Data security

Data boundaries, access permissions, and protection requirements are part of how a project is designed and delivered.

ISO/IEC 27001 / Management framework

This security policy uses the ISO/IEC 27001 information security management framework as a reference. The controls, implementation status, and verification scope for a specific engagement are defined in the project documentation and agreement. This statement does not claim third-party ISO/IEC 27001 certification.

GDPR / Applicable data protection requirements

Where GDPR applies, processing design considers purpose limitation, data minimization, transparency, retention, and individual rights. Contracts define the roles and responsibilities of the customer and service providers.

Security controls and project responsibilities

Depending on the engagement, controls may include role-based access, encrypted transport, backup arrangements, operational logs, and incident handling. Deployment locations, suppliers, validation requirements, and service commitments are agreed within the project scope.

Security enquiries

Contact info@newgens.org to discuss security requirements or report a concern. Describe the issue without including credentials or unnecessary customer data.