Data Security Policy
The standards, certifications and controls Smile Groups maintains to protect client and customer data.
On this page
1. Our Security Commitment
Data security is treated as a delivery requirement at Smile Groups, not an afterthought. Because our services routinely involve customer, transactional and operational data on behalf of clients, we maintain a security posture designed to protect that data at every stage of an engagement.
2. Standards & Certifications
- ISO 9001:2015 our quality management system is aligned with ISO 9001 principles across service delivery.
- PCI-DSS aligned handling where engagements involve payment card data, our processes are aligned with Payment Card Industry Data Security Standard requirements.
3. Technical & Organisational Controls
- Role-based access controls limiting data access to staff assigned to a given engagement
- Encrypted transmission for data in transit where applicable
- Monitored network infrastructure across our delivery centers
- Confidentiality agreements signed by all staff handling client or customer data
- Secure disposal procedures for data no longer required
4. Access Management
Access to client systems and data is provisioned on a least-privilege basis and reviewed regularly. Access is revoked immediately upon a team member's reassignment or departure from an engagement.
5. Incident Response
We maintain an internal process for identifying, escalating and responding to potential security incidents, including timely notification to affected clients in line with contractual and legal obligations.
6. Client Data Handling
Data belonging to our clients and their customers is used exclusively to deliver the contracted service and is never used for unrelated purposes. Specific data handling terms, including retention and deletion requirements, are set out in each client's service agreement.
7. Contact Us
For security-related questions or to report a concern, contact info@smilegroups.in.
Questions about this policy?
Reach our team at info@smilegroups.in or through our contact page.