1. Security governance
Security responsibilities are assigned based on role, access is limited to business need, and service providers are selected and contracted with regard to confidentiality, privacy and security requirements.
2. Safeguards
- Access controls, strong authentication and least-privilege practices.
- Encryption, masking or equivalent protection where appropriate.
- Secure configuration, patching, anti-malware and vulnerability management.
- Logging, monitoring, review and retention of relevant security records.
- Backups, continuity measures and recovery testing.
- Confidentiality commitments, staff awareness and incident escalation.
- Contractual controls for processors and technology vendors.
3. Incident response
Suspected incidents are assessed, contained, investigated, documented and remediated. Where a personal data breach is likely to affect individuals or notification is required, we will communicate with affected persons and relevant authorities in the form and timeframe required by applicable law.
4. User responsibilities
Users should keep devices and browsers updated, avoid sending sensitive information through unsecured channels, verify payment instructions and report suspicious activity promptly.
5. Security reports
Report a suspected vulnerability or data incident to business@lilyinasia.com with the subject “Security Incident”. Do not include exploited personal data or publicly disclose details before coordinated remediation.