Security Policy

Effective Date: 26 May 2025

1. Purpose

Wilkos Marine is committed to maintaining the highest standards of security and privacy for our customers. This Security Policy outlines the protocols and practices we implement to safeguard personal data, secure transactions, and protect our web infrastructure.

2. Scope

This policy applies to all users of the Wilkos Marine web store, including customers, employees, contractors, and third-party service providers who handle or access data and systems.

3. Data Protection & Privacy

3.1 Compliance

We comply with the Privacy Act 1988 and the Australian Privacy Principles (APPs).

3.2 Data Collection

We collect personal data such as names, email addresses, shipping details, and order history. Payment details are processed securely through compliant third-party services and are not stored on our servers.

3.3 Data Storage and Retention

Data is stored securely using encrypted systems within Australia or equivalent jurisdictions, and retained only as long as necessary.

4. Payment and Transaction Security

All transactions are encrypted via SSL (HTTPS). We partner with PCI DSS-compliant payment providers such as Stripe and PayPal. Credit card numbers and CVV codes are never stored.

5. Access Control

Access to administrative systems is restricted to authorised staff and protected with Multi-Factor Authentication (MFA). We implement role-based access to minimise exposure of sensitive data.

6. Website and Infrastructure Security

6.1 Hosting

Our site is hosted on secure platforms with firewalls, DDoS protection, and 24/7 monitoring.

6.2 Software Updates

We regularly update all software and plugins to mitigate vulnerabilities.

6.3 Secure Coding

We follow OWASP Top 10 best practices and review all custom code for security risks.

7. Monitoring and Logging

We use logging and monitoring tools to detect suspicious activity. Audit logs are retained and reviewed periodically.

8. Incident Response

We maintain an Incident Response Plan to manage any breaches. We comply with the Notifiable Data Breaches (NDB) scheme and will notify affected customers as required.

9. Employee Training

Staff receive regular training on data security, phishing awareness, and best practices for handling customer data.

10. Third-Party Vendors

We evaluate the security standards of all third-party providers before engagement. Data sharing is governed by strict contractual agreements.

11. Policy Review

This policy is reviewed annually and whenever significant system or regulatory changes occur. Customers will be notified of major updates.