For Feinar, information security is a priority, aimed at protecting the company’s information assets, customer data and the rights of natural persons whose personal data are processed. The active protection of information and sensitive data is an integral part of our responsibility, reflecting our constant commitment to ensuring the requirements of confidentiality, integrity and availability of information.
To achieve these objectives, Feinar invests in the design, management and maintenance of a solid technological, physical, logical and organizational structure. In this perspective, the organization is committed to developing, maintaining and continuously improving an Information Security Management System (ISMS), compliant with the requirements of the ISO/IEC 27001 standard, integrated into the processes and services provided.
We operate in full compliance with Regulation (EU) 2016/679 – GDPR, ensuring lawful, secure and transparent processing of personal data.
For the implementation and delivery of cloud services, pursuant to ISO 27017 guidelines, Feinar undertakes to adopt security requirements that take into account risks arising from internal personnel, the secure management of multi-tenancy (infrastructure sharing), access to customers’ cloud assets by its personnel, access control (in particular administrators), communications to customers when infrastructure changes occur, the security of virtualization systems, the protection and access of customer data in a cloud environment, the management of the lifecycle of customers’ cloud accounts, the communication of data breaches and guidelines for sharing information to support investigation and forensic activities, as well as constant security regarding the physical location of data on cloud servers.
Furthermore, Feinar is constantly committed to protecting the personal data of the data subjects it manages, with particular reference to those of its customers. With regard to the latter, the company, pursuant to ISO 27018 guidelines and in accordance with applicable privacy legislation (GDPR), acts as a “Data Processor”, i.e., as a Data Processor pursuant to art. 28 of the GDPR, declaring this status and the related obligations deriving therefrom in contracts with customers.
These obligations are also reported in the appointments as processor of the suppliers used by Feinar to carry out the processing.
The following are available: