Skip to content

📝 Information Security Policy ​

Purpose ​

This policy sets the requirements for protecting the confidentiality, integrity, and availability of Syslifters and customer information, and for meeting applicable law (primarily GDPR, as an Austrian controller).

Scope ​

This policy applies to all employees, contractors, and third parties who access or manage our information systems, networks, or data, whether stored digitally or physically.

Information Protection Principles ​

  • Confidentiality. Personal and sensitive data must be protected from unauthorized access, disclosure, or misuse.
  • Integrity. Information must be accurate, complete, and protected from unauthorized modification or destruction.
  • Availability. Information and systems must be accessible to authorized users as needed for business operations.

Customer data handling ​

  • Use only company-issued devices for Syslifters and customer work. Private use of those devices is not allowed.
  • Use Signal with disappearing messages for internal and project communication.
  • Do not put customer data into cloud AI unless the customer has explicitly allowed it. Use our self-hosted models (e.g., local_model_default) as the default.

Personal Information Protection ​

  • Collect, store, process, and transmit personal data only for a legitimate business purpose and in line with GDPR and other applicable law.
  • Keep only what is needed, and only for as long as it is needed.
  • We maintain our privacy policies and registers at Metasoul. Website processing is described in the Privacy notice.
  • Report any suspected or confirmed security or privacy incident immediately, following our incident response procedures.

Responsibilities ​

All employees must follow this policy and complete periodic information security and privacy training. Management oversees compliance, monitors controls, and updates the policy as needed.

Exceptions to this policy need written approval from a director before the work proceeds.

Policy Review ​

This policy will be reviewed annually or following significant organizational or regulatory changes.

Last reviewed: 03/09/2026