+61 2 6271 8888 fegelo@hotmail.com
Fegelo
Fegelo
Floral Design Education

Security Policy

Last Updated: May 8, 2025

Introduction

Fegelo is committed to protecting the security and integrity of your personal information and data. This Security Policy outlines the measures we implement to safeguard information collected through our platform and services.

Information Security Framework

We maintain a comprehensive information security program designed to protect against unauthorized access, disclosure, alteration, and destruction of data. Our security framework is built on industry-standard practices and continuously evolves to address emerging threats.

Data Protection Measures

Technical Safeguards

We employ multiple layers of technical security controls to protect your information:

  • Encryption of data in transit using industry-standard protocols
  • Encryption of sensitive data at rest
  • Secure authentication mechanisms and password protection
  • Regular security monitoring and intrusion detection systems
  • Firewall protection and network segmentation
  • Automated backup systems with secure storage
  • Regular security patches and system updates

Administrative Safeguards

Our organizational security practices include:

  • Access controls limiting data access to authorized personnel only
  • Employee security training and awareness programs
  • Background checks for personnel with access to sensitive data
  • Defined security policies and procedures
  • Regular security audits and assessments
  • Incident response and breach notification procedures
  • Vendor security assessments for third-party service providers

Physical Safeguards

Physical security measures protect our infrastructure and data centers:

  • Restricted access to facilities housing servers and equipment
  • Surveillance and monitoring systems
  • Environmental controls to protect against physical damage
  • Secure disposal procedures for hardware and storage media

Account Security

User Responsibilities

You play a critical role in protecting your account. We recommend the following practices:

  • Create strong, unique passwords combining letters, numbers, and symbols
  • Never share your password or login credentials with others
  • Log out of your account when using shared or public devices
  • Enable multi-factor authentication if available
  • Monitor your account for unauthorized activity
  • Report suspicious activity immediately
  • Keep your contact information current for security notifications

Password Security

Passwords are stored using secure hashing algorithms. We never store passwords in plain text and cannot retrieve your password if forgotten. Password reset procedures require verification of account ownership through registered email addresses.

Data Transmission Security

All data transmitted between your device and our servers is encrypted using Transport Layer Security protocols. We regularly review and update our encryption standards to maintain the highest level of protection.

Third-Party Services

We carefully select third-party service providers and require them to maintain security standards consistent with this policy. However, we cannot guarantee the security practices of external websites or services linked from our platform. Users should review the security policies of any third-party services they access.

Payment Security

Payment information is processed through secure, certified payment processors. We do not store complete payment card information on our servers. All payment transactions are encrypted and comply with relevant payment card industry standards.

Security Incident Response

Monitoring and Detection

We maintain continuous monitoring systems to detect potential security incidents, including:

  • Automated threat detection and alerting
  • Log analysis and anomaly detection
  • Regular vulnerability scanning
  • Penetration testing conducted by qualified security professionals

Incident Management

In the event of a security incident, we follow established procedures to:

  • Contain and mitigate the incident
  • Investigate the cause and scope of the breach
  • Notify affected users in accordance with applicable laws
  • Implement corrective measures to prevent recurrence
  • Document and review the incident for continuous improvement

Data Retention and Disposal

We retain data only as long as necessary to provide services and comply with legal obligations. When data is no longer needed, we securely delete or anonymize it using industry-standard methods to prevent unauthorized recovery.

Employee Access and Training

Access to user data is restricted to employees who require it to perform their job functions. All employees with data access receive regular security training covering:

  • Data protection principles and best practices
  • Recognition of security threats including phishing and social engineering
  • Incident reporting procedures
  • Compliance with security policies
  • Confidentiality obligations

Vulnerability Management

We maintain an active vulnerability management program that includes:

  • Regular security assessments and code reviews
  • Timely application of security patches
  • Coordinated disclosure process for reported vulnerabilities
  • Testing of security controls and incident response procedures

Compliance and Certifications

Our security practices are designed to comply with applicable laws and industry standards. We regularly review our security program to ensure alignment with evolving regulatory requirements and best practices.

Reporting Security Concerns

If you discover a security vulnerability or have concerns about the security of our platform, please report it immediately to our security team at support@Fegelo.com. We take all security reports seriously and will investigate promptly.

When reporting security issues, please provide:

  • Detailed description of the vulnerability or concern
  • Steps to reproduce the issue if applicable
  • Potential impact of the vulnerability
  • Your contact information for follow-up

Limitations

While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of data transmitted over the internet or stored on our systems. Users acknowledge that they provide information at their own risk.

Updates to This Policy

We may update this Security Policy periodically to reflect changes in our practices, technology, or legal requirements. The date of the most recent revision is indicated at the top of this document. Continued use of our services after changes constitutes acceptance of the updated policy.

Contact Information

For questions or concerns regarding this Security Policy, please contact us:

Fegelo
Emanuel Pl, Conder ACT 2906, Australia
Email: fegelo@hotmail.com
Phone: +61262718888