Explore Categories
0

Information security policy

Ellicere – Online Retail Business Version 1.0 – 2026

1. Purpose

The purpose of this Information Security Policy is to define the security principles, responsibilities, and controls implemented by Ellicere to protect its information assets, ensure secure operation of its online store, and comply with applicable requirements of the Payment Card Industry Data Security Standard (PCI DSS).

2. Scope

This policy applies to:

Ellicere does not store, process, or transmit cardholder data. All payment card information is handled exclusively by certified third‑party payment service providers.

3. Business Environment Overview

Ellicere operates as an online‑only retail business selling cosmetics and hand‑painted porcelain products. The company:

No cardholder data passes through or resides on Ellicere’s systems, devices, networks, or infrastructure.

4. Information Security Principles

Ellicere follows these core security principles:

5. Access Control

6. System Security

7. Data Protection

8. Payment Security

9. Incident Response

Ellicere maintains an incident response approach that includes:

10. Vendor Management

Ellicere ensures that all third‑party service providers:

11. Physical Security

12. Policy Review

This policy is reviewed annually or whenever significant changes occur in:

13. Compliance Statement

Ellicere confirms that:

End of Document