Security & Data Protection

Last updated: 2026. 07. 18.
Legal

I. Purpose and Scope of the Policy

This Security Policy (“Policy”) describes the advanced technical and organizational measures applied by Smairthub (“Service Provider”) to ensure the confidentiality, integrity, and continuous availability of data processed on the Platform.

This Policy applies to the Smairthub core framework and general IT infrastructure, and complements the Privacy Policy and the Data Processing Agreement (DPA). The specific technical security and data protection characteristics of individual functional components (“Modules”) are defined in the Annexes to this Policy.

II. Security Principles

The Service Provider operates its systems according to the following principles:

  • Confidentiality: Data is accessible only to strictly authorized users and processes.
  • Integrity: Data is protected against unauthorized, accidental, or malicious modification.
  • Availability: The Platform aims for high business continuity and reliable uptime.
  • Data Minimization and Isolation: Only data essential for service delivery is processed, in logically isolated environments.

III. Technical Security Measures

1. Encryption

  • Transport Encryption: Mandatory full HTTPS/TLS encryption for all network communication and client–server data exchange.
  • Server-side Encryption: Appropriate server-side protection mechanisms for temporarily stored data and records.

2. Access Control and Permissions

  • Role-based access control (RBAC) for internal systems.
  • Strictly limited and audited administrator access to the production environment.
  • Multi-step internal authentication for infrastructure management interfaces.

3. Infrastructure and Network Security

  • Advanced firewall protection and network-level traffic filtering.
  • Automated intrusion detection and prevention systems (IDS/IPS).
  • Regular vulnerability assessments and baseline security updates.
  • Use of secure, internationally certified cloud infrastructure.

4. Data Isolation and Sandbox Execution

User data is processed in fully isolated logical environments. Module execution and computational tasks run in closed sandbox environments, ensuring that no other user can access the data.

5. Logging and Monitoring

  • Detailed audit logs for critical security and balance-related operations.
  • 24/7 monitoring of system performance, load, and anomalies.
  • Automated alerting systems for suspicious activity or cybersecurity events.

6. Abuse Protection (Bot Protection)

To protect the Platform infrastructure and User accounts from unauthorized access, automated attacks, and bot activity, the Service Provider uses Cloudflare Turnstile.

This technology analyzes technical interaction data (IP address, browser data, device fingerprint) to verify human presence without invasive data collection. Processing is strictly limited to maintaining Platform integrity and does not involve long-term tracking or profiling.

IV. Organizational Security Measures

1. Internal Confidentiality

All personnel or partners who may access the infrastructure for technical reasons are bound by strict written confidentiality obligations and are trained in applicable data protection policies.

2. Incident Management

The Service Provider maintains a dedicated incident management procedure for rapid detection, isolation, and mitigation of security events. In case of an incident involving personal or critical data, affected partners are notified without delay in accordance with applicable laws and the DPA.

3. Change Management

Software updates, configuration changes, and the introduction of new functional components follow a controlled, tested, and documented change management process to minimize production downtime.

V. Business Continuity and Availability

  • Redundant infrastructure components to ensure high availability.
  • Regular backups of critical system components and configurations (excluding temporary user-uploaded data files).
  • Maintenance of disaster recovery procedures.

VI. User Security Responsibilities

The User is solely responsible for the secure handling of account-related identifiers (email access, OTP codes). The User must ensure that uploaded data originates from lawful sources and is free of viruses or malicious code.

VII. Policy Modifications

The Service Provider may modify this Policy unilaterally. Users will be notified of changes via the Platform interface or email.

Annex 1 – Spreadsheet AI Module Technical Security Terms

Integral part of the Security Policy

1. Data Minimization and AI Security

During operation of the Spreadsheet AI module, the full uploaded dataset is never transferred to the third-party AI provider. To ensure data security and minimization, the AI receives only:

  • the technical structure of the table (column names, metadata),
  • field data types (e.g., text, number, date),
  • a limited number of randomly selected sample rows.

Enterprise-grade API connections (OpenAI Ireland Ltd. / Azure OpenAI Enterprise) guarantee that transferred samples are not stored long-term and are not used for model training.

2. Strict Retention and Deletion Cycle

All CSV, XLS, and XLSX files processed by the module, along with temporary database records generated from them, are automatically and permanently deleted within 12 hours of upload.

Deletion constitutes physical destruction within the server environment and is irreversible. No backups of these data are created as part of business continuity procedures.

Annex 2 – Social Factory AI Module Technical Security Terms

Integral part of the Security Policy

1. Data Minimization and AI Security

During operation of the Social Factory AI module, the full uploaded or generated content (text, avatar image, audio, video) is never transferred as a complete dataset to third-party AI providers. To ensure data minimization, the AI receives only:

  • script or narration text,
  • uploaded or generated avatar image,
  • text required for voice generation,
  • audio file required for lip-sync.

Enterprise-grade API connections used by OpenAI, ElevenLabs, fal.ai and Sonilo guarantee that transferred data is not stored long-term and is not used for model training.

2. Temporary Storage and Automatic Deletion

Images, audio files, and videos generated by the module are stored for a maximum of 7 days. After this period, all content is automatically, permanently, and irreversibly deleted.

Deletion constitutes physical destruction within the server environment. No backups of generated content are created.

3. Sandbox and Isolated Execution

Video and audio generation processes run in closed, isolated sandbox environments, ensuring complete separation of User content.

4. Abuse Protection

The module automatically blocks attempts to generate prohibited content (e.g., deepfake impersonation, political campaigning, sexual content involving minors, hate speech). Such attempts are logged for security purposes.

5. User Responsibility

The User must ensure that uploaded avatar images, text, and other content are lawful and do not infringe third-party rights.

Long-term storage of generated videos is the User’s responsibility, as the system deletes them automatically after the 7-day retention period.

Security & Data Protection - SmairtHub