Does Plum follow GDPR?
Does Plum follow GDPR?
Does Xoxoday have an information security policy and is it communicated and published to all employees, suppliers, and other relevant external parties?
Does Xoxoday have an information security policy and is it communicated and published to all employees, suppliers, and other relevant external parties?
Does Xoxoday have a formal established disciplinary or sanction policy for its employees who have violated security policies and controls?
Does Xoxoday have a formal established disciplinary or sanction policy for its employees who have violated security policies and controls?
Does Xoxoday ensure that all projects go through some form of information security assessment?
Does Xoxoday ensure that all projects go through some form of information security assessment?
Does Xoxoday have a mobile device policy?
Does Xoxoday have a mobile device policy?
Does Xoxoday have a policy governing information classification and is there a process by which all information can be appropriately classified?
Does Xoxoday have a policy governing information classification and is there a process by which all information can be appropriately classified?
Does Xoxoday have a formal procedure governing how removable media is disposed of?
Does Xoxoday have a formal procedure governing how removable media is disposed of?
Does Xoxoday have a process to access the information and application system functions restricted in line with the access control policy?
Does Xoxoday have a process to access the information and application system functions restricted in line with the access control policy?
What kind of Encryption and Hashing is used at Xoxoday?
What kind of Encryption and Hashing is used at Xoxoday?
Does Xoxoday have a documented and tested Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) available? If Yes, kindly mention the location where the data would be stored?
Does Xoxoday have a documented and tested Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) available? If Yes, kindly mention the location where the data would be stored?
Is there a process for reporting identified information security weaknesses at Xoxoday and Is this process widely communicated?
Is there a process for reporting identified information security weaknesses at Xoxoday and Is this process widely communicated?
Where systems or applications are developed, are they security tested as part of the development process?
Where systems or applications are developed, are they security tested as part of the development process?
Are there policies mandating the implementation and assessment of security controls at Xoxoday?
Are there policies mandating the implementation and assessment of security controls at Xoxoday?
Do contracts with external parties and agreements within the organization detail the requirements for securing business information in a transfer?
Do contracts with external parties and agreements within the organization detail the requirements for securing business information in a transfer?
Are IS Systems subject to audit at Xoxoday and does the audit process ensure business disruption is minimized?
Are IS Systems subject to audit at Xoxoday and does the audit process ensure business disruption is minimized?
Is there a process to risk assess and react to any new vulnerabilities as they are discovered at Xoxoday?
Is there a process to risk assess and react to any new vulnerabilities as they are discovered at Xoxoday?
How secure is Plum?
How secure is Plum?
How does Plum use my information?
How does Plum use my information?
- To personalize your experience and to allow us to deliver the type of content and product offerings in which you are most interested.
- To improve our website in order to better serve you.
- To allow us to better service you in responding to your customer service requests.
- To ask for ratings and reviews of services or products.
- To follow up with them after correspondence (live chat, email, or phone inquiries).
Data security and ownership?
Data security and ownership?
Do you have procedures in place to ensure production data shall not be replicated or used in non-production environments?
Do you have procedures in place to ensure production data shall not be replicated or used in non-production environments?
A formal privacy management framework is in place
A formal privacy management framework is in place
Are there documented privacy policies and procedures that address choice and consent based on the statutory, regulatory, or contractual obligations to provide privacy protection for client-scoped privacy data?
Are there documented privacy policies and procedures that address choice and consent based on the statutory, regulatory, or contractual obligations to provide privacy protection for client-scoped privacy data?
Does the Vendor allow Audits by the customer or any Third Paties appointed by the customer of the below given nature:
Does the Vendor allow Audits by the customer or any Third Paties appointed by the customer of the below given nature:
Are there documented privacy policies and procedures that address choice and consent based on the statutory, regulatory, or contractual obligations to provide privacy protection for client-scoped privacy data? (2)
Are there documented privacy policies and procedures that address choice and consent based on the statutory, regulatory, or contractual obligations to provide privacy protection for client-scoped privacy data? (2)
Is your Privacy Notice/ Privacy Policy externally available? Please provide us with the URL.
Is your Privacy Notice/ Privacy Policy externally available? Please provide us with the URL.
A copy of your privacy policy and external privacy statement, if they are separate documents.
A copy of your privacy policy and external privacy statement, if they are separate documents.
Is Records of Processing or an inventory is maintained on what personal data is collected/stored/processed/managed on behalf of Infosys?
Is Records of Processing or an inventory is maintained on what personal data is collected/stored/processed/managed on behalf of Infosys?
Do you maintain a list of all individuals having access to Personal Data and do you regularly review (whether it is electronic data, hard copy data, etc.)
Do you maintain a list of all individuals having access to Personal Data and do you regularly review (whether it is electronic data, hard copy data, etc.)
Do you follow privacy guidance when collecting, storing, or processing Personal Data via electronic, audio, visual or print media?
Do you follow privacy guidance when collecting, storing, or processing Personal Data via electronic, audio, visual or print media?
Do you routinely access/review/monitor your organization's measures to meet the objectives of privacy commitment, when Personal Data of Infosys is collected/stored/processed as part of service engagement?
Do you routinely access/review/monitor your organization's measures to meet the objectives of privacy commitment, when Personal Data of Infosys is collected/stored/processed as part of service engagement?
Are your employees and subcontractors given regular and formal privacy training? If Yes, what is the frequency of Training?
Are your employees and subcontractors given regular and formal privacy training? If Yes, what is the frequency of Training?
Do you confirm compliance with applicable data privacy clauses in your contract executed with Infosys?
Do you confirm compliance with applicable data privacy clauses in your contract executed with Infosys?
Do you develop and maintain an agreed upon audit plan (e.g., scope, objective, frequency, resources, etc.) for reviewing the efficiency and effectiveness of implemented security controls?
Do you develop and maintain an agreed upon audit plan (e.g., scope, objective, frequency, resources, etc.) for reviewing the efficiency and effectiveness of implemented security controls?
