Data Protection Policy
Principles, controls, and operating procedures for protecting personal data
Privacy by Design
Built-in
Encryption
In Transit & At Rest
Auto-Deletion
30-63 Days
Compliance
GDPR / US State
1) Purpose
This Data Protection Policy ("Policy") establishes the principles, controls, and operating procedures Screna Tech Inc. ("Company") uses to protect personal data processed through Screna.ai and related services.
- Ensure privacy-by-design and security-by-design across the product lifecycle
- Reduce risk of unauthorized access, disclosure, alteration, loss, or misuse of personal data
- Support compliance with applicable privacy and security laws and contractual obligations
- Define roles, responsibilities, and minimum operational standards
2) Scope
This Policy applies to:
- All Company personnel (employees, contractors, interns) and temporary staff
- All Company systems, networks, endpoints, cloud environments, and third-party services used to process Company data
- All personal data processed in connection with the Service, including audio/video recordings, transcripts, AI-generated evaluations, account data, and payment/subscription metadata
4) Roles and Responsibilities
Data Protection Lead
- Privacy governance & policy updates
- DPIAs & vendor privacy reviews
- DSR handling & ROPA maintenance
Security Lead
- Security controls & monitoring
- Vulnerability management
- Incident response execution
Engineering
- Privacy-by-design controls
- Secure SDLC & access controls
- Encryption & deletion workflows
Support & Operations
- User support & DSR escalation
- Least-privilege access
- Audit trails & secure workflows
6) Data Categories and Classification
| Classification | Description | Examples |
|---|---|---|
| Public | Approved for public release | Marketing materials, public documentation |
| Internal | Non-public business info | Internal policies, roadmaps |
| Confidential | Personal data, security info | Account data, transcripts, AI scores |
| Restricted | Highest sensitivity | Raw audio/video recordings, credentials |
Default rule: Raw audio/video recordings are classified as Restricted.
9) Security Controls (Minimum Baseline)
Access Controls
- Role-based access control (RBAC) with least privilege
- MFA required for all admin accounts and critical services
- Quarterly access reviews for sensitive systems
Encryption
- Encrypt data in transit (TLS) and at rest (AES-256)
- Restricted data uses strong encryption at rest
- Secrets managed via dedicated secrets manager
Logging & Monitoring
- Log access to Restricted data (who/when/what)
- Monitor for anomalous access patterns
- Retain security logs for at least 30 days
10) Data Retention and Deletion
Audio/Video Recordings
Until user deletes or 30 days
Backups
Expire within 63 days
Account Deletion
63 days max retention
14) Incident Response and Breach Notification
Reporting: All suspected incidents must be reported immediately to:
andysim3d@gmail.com
Response Steps:
- Triage and contain
- Preserve evidence
- Assess scope and risk
- Remediate and patch
- Notify affected parties
Timing:
- GDPR: Notify regulators within 72 hours
- Other jurisdictions: Without unreasonable delay
16) Training and Awareness
Mandatory onboarding training
Annual refresher training
Role-specific security training
Appendix C — Minimum Security Controls for Audio/Video Recordings
- Classified as Restricted
- Stored with strict IAM policies
- Access logged and monitored
- No direct public URLs by default
- Expiring signed URLs for playback
- Optional watermarking for shares
- Automated deletion workflows
- Backup expiry enforcement
Effective: March 21, 2026 | Last Reviewed: March 21, 2026