Your data never stops being yours.

Handing over back-office operations means handing over payroll files, customer records and board documents. We treat that as the core of the engagement, not an appendix to it.

Data Protection Overview

Four principles that govern every engagement.

Least privilege, always

Operators receive the narrowest access that lets them do the job — a specific ledger, a specific queue, a specific folder. Nobody holds standing administrative rights on a client system, and no operator can see data belonging to another client.

Confidentiality in writing

Every ViralFlux employee signs a confidentiality undertaking on hire and a project-specific NDA before onboarding to your account. We countersign your own NDA and DPA where you have one — our templates are a floor, not a ceiling.

Encryption end to end

TLS 1.2+ for everything in transit and AES-256 at rest. Client documents stay in your storage environment wherever possible; where we must hold a working copy, it lives in an encrypted, client-segregated workspace.

Revocation in one business day

When an operator leaves your account or our company, access is revoked across every connected system within one business day, and the change is logged for your quarterly access review.

Role-Based Access Control

Who can see what — and how you verify it.

Access is provisioned under your identity provider, so the audit trail belongs to you rather than sitting in a vendor system you cannot query.

Provisioning
Accounts are created inside your own directory (Google Workspace, Microsoft Entra ID, Okta) with SSO and mandatory MFA. We do not use shared logins, and we do not ask for a password to an existing account — ever.
Role definitions
Each engagement defines named roles (e.g. AP Operator, HR Records, CRM Data) with an explicit permission list agreed in writing before handover. Scope changes require a documented request from your authorised contact.
Segregation of duties
Payment preparation and payment approval are never held by the same operator. We prepare; a named authoriser on your side releases. ViralFlux does not hold payment release authority on client bank accounts.
Device controls
Company-managed endpoints only: full-disk encryption, screen lock, endpoint protection, automatic patching and no removable-media write access. Personal devices are not permitted for client work.
Monitoring & review
Access lists are reviewed quarterly with your account owner and reconciled against active personnel. Anomalous access patterns are escalated to your named contact.
Offboarding
Immediate directory suspension on termination, credential rotation for any shared service, device wipe, and written confirmation to you within one business day.

Standards & Certifications

Where we stand today.

We publish our actual position rather than a wall of logos. If a control matters to your procurement team and it isn't listed here, ask us directly.

Readiness programme

ISO/IEC 27001

Our Information Security Management System is built to the ISO/IEC 27001:2022 control set, with documented policies, a risk register and annual internal review. We are operating an active readiness programme toward external certification and can share our Statement of Applicability and gap assessment under NDA.

Compliant

GDPR & Hong Kong PDPO

We act as a data processor under Article 28 GDPR and as a data user under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486). Standard Contractual Clauses are available for EU/EEA transfers, and we maintain records of processing activities per engagement. See our GDPR Statement.

In force

Data Processing Agreement

A DPA is executed with every client before any personal data is processed, defining scope, retention, sub-processors, breach notification timelines and deletion obligations at end of term.

In force

Encrypted communications

TLS 1.2+ in transit, AES-256 at rest, enforced MFA on every account, and no client data transmitted over consumer messaging or personal email under any circumstances.

Annual

Personnel vetting & training

Background and reference verification appropriate to role before account assignment, plus mandatory annual security and data-protection training with completion records available on request.

Tested

Business continuity

Every process has a named backup operator and a written runbook, so continuity does not depend on one individual. Continuity procedures are exercised at least annually.

Incident Response

If something goes wrong, you hear it from us first.

We maintain a documented incident response procedure with defined severity tiers and named owners. Any confirmed security incident affecting your data is reported to your named contact without undue delay and within 24 hours of confirmation, together with the facts known at that point, the containment steps taken and the remediation plan.

Where the incident constitutes a personal data breach, we support your notification obligations to supervisory authorities and data subjects within the GDPR's 72-hour window.

1. Detect & contain

Isolate affected accounts and systems; preserve evidence.

2. Notify

Named client contact informed within 24 hours of confirmation.

3. Investigate

Root-cause analysis with a written report to the client.

4. Remediate & review

Corrective controls implemented and verified at the next review.

For procurement & security teams

Running a vendor assessment?

We complete security questionnaires as standard and can provide our security policy set, Statement of Applicability, DPA template and sub-processor list under NDA. Ask for the due-diligence pack.