Ellicere – Online Retail Business Version 1.0 – 2026
1. Purpose
The purpose of this Information Security Policy is to define the security principles, responsibilities, and controls implemented by Ellicere to protect its information assets, ensure secure operation of its online store, and comply with applicable requirements of the Payment Card Industry Data Security Standard (PCI DSS).
2. Scope
This policy applies to:
- The Ellicere online store and its supporting systems
- All employees, contractors, and individuals acting on behalf of Ellicere
- All information assets owned or managed by Ellicere
- All processes related to website operation, customer service, and order fulfillment
Ellicere does not store, process, or transmit cardholder data. All payment card information is handled exclusively by certified third‑party payment service providers.
3. Business Environment Overview
Ellicere operates as an online‑only retail business selling cosmetics and hand‑painted porcelain products. The company:
- Does not operate physical retail locations
- Does not use POS terminals, card readers, or payment hardware
- Does not maintain internal servers or local databases
- Uses a hosted e‑commerce platform provided by Hostinger
- Relies entirely on external PCI DSS‑certified payment providers (Tpay, PayU, Google Pay, Apple Pay, BLIK, PayPal)
No cardholder data passes through or resides on Ellicere’s systems, devices, networks, or infrastructure.
4. Information Security Principles
Ellicere follows these core security principles:
- Confidentiality – Protecting sensitive information from unauthorized access
- Integrity – Ensuring information is accurate, complete, and unaltered
- Availability – Ensuring systems and services remain operational and accessible
5. Access Control
- Access to administrative areas of the website is restricted to authorized personnel only.
- Strong passwords are required for all accounts.
- Multi‑factor authentication (MFA) is enabled where supported.
- Access rights are granted based on job responsibilities and reviewed periodically.
6. System Security
- The Ellicere website is hosted on Hostinger, which provides secure infrastructure, firewalls, and network protection.
- All systems used to manage the website are kept up to date with security patches.
- Administrative access is performed only from trusted devices.
- No local servers or internal networks store customer or payment information.
7. Data Protection
- Ellicere does not store, process, or transmit cardholder data.
- Customer personal data (name, address, email) is stored securely within the e‑commerce platform.
- Backups of website configuration and product data are maintained securely by the hosting provider.
- Sensitive data is never shared via email or messaging platforms.
8. Payment Security
- All payment transactions are processed externally by certified third‑party payment service providers:
- Tpay
- PayU
- Google Pay
- Apple Pay
- BLIK
- PayPal
- Ellicere does not have access to full card numbers, CVV codes, expiration dates, or magnetic stripe data.
- No payment information is stored on Ellicere systems, devices, or networks.
9. Incident Response
Ellicere maintains an incident response approach that includes:
- Immediate investigation of any suspected security issue
- Communication with hosting provider or payment processors if needed
- Documentation of incidents and corrective actions
- Notification of affected parties when legally required
10. Vendor Management
Ellicere ensures that all third‑party service providers:
- Are reputable and trusted
- Maintain appropriate security controls
- Are compliant with PCI DSS when handling payment card data
11. Physical Security
- Ellicere does not operate physical offices or retail locations that store sensitive data.
- Devices used for business operations are protected against unauthorized access.
12. Policy Review
This policy is reviewed annually or whenever significant changes occur in:
- Business operations
- Technology infrastructure
- Legal or regulatory requirements
13. Compliance Statement
Ellicere confirms that:
- It does not store, process, or transmit cardholder data
- All payment processing is fully outsourced
- Its environment meets the requirements applicable to PCI DSS SAQ A
- This policy is maintained to support compliance and secure business operations.
End of Document

