Legal information
Information Security and Privacy Policy
1. Introduction
At Priuser, we consider information security and privacy fundamental to developing and providing our products and services.
Priuser is a product developed and marketed by Attic LLC, which is committed to establishing, maintaining and improving practices to protect the information it manages and processes in its operations.
This Information Security and Privacy Policy establishes the general principles used to protect information assets and preserve their confidentiality, integrity, availability and traceability, in accordance with service needs, client commitments and applicable law.
Information security is a shared responsibility of Attic LLC, its staff, technology providers and third parties involved in delivering Priuser services.
2. Scope
This Policy applies to information managed or processed by Attic LLC in connection with Priuser, regardless of its format, system or infrastructure.
Its scope includes, where applicable:
- Priuser products and services;
- technology infrastructure;
- applications and systems;
- databases;
- communications;
- third-party service integrations;
- client and user information;
- business and operational information;
- personal data;
- staff and contractors;
- technology providers and third parties with authorized access to information.
Specific obligations for clients, providers and third parties may also be established in the relevant contracts, agreements and terms.
3. Information security and privacy principles
Priuser's security strategy is based on principles designed to protect information throughout its lifecycle.
Confidentiality
We adopt measures to make information accessible only to duly authorized people, systems and services.
Permissions and access must meet legitimate needs relating to the provision, administration, support or security of our services.
Integrity
We seek to preserve information accuracy, consistency and integrity and protect it against unauthorized modification, alteration or destruction.
Availability
We implement measures to keep our systems, services and information available when needed for authorized operations.
Technology infrastructure and operating procedures are designed with service availability and continuity in mind.
Traceability
We seek to maintain mechanisms to record and analyze relevant system activities when needed for operations, security, diagnostics or incident investigation.
Privacy
Personal data is processed in accordance with our Privacy Policy, contractual commitments and applicable regulations.
4. Access management
Priuser uses access management mechanisms to limit systems and information to authorized people and services.
Access is assigned according to roles and operational needs and may be changed or revoked when no longer needed.
Where supported by the technology and appropriate, additional authentication and credential protection mechanisms may be implemented.
Users are responsible for keeping their credentials confidential and preventing unauthorized use.
5. Technology infrastructure
Priuser operates primarily on infrastructure and technology services provided by Amazon Web Services (AWS) and Google.
These providers supply technology components that may support functions such as:
- processing infrastructure;
- application and service hosting;
- information storage;
- databases;
- communications;
- security;
- monitoring;
- backups;
- availability and operational continuity.
Using specialist providers allows infrastructure, security and availability capabilities to match the needs of Priuser services.
Security measures for infrastructure managed directly by these providers are also subject to their respective security models, terms and responsibilities.
6. Application and development security
Priuser seeks to incorporate security considerations into the design, development, implementation and maintenance of its products and services.
This includes, where applicable:
- development environment access management;
- change control;
- reasonable separation of responsibilities and environments;
- application review and maintenance;
- technology component updates;
- management of identified vulnerabilities;
- protection of credentials and secrets;
- system and service monitoring.
These practices may evolve with product characteristics, identified risks and new technologies.
7. Personal data protection
Personal data protection is part of Priuser's security principles.
Attic LLC adopts reasonable technical and organizational measures to reduce the risks of unauthorized access, loss, alteration, disclosure or misuse of personal data.
When Priuser processes information on behalf of clients, it does so in accordance with the contracted services, relevant instructions and applicable agreements.
Information about collection, use, retention, international transfers and data subject rights is set out in our Privacy Policy.
8. Third-party integrations and services
Priuser may integrate with third-party platforms and technology services to provide certain client features.
These may include Google, Meta — including Facebook, Instagram and WhatsApp — Mercado Libre, Pilot, Redoo and other platforms integrated with Priuser.
These integrations may involve information exchange needed to perform certain sales, administrative or communication processes.
Priuser seeks to ensure that integrations developed or managed by Attic LLC use appropriate authentication, authorization and information transmission mechanisms.
Once information is processed directly by an external platform, security measures in that environment also depend on the relevant provider's policies, technologies and responsibilities.
9. Communications and information transmission
Attic LLC adopts reasonable measures to protect information during transmission between the systems and services in Priuser's technology ecosystem.
These measures may vary according to the nature of the integration, the provider and the type of information processed.
Where technically possible, exchanges with external systems are limited to the data needed for the relevant feature.
10. Monitoring and incident management
Priuser applies practices to detect, analyze and respond to events that may affect the security of its systems or processed information.
When a security incident is identified, we will seek to:
- analyze its nature and scope;
- take measures to contain its effects;
- mitigate identified risks;
- restore affected services where applicable;
- preserve information needed for analysis;
- implement corrective measures where appropriate;
- send communications or notifications required by law or applicable contractual commitments.
The response will depend on the nature, severity and scope of each incident.
11. Service continuity and availability
Attic LLC considers operational continuity part of Priuser's technology management.
The architecture, infrastructure and procedures used aim to reduce the impact of technical failures, incidents or unforeseen circumstances on service availability.
Depending on each system, backups, recovery, redundancy, monitoring or other measures may be used to support service continuity or restoration.
12. Provider management
Technology providers are an important part of Priuser's operating ecosystem.
When selecting and using providers involved in information processing or storage, Attic LLC considers service characteristics, operational needs, contractual terms and relevant security and privacy aspects.
Security responsibilities may be shared between Attic LLC and each provider according to the nature of the contracted service.
13. Staff and contractors
People who have access to information managed by Attic LLC as part of their roles must use it solely for authorized purposes and maintain its confidentiality.
Staff and contractors must follow the policies, procedures, confidentiality commitments and access controls applicable to their roles.
Access may be reviewed, changed or revoked when a person's role changes or their relationship with Attic LLC ends.
14. Compliance
Attic LLC seeks to develop its security and privacy practices in accordance with:
- applicable laws and regulations;
- contractual commitments to clients;
- personal data protection obligations;
- requirements arising from the technology services and providers used.
Measures and procedures may be updated in response to regulatory, technological, operational or security risk changes.
15. Responsibilities
Attic LLC
Responsible for establishing Priuser's general security and privacy guidelines and allocating the resources reasonably necessary to implement them.
Staff and contractors
Must follow applicable policies and procedures, protect information they access and report any situation that may compromise its security or privacy.
Clients
Clients are responsible for managing user access appropriately, using services according to contracted terms and adopting appropriate security measures in systems, devices and processes under their control.
Providers and third parties
Providers and third parties involved in delivering services must meet the security, privacy and confidentiality obligations applicable under the relevant agreements and terms.
16. Continuous improvement
Information security is an ongoing process.
Attic LLC may review and adapt its practices, technologies and procedures as Priuser evolves, new features are added, infrastructure changes, risks are identified and security threats develop.
This Policy may be updated to reflect these changes.
17. Contact
To ask questions or report a situation relating to the security or privacy of Priuser information, please contact:
Attic LLC
407 Lincoln Road, Suite 6G
Miami Beach, FL 33139
United States
Email: soporte@priuser.com