Your clients trust you with their information; you trust us with yours. This page describes how BuyerIntentSystem protects customer data and the lead data processed through the Serious Buyer System™. It supplements our Privacy Policy and forms the basis of the security annex in our Data Processing Agreement.
🔐 Encryption
TLS 1.2+ in transit; encryption at rest via our cloud providers.
👤 Least privilege
Role-based access, MFA on all admin accounts, prompt revocation.
🏢 Vetted infrastructure
Certified cloud providers (ISO 27001 / SOC 2) — we don't run our own servers.
🚨 Incident response
Documented process; customer notification within forty-eight (48) hours of a confirmed breach.
1. Security Governance
- Security is owned by the Founder, acting as designated Security Lead, who is responsible for this program, vendor review, and incident response.
- All personnel and contractors sign confidentiality agreements before receiving any access to customer data.
- Security and privacy practices are reviewed at least annually and after any significant incident or change to the Services.
2. Data Classification & Minimization
- Customer data (your account, billing, and engagement information) and lead data (data your leads submit through the system) are treated as confidential.
- Our intake forms and scoring tools collect only the fields needed to score buyer intent — name, contact details, budget, timeline, financing status, and preferences. We do not request sensitive-category data (health, government IDs, precise financial account data).
- Card payment data is handled entirely by Stripe and Razorpay (PCI DSS certified); we never store full card numbers.
3. Access Control
- Unique named accounts for every person; no shared credentials.
- Multi-factor authentication is enforced on administrative accounts and all provider consoles (hosting, email, CRM, payments).
- Access follows least privilege: personnel see only the customer data required for their work.
- Access is reviewed periodically and revoked within twenty-four (24) hours when a person's role ends or changes.
4. Infrastructure & Application Security
- The Services run on established, independently certified cloud platforms holding independent certifications such as ISO 27001 and SOC 2. Physical security, network security, and hardware lifecycle are managed by those providers.
- All web traffic is served over HTTPS (TLS 1.2+); HTTP requests are redirected to HTTPS.
- Data at rest is encrypted using provider-managed encryption (AES-256).
- Customer data is logically separated per customer within our tools and storage.
- Software dependencies and platform components are kept up to date; provider security advisories are monitored.
5. Endpoint & Operational Security
- Work devices use full-disk encryption, automatic screen locks, and up-to-date operating systems.
- Company accounts use a password manager and strong unique passwords.
- Customer data is not stored on personal devices or removable media except transiently and encrypted where operationally unavoidable.
6. Vendor & Sub-processor Management
- We review each vendor's security posture and data-protection terms before use.
- Vendors that process personal data on our customers' behalf are bound by data-processing terms and listed in Annex 3 of our DPA.
- Customers are notified of sub-processor changes per the DPA (fourteen (14) days' advance notice).
7. Backups & Continuity
- Data stored in our cloud tools is backed up through provider-managed redundancy and backup features.
- Recovery procedures are documented; in a regional provider outage, service is restored per the providers' published recovery objectives.
- Deleted customer data leaves backup rotations within ninety (90) days.
8. Incident Response
- We maintain a documented incident-response process: detect → contain → assess → notify → remediate → post-incident review.
- Customers affected by a confirmed personal-data breach are notified without undue delay and within forty-eight (48) hours of our becoming aware, with the details required for their own regulatory notifications (see DPA §8).
- We cooperate with affected customers and, where applicable, regulators (e.g., supervisory authorities under GDPR, the Data Protection Board of India).
9. Privacy Compliance
- We support GDPR/UK GDPR, CCPA/CPRA, and India DPDP Act obligations — see our Privacy Policy and DPA.
- Data subject requests forwarded by customers are actioned within the timelines in the DPA.
- Data retention and deletion follow the schedules published in our Privacy Policy and DPA.
10. Reporting a Vulnerability
If you believe you've found a security vulnerability in our website or tools, please email buyerintentsystem@gmail.com with details and steps to reproduce. We ask that you:
- Give us reasonable time to investigate and fix before public disclosure;
- Avoid accessing, modifying, or deleting data that isn't yours;
- Not run automated scans or denial-of-service tests against our systems.
We will acknowledge reports within three (3) business days and won't pursue action against good-faith research conducted within these guidelines.
Questions
Security questionnaires, audit requests (per DPA §10), and any other questions: buyerintentsystem@gmail.com.