Information security policy
Cyber Essentials certified and ICO registered. This policy sets out how we protect the information entrusted to us.
Last updated 18 September 2025
1. Purpose
The purpose of this policy is to establish Logisam’s approach to information security and data protection. It sets out how Logisam safeguards client data, ensures compliance with UK Data Protection Act 2018, UK GDPR, and industry standards, and prevents unauthorised access, loss, or misuse of information.
2. Scope
This policy applies to all Logisam employees, contractors, partners, and third parties who have authorised access to Logisam’s systems and services, including all solutions developed and provided by Logisam (e.g., LegalCase365, HR365, FixIT365, TimeSheet365, and Licences365).
3. Policy Statement
Logisam is committed to:
Maintaining the confidentiality, integrity, and availability of client data.
Using client data strictly for the purposes agreed in contracts and service agreements.
Avoiding any transfer, replication, or storage of client data outside of the client’s own Microsoft 365 tenant unless explicitly agreed in writing.
Ensuring compliance with applicable legislation, contractual obligations, and international information security standards.
4. Data Handling and Use
Client data will only be accessed for the provision of contracted services and with appropriate authorisation.
No client data will be copied, shared, or disclosed to unauthorised parties.
Personal data will be processed only in accordance with the client’s documented instructions.
All data in transit and at rest will be encrypted using industry-standard protocols.
5. Data Residency and Transfer
Client data remains within the client’s Microsoft 365 tenant by default.
Logisam will not export or transfer client data outside of the client environment.
Any exceptional requirement for data transfer (e.g., legal obligation) will only be undertaken with prior written approval from the client and in compliance with UK GDPR.
6. Access Control
Access to client data is restricted based on the principle of least privilege.
Authentication is managed through Microsoft Entra ID (Azure Active Directory) with support for multi-factor authentication (MFA).
Administrative access is logged, monitored, and regularly reviewed.
7. Incident Management
All staff must immediately report any suspected data breach or security incident.
Logisam will notify the client and, where applicable, the Information Commissioner’s Office (ICO) within statutory timeframes.
An incident response plan is maintained and tested regularly.
8. Roles and Responsibilities
Information Security Officer (ISO): Responsible for policy implementation and security governance.
Data Protection Officer (DPO): Ensures compliance with data protection laws and acts as the point of contact for clients and regulators.
All Employees and Contractors: Must comply with this policy and complete mandatory information security training.
9. Compliance and Review
Logisam aligns its practices with ISO 27001, Cyber Essentials Plus, and Microsoft’s compliance frameworks.
This policy will be reviewed annually or when significant changes occur in legislation, regulations, or business practices.
10. Enforcement
Failure to comply with this policy may result in disciplinary action, up to and including termination of employment or contract.
