Legal Center

Legal

Data Processing & Security Policy

The technical and organisational measures DealerOS uses to protect your data.

Version 1.0Effective 26 June 2026Last updated 26 June 2026

1. Overview

DealerOS applies layered technical and organisational measures to protect the confidentiality, integrity, and availability of your data. This policy summarises our key controls.

2. Encryption

Data is encrypted in transit using TLS and protected at rest. Sensitive secrets are stored securely and are never exposed to the client application.

3. Authentication & Session Security

Passwords are hashed using a strong, salted algorithm and are never stored in plain text. Sessions are protected with secure, HTTP-only cookies and expiry controls. Multi-factor authentication is supported to add a further layer of protection.

4. Access Control & Tenant Isolation

Access is governed by role-based access control (RBAC), enforced on the server for every request. Each company’s data is logically isolated through multi-tenant scoping, and sensitive actions are recorded in audit logs.

5. Infrastructure & File Storage

The Service runs on reputable cloud infrastructure. Uploaded files are stored in dedicated object storage with scoped, time-limited access rather than in the application database. Systems are continuously monitored for availability and anomalies.

6. Backups & Disaster Recovery

We maintain regular backups and disaster-recovery practices designed to restore the Service and your data in the event of a significant disruption.

7. Incident Response

We maintain an incident-response process to detect, investigate, and remediate security events, and to notify affected customers where required by law.

8. Contact

Security questions can be sent to support@dealeros.com.