LIMITED TIME 🎁: Register now to get 60 minutes of AI Mock Interviewing for FREE!

Join
    Internal Policy

    Data Protection Policy

    Principles, controls, and operating procedures for protecting personal data

    Effective: March 21, 2026Last Reviewed: March 21, 2026
    Review Frequency: At least annually

    Privacy by Design

    Built-in

    Encryption

    In Transit & At Rest

    Auto-Deletion

    30-63 Days

    Compliance

    GDPR / US State

    1) Purpose

    This Data Protection Policy ("Policy") establishes the principles, controls, and operating procedures Screna Tech Inc. ("Company") uses to protect personal data processed through Screna.ai and related services.

    • Ensure privacy-by-design and security-by-design across the product lifecycle
    • Reduce risk of unauthorized access, disclosure, alteration, loss, or misuse of personal data
    • Support compliance with applicable privacy and security laws and contractual obligations
    • Define roles, responsibilities, and minimum operational standards

    2) Scope

    This Policy applies to:

    • All Company personnel (employees, contractors, interns) and temporary staff
    • All Company systems, networks, endpoints, cloud environments, and third-party services used to process Company data
    • All personal data processed in connection with the Service, including audio/video recordings, transcripts, AI-generated evaluations, account data, and payment/subscription metadata

    4) Roles and Responsibilities

    Data Protection Lead

    • Privacy governance & policy updates
    • DPIAs & vendor privacy reviews
    • DSR handling & ROPA maintenance

    Security Lead

    • Security controls & monitoring
    • Vulnerability management
    • Incident response execution

    Engineering

    • Privacy-by-design controls
    • Secure SDLC & access controls
    • Encryption & deletion workflows

    Support & Operations

    • User support & DSR escalation
    • Least-privilege access
    • Audit trails & secure workflows

    6) Data Categories and Classification

    ClassificationDescriptionExamples
    PublicApproved for public releaseMarketing materials, public documentation
    InternalNon-public business infoInternal policies, roadmaps
    ConfidentialPersonal data, security infoAccount data, transcripts, AI scores
    RestrictedHighest sensitivityRaw audio/video recordings, credentials

    Default rule: Raw audio/video recordings are classified as Restricted.

    9) Security Controls (Minimum Baseline)

    Access Controls

    • Role-based access control (RBAC) with least privilege
    • MFA required for all admin accounts and critical services
    • Quarterly access reviews for sensitive systems

    Encryption

    • Encrypt data in transit (TLS) and at rest (AES-256)
    • Restricted data uses strong encryption at rest
    • Secrets managed via dedicated secrets manager

    Logging & Monitoring

    • Log access to Restricted data (who/when/what)
    • Monitor for anomalous access patterns
    • Retain security logs for at least 30 days

    10) Data Retention and Deletion

    Audio/Video Recordings

    Until user deletes or 30 days

    Backups

    Expire within 63 days

    Account Deletion

    63 days max retention

    14) Incident Response and Breach Notification

    Reporting: All suspected incidents must be reported immediately to:

    andysim3d@gmail.com

    Response Steps:

    • Triage and contain
    • Preserve evidence
    • Assess scope and risk
    • Remediate and patch
    • Notify affected parties

    Timing:

    • GDPR: Notify regulators within 72 hours
    • Other jurisdictions: Without unreasonable delay

    16) Training and Awareness

    Mandatory onboarding training

    Annual refresher training

    Role-specific security training

    Appendix C — Minimum Security Controls for Audio/Video Recordings

    • Classified as Restricted
    • Stored with strict IAM policies
    • Access logged and monitored
    • No direct public URLs by default
    • Expiring signed URLs for playback
    • Optional watermarking for shares
    • Automated deletion workflows
    • Backup expiry enforcement

    Effective: March 21, 2026 | Last Reviewed: March 21, 2026