Last updated: October 18, 2024
RitzyNord (“we,” “our,” or “us”) is committed to protecting the security, integrity, and confidentiality of personal information across all regions in which we operate. This Security Policy outlines the technical and organizational measures we implement to safeguard data and ensure secure transactions on our platform.
1. Information Security Framework
We implement appropriate technical and organizational measures (TOMs) designed to protect personal data against unauthorized access, loss, misuse, disclosure, alteration, or destruction. These measures are aligned with internationally recognized security standards and best practices.
2. Encryption and Secure Transmission
All data transmitted between users and our platform is encrypted using Secure Socket Layer (SSL) or Transport Layer Security (TLS) protocols. This ensures secure communication and protects sensitive information from interception.
3. Payment Security and PCI-DSS Compliance
RitzyNord utilizes third-party payment processors that adhere to PCI-DSS (Payment Card Industry Data Security Standard) requirements.
- We do not store full payment card details on our servers
- Payment data is processed through secure, certified gateways
- Transactions are monitored for potential fraud and unauthorized activity
4. Data Protection and Privacy Compliance
We process personal data in accordance with applicable global data protection laws, including but not limited to:
- General Data Protection Regulation (GDPR) – European Economic Area (EEA)
- UK GDPR & Data Protection Act 2018 – United Kingdom
- California Consumer Privacy Act (CCPA/CPRA) – United States
- Information Technology Act, 2000 – India and applicable rules
- Personal Information Protection and Electronic Documents Act (PIPEDA) – Canada
- Privacy Act 1988 – Australia Lei Geral de Proteção de Dados (LGPD) – Brazil
- Personal Data Protection Act (PDPA) – Singapore and other applicable jurisdictions
We are committed to ensuring that personal data is handled lawfully, transparently, and securely across all regions in which we operate. Depending on your jurisdiction, you may have rights including access, correction, deletion, restriction, or objection to the processing of your personal data.
5. Data Minimization and Retention
We adhere to the principles of data minimization and purpose limitation:
- Personal data is collected only for specified, legitimate purposes
- Data is retained only for as long as necessary to fulfill those purposes or comply with legal obligations
- Data is securely deleted or anonymized when no longer required
6. Access Controls and Confidentiality
Access to personal data is restricted to authorized personnel and service providers on a need-to-know basis. All individuals with access to such data are bound by confidentiality obligations and are required to follow strict data protection practices.
7. International Data Transfers
Where personal data is transferred across borders, RitzyNord ensures that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs)
- Data processing agreements with third-party providers
- Transfers to jurisdictions deemed to provide an adequate level of data protection
8. Third-Party Service Providers
We engage trusted third-party service providers (including payment processors, hosting providers, and logistics partners) who maintain appropriate security standards. However, RitzyNord does not control and is not responsible for the independent security practices of such third parties.
9. Fraud Prevention and Monitoring
We employ automated systems and manual reviews to detect, prevent, and respond to fraudulent or unauthorized transactions. RitzyNord reserves the right to suspend, cancel, or verify orders where suspicious activity is identified.
10. Incident Response and Breach Notification
In the event of a data breach or security incident:
- We will take immediate steps to contain and mitigate the impact
- Investigate the root cause and implement corrective measures
- Notify affected users and relevant regulatory authorities where required by applicable law
11. User Responsibilities
Users are responsible for maintaining the confidentiality of their account credentials. RitzyNord shall not be liable for unauthorized access resulting from failure to protect login information.
Users should immediately report any suspected unauthorized use of their account.
12. Children’s Data Protection
RitzyNord does not knowingly collect personal data from children under the age required by applicable laws (e.g., 13 or 16 depending on jurisdiction). If such data is identified, it will be promptly deleted.
13. Continuous Security Improvements
We regularly review, audit, and enhance our security practices to align with evolving regulatory requirements, industry standards, and emerging threats.
14. Policy Updates
This Security Policy may be updated periodically to reflect changes in legal, technical, or operational requirements. The updated version will be posted on this page with a revised effective date.
15. Contact Information
For any questions, concerns, or to exercise your data protection rights, please contact:
Email: support@ritzynord.com
