Usage logs and session metadata
- Internal operational data and configuration records
3. Security Principles
Our approach to security is guided by the following core principles:
- Confidentiality: Information is accessible only to authorised individuals and systems.
- Integrity: Data is accurate, complete, and protected from unauthorised modification.
- Availability: Services and data remain accessible to authorised users when needed.
- Accountability: Actions taken within our systems are logged and attributable.
4. Technical Security Measures
4.1 Encryption
All data transmitted between clients and our platform is encrypted using industry-standard Transport Layer Security (TLS). Data stored on our servers is encrypted at rest using recognised encryption algorithms. Encryption keys are managed through secure key management practices and rotated on a regular schedule.
4.2 Access Controls
Access to systems and data is governed by the principle of least privilege. Staff members are granted access only to the resources necessary for their role. Access rights are reviewed periodically and revoked promptly upon role change or departure. Multi-factor authentication is required for access to administrative systems and sensitive environments.
4.3 Network Security
Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation. Traffic is monitored continuously for anomalies and potential threats. External-facing services are regularly assessed for vulnerabilities.
4.4 Application Security
Our development practices incorporate security at each stage of the software lifecycle. Code changes undergo review before deployment. We conduct periodic security assessments, including vulnerability scanning and penetration testing, to identify and remediate weaknesses in our applications.
4.5 Authentication and Session Management
User accounts are protected by password requirements that enforce minimum complexity standards. Session tokens are issued securely, expire after defined periods of inactivity, and are invalidated upon logout. Repeated failed authentication attempts trigger automatic protective responses.
4.6 Data Integrity
We implement checksums and validation controls to detect unauthorised changes to stored data. Audit logs capture significant system and user actions and are protected from tampering.
5. Operational Security Measures
5.1 Personnel Security
All personnel with access to client data or internal systems are subject to confidentiality obligations. Staff receive security awareness training upon onboarding and on an ongoing basis. Access privileges are assigned based on documented roles and responsibilities.
5.2 Third-Party Vendors
We evaluate the security practices of third-party service providers before engagement. Vendors who process or have access to client data are required to maintain appropriate security standards. We review vendor relationships periodically to ensure continued compliance.
5.3 Physical Security
Our services are hosted in data centre facilities that maintain physical access controls, environmental protections, and continuous monitoring. Physical access to server infrastructure is restricted to authorised personnel only.
5.4 Backup and Recovery
Data is backed up regularly using automated processes. Backups are stored securely and tested periodically to verify recoverability. We maintain business continuity and disaster recovery plans to minimise service disruption in the event of an incident.
5.5 Patch Management
Operating systems, software dependencies, and third-party components are kept up to date. Security patches are applied in a timely manner following assessment of risk and impact.
6. Incident Response
6.1 Detection and Containment
We maintain monitoring systems designed to detect potential security incidents in a timely manner. Upon detection of a suspected incident, our team initiates containment procedures to limit impact and prevent further exposure.
6.2 Investigation and Remediation
Confirmed incidents are investigated to determine scope, root cause, and affected data or systems. Remediation steps are implemented to address the vulnerability or weakness that enabled the incident. Findings are documented and used to improve future security controls.
6.3 Notification
Where a security incident results in unauthorised access to or disclosure of personal data, we will notify affected users in accordance with applicable legal obligations. Notifications will describe the nature of the incident, the data involved, and the steps taken in response.
7. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities identified in our systems. If you believe you have discovered a security issue affecting our platform, please contact us promptly at contact@choiceventureflow.online. We ask that you:
- Provide sufficient detail to allow us to reproduce and investigate the issue
- Avoid accessing, modifying, or disclosing data beyond what is necessary to demonstrate the vulnerability
- Allow us reasonable time to investigate and remediate before any public disclosure
We are committed to acknowledging valid reports and working collaboratively toward resolution. We do not pursue legal action against researchers who act in good faith in accordance with these guidelines.
8. Client Responsibilities
The security of your account is a shared responsibility. We encourage all users of our platform to:
- Use strong, unique passwords and update them regularly
- Enable multi-factor authentication where available
- Avoid sharing account credentials with third parties
- Log out of sessions on shared or public devices
- Report any suspected unauthorised access to your account promptly
- Ensure that documents submitted to our platform do not contain malicious code or files
We are not responsible for security incidents arising from a user's failure to maintain appropriate account security practices.
9. Data Retention and Deletion
We retain data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable legal obligations. Upon account closure or upon request, personal data and submitted documents are deleted or anonymised in accordance with our Privacy Policy. Backup copies may persist for a limited period following deletion in accordance with our backup retention schedule.
10. Compliance and Auditing
We periodically review our security controls against recognised industry frameworks and best practices. Internal audits are conducted to assess the effectiveness of implemented measures. Where deficiencies are identified, remediation plans are developed and tracked to completion.
11. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically. Continued use of our services following any update constitutes acceptance of the revised policy.
12. Contact Us
If you have questions or concerns about this Security Policy or our security practices, please contact us using the details below:
Choiceventureflow
214 High St, Maitland NSW 2320, Australia
Email: contact@choiceventureflow.online
Phone: +61 2 8850 0555
Website: choiceventureflow.online