Security Policy
Last updated: September 7, 2025
Duburuo is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we take to safeguard information, the responsibilities of users, and the procedures we follow in the event of a security incident.
1. Scope
This policy applies to all systems, services, and infrastructure operated by Duburuo, including the website at duburuo.com, associated web applications, and any data processed through our platform. It applies to all users, staff, contractors, and third parties who interact with our services.
2. Data Protection and Storage
All data collected through our platform is stored using industry-standard security practices. We apply appropriate technical and organisational measures to protect personal and sensitive data against unauthorised access, loss, destruction, or alteration.
2.1 Encryption
Data transmitted between your browser and our servers is protected using Transport Layer Security (TLS). Sensitive data stored on our systems is encrypted at rest using recognised encryption standards.
2.2 Access Controls
Access to data and internal systems is restricted on a need-to-know basis. We enforce strong authentication requirements for all internal accounts and review access privileges regularly. Privileged access is logged and monitored.
2.3 Data Minimisation
We collect only the data necessary to provide our services. Data that is no longer required is securely deleted or anonymised in accordance with our data retention practices.
3. Infrastructure Security
Our infrastructure is hosted with reputable service providers that maintain recognised security certifications. We apply security hardening to all server configurations and keep systems updated with security patches in a timely manner.
3.1 Network Security
We use firewalls, intrusion detection systems, and network segmentation to reduce the risk of unauthorised access. Traffic to and from our systems is monitored for anomalous activity.
3.2 Availability and Resilience
We maintain backup procedures and disaster recovery plans to ensure continuity of service. Critical data is backed up regularly, and backups are tested periodically to verify integrity and restorability.
4. Application Security
Security is considered throughout the development lifecycle of our platform. We apply secure coding practices, conduct code reviews, and test for common vulnerabilities including those listed in widely recognised security frameworks such as the OWASP Top Ten.
4.1 Vulnerability Management
We conduct periodic security assessments and vulnerability scans of our systems. Identified vulnerabilities are prioritised and remediated based on their severity and potential impact.
4.2 Third-Party Dependencies
We monitor third-party libraries and components used in our platform for known security vulnerabilities and apply updates as needed.
5. User Account Security
Users are responsible for maintaining the security of their account credentials. We recommend using a strong, unique password for your Duburuo account and enabling any additional authentication options made available on the platform.
You must not share your login credentials with others. If you suspect your account has been compromised, you should change your password immediately and contact us at support@duburuo.com.
6. Incident Response
We maintain an incident response process to detect, contain, and recover from security events in a timely manner. In the event of a confirmed security incident that affects user data, we will notify affected users and relevant authorities as required, without undue delay.
6.1 Reporting a Security Concern
If you discover a potential security vulnerability or have concerns about the security of our platform, we encourage you to report it to us responsibly. Please contact us at support@duburuo.com with a description of the issue. We will investigate all reports and respond as promptly as possible.
We ask that you do not publicly disclose any potential vulnerability before we have had a reasonable opportunity to investigate and address it.
7. Third-Party Services
We may use third-party services to support the operation of our platform, including payment processors, analytics providers, and hosting infrastructure. These providers are selected with regard to their security practices and are bound by appropriate data processing agreements where applicable. We are not responsible for the security practices of external websites or services linked from our platform.
8. Employee and Contractor Responsibilities
All individuals with access to our systems and data are required to follow this policy and any associated internal security guidelines. Security awareness is part of onboarding and is reinforced on an ongoing basis. Any individual who becomes aware of a security concern is required to report it promptly through internal channels.
9. Physical Security
Access to physical locations where sensitive systems or data are processed is restricted to authorised personnel. We rely on our hosting providers to maintain appropriate physical security controls for data centre environments.
10. Cookies and Tracking Technologies
Our use of cookies and similar technologies is described in our Cookie Policy. From a security perspective, session cookies are protected with appropriate flags to reduce the risk of interception or misuse.
11. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. The date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically. Continued use of our services following any update constitutes acceptance of the revised policy.
12. Contact
If you have any questions about this Security Policy or our security practices, please contact us:
Duburuo
31 Duffry Gate, Enniscorthy, Co. Wexford, Y21 D370, Ireland
Email: support@duburuo.com
Phone: +353 65 707 4014