The business travel management platform processes employee personal data, booking details, travel itineraries, billing information, and company-related data, among other things. Therefore, security encompasses both technological solutions and team procedures and workflows. The worktrips.com system protects data through access control, account and connection security, system monitoring, regular resilience verification, GDPR-compliant procedures, and Microsoft Azure infrastructure.
How does worktrips.com protect data?
Access control and account protection
The worktrips.com system employs access management policies designed to ensure that only those who need it to perform their duties are able to access data. These security policies also cover the use of passwords, company email, the internet, team tools, and secure remote access. Security also extends to user accounts and platform connections, limiting the risk of access hijacking and unauthorized reading of transmitted information.
Monitoring and external security verification
The worktrips.com system is monitored for potential threats. Its security resilience is also regularly verified by independent, external experts. This allows for security assessments from both the platform development team and external experts.
Security in cooperation with partners
The business travel platform operates within an ecosystem of services and suppliers. Therefore, worktrips.com also defines principles for secure collaboration with partners and the protection of information shared within the framework of ongoing processes.
Information Security Policy
The foundation of organizational data protection at WorkTrips is the Information Security Policy. It covers, among other things:
- information access management,
- rules for creating and using secure passwords,
- use of company email and the Internet,
- classifying information,
- protection against threats,
- secure remote access,
- cooperation with partners,
- procedures in the event of a failure or breach of personal data. The policy is regularly updated and is supplemented by periodic team training and internal audits to verify compliance with the adopted principles.
GDPR and user data protection
The worktrips.com system processes user data in accordance with the GDPR. This includes both securing information against unauthorized access and ensuring the rights of data subjects.
The User may, among other things, obtain access to their data, rectify them or request their deletion to the extent provided for by applicable law.
Microsoft Azure as platform infrastructure
WorkTrips uses Microsoft Azure as the cloud environment for its platform. This infrastructure supports data protection and business continuity, including:
- data encryption,
- regular backups,
- protection against failures,
- protection against Internet attacks, including DDoS.
The cloud environment provides the technological foundation for the subsequent layers of protection employed by worktrips.com, such as monitoring, access control, and incident response procedures.
Responding to outages and data breaches
The worktrips.com platform has procedures in place to determine how to proceed in the event of a failure or breach of personal data.
Monitoring, backups and incident procedures support three basic stages of protection:
- threat prevention,
- detection of irregularities,
- responding and restoring proper operation.
The platform's security is based on a combination of technological infrastructure, organizational policies, monitoring, access control, training and regular verification of the security measures used.
Top comments (0)