Information Security Policy

Statement of Policy

(1) Plumir is committed to maintaining appropriate standards of information security to protect personal data, business information, and marketplace activity from unauthorised access, disclosure, alteration, or destruction.

(2) This Information Security Policy applies to all individuals who have access to Plumir systems or data, including employees, directors, contractors, consultants, and any third parties engaged by Plumir (“Authorised Persons”).

(3) All Authorised Persons must comply with this Policy and take reasonable steps to protect the confidentiality, integrity, and availability of information processed through Plumir’s systems.

Purpose of Policy

(4) Under the UK General Data Protection Regulation (UK GDPR), Plumir is required to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its data processing activities.

(5) This includes ensuring:

a. the confidentiality, integrity, and availability of personal data;

b. protection against unauthorised or unlawful processing;

c. protection against accidental loss, destruction, or damage;

d. the ability to demonstrate compliance with applicable data protection laws.

(6) The purpose of this Policy is to:

a. establish clear standards for safeguarding personal data and business information;

b. protect Plumir’s digital systems, marketplace infrastructure, and informational assets from misuse, loss, or unauthorised access;

c. ensure that individuals with authorised access to Plumir systems understand their responsibilities regarding information security;

d. support compliance with UK GDPR and related data protection legislation.

(7) This Policy does not form part of any contract of employment or engagement and may be amended at any time to reflect changes in legal requirements, business operations, or security practices.

Definitions

For the purposes of this Policy:

a. business Information means non-personal business-related information belonging to Plumir, including operational, financial, commercial, and strategic information.

b. confidential Information means any information (whether personal data or business information) that is not publicly available and is intended to remain confidential, including trade secrets and proprietary information.

c. personal Data means any information relating to an identified or identifiable individual, as defined under UK GDPR.

d. special Category Data means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data (where used for identification), health data, or data concerning a person’s sex life or sexual orientation.

Roles and Responsibilities

(8) Overall responsibility for information security rests with Plumir’s management.

(9) The person responsible for data protection and information security compliance within Plumir is the Data Protection Lead.

(10) The Data Protection Lead is responsible for:

a. implementing and maintaining this Information Security Policy;

b. ensuring appropriate technical and organisational security measures are in place;

c. monitoring and responding to potential or actual security incidents;

d. ensuring compliance with UK GDPR and related data protection legislation;

e. reviewing security practices periodically to ensure continued effectiveness.

(11) All individuals with authorised access to Plumir systems or data must:

a. comply with this Policy;

b. protect login credentials and authentication methods;

c. report any suspected data breach or security concern promptly;

d. use Plumir systems only for authorised purposes.

Scope of This Policy

(12) This Policy applies to all information processed by or on behalf of Plumir, whether in digital, physical, or verbal form.

(13) It covers information held or transmitted through:

a. marketplace platforms and administrative dashboards (including Sharetribe);

b. payment processing systems (including Stripe);

c. email systems and cloud-based services;

d. laptops, mobile devices, and other devices used for business purposes;

e. any downloaded or exported business records.

(14) The information covered by this Policy includes:

a. personal Data relating to users (including sellers and buyers), contractors, or business contacts;

b. business Information relating to Plumir’s operations, finances, strategy, or technical infrastructure;

c. confidential Information belonging to Plumir or third parties.

(15) This Policy should be read alongside Plumir’s Privacy Policy and any internal procedures relating to data protection, access control, and incident response.

General Principles

(16) All information processed by Plumir must be treated as confidential and commercially valuable where appropriate.

(17) Personal Data must be protected against unauthorised access, accidental loss, alteration, disclosure, or destruction through appropriate technical and organisational measures.

(18) Personal Data must only be processed for specified, explicit, and legitimate purposes and must not be used for unrelated personal or commercial purposes.

(19) Access to information must be limited to those with a legitimate business need.

Information Management

(20) Personal Data must be processed in accordance with UK GDPR principles, including:

a. lawfulness, fairness and transparency;

b. purpose limitation;

c. data minimisation;

d. accuracy;

e. storage limitation;

f. integrity and confidentiality;

g. accountability.

(21) Personal Data must be adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

(22) Plumir will implement appropriate security measures including:

a. secure SaaS hosting infrastructure (e.g. Sharetribe);

b. secure payment processing (e.g. Stripe);

c. strong authentication controls;

d. encryption of data in transit (HTTPS/SSL);

e. regular review of system access rights.

(23) Personal Data must not be retained longer than necessary and will be handled in accordance with Plumir’s retention practices.

Access Control and System Security

(24) Access to administrative dashboards and systems must be restricted to authorised individuals only.

(25) Strong, unique passwords must be used for all business systems.

(26) Multi-factor authentication (2FA) must be enabled wherever available, including for:

a. email accounts;

b. Stripe accounts;

c. marketplace administration systems.

(27) User credentials must not be shared or reused across platforms.

(28) Devices used to access business systems must:

a. be password protected;

b. have up-to-date operating systems and security updates;

c. be locked when unattended.

Device and Remote Working Security

(29) As Plumir operates primarily through cloud-based systems, business data should not be downloaded or stored locally unless strictly necessary.

(30) If data is downloaded for legitimate purposes, it must:

a. be stored securely;

b. not be shared;

c. be deleted once no longer required.

(31) Confidential Information must not be accessed or displayed in public environments where it may be visible to unauthorised individuals.

(32) Personal devices used for business access must be secured with password protection and updated software.

Communications and Data Transfer

(33) Care must be taken to verify email addresses before sending Personal Data or Confidential Information.

(34) Particularly sensitive information should be transmitted using secure methods or encrypted where appropriate.

(35) Personal email accounts must not be used for business purposes involving Personal Data.

Third-Party Service Providers

(36) Plumir may engage third-party service providers to process information on its behalf.

(37) Such providers must offer appropriate security safeguards and enter into written agreements where required under UK GDPR.

(38) Examples of third-party processors include hosting and marketplace infrastructure providers and payment service providers.

International Data Transfers

(39) Where Personal Data is transferred outside the UK, appropriate safeguards must be in place in accordance with UK GDPR requirements.

(40) Transfers via reputable cloud service providers may rely on recognised adequacy regulations or appropriate contractual safeguards.

Training and Awareness

(41) Individuals with authorised access to Plumir systems must understand their responsibilities regarding information security and data protection.

(42) Security awareness will be reviewed periodically and updated where necessary.

Reporting Security Incidents

(43) Any suspected or actual data breach must be reported immediately to the Data Protection Lead.

(44) All incidents will be handled in accordance with Plumir’s Incident Response Procedure.

Consequences of Non-Compliance

(45) Failure to comply with this Policy may result in removal of system access or termination of engagement, as appropriate.

Last updated: 18 February 2026