Cart 0 x

Information Security Policy

Effective: November 15, 2025

1. Introduction

Didii Management Ltd. (“Didii”, “we”, “our”, or “the Company”) is committed to protecting the confidentiality, integrity, and availability of information systems and customer data used on the Didii website.

This Information Security Policy outlines the procedures and safeguards implemented to protect sensitive information, ensure compliance with payment card industry standards, and maintain secure online services.

This policy applies to:

  • – The Didii website and related digital infrastructure

  • – Employees, contractors, and service providers with access to company systems

  • – Any systems used to store, transmit, or process customer information

– The policy is reviewed annually and updated as necessary.


2. Security Commitment

Didii Management Ltd. is committed to:

  1. Protecting customer privacy and personal information
  2. Maintaining secure systems and network infrastructure
  3. Preventing unauthorized access to company data
  4. Complying with applicable data protection and payment security standards
  5. Ensuring the secure processing of payment card transactions

All individuals with access to company systems share responsibility for maintaining information security.


3. Payment and Cardholder Data Security

Didii Management Ltd. does not store, process, or retain payment card information on its own servers.

All credit card transactions conducted through the Didii website are securely processed through a certified third-party payment processor and gateway provider.

Security measures include:

  1. Redirection to secure payment environments hosted by the payment processor
  2. Encrypted payment transmission using industry-standard protocols (TLS/HTTPS)
  3. Compliance with Payment Card Industry Data Security Standards (PCI DSS) by the payment provider
  4. No storage of sensitive authentication data such as:

– Full card numbers (PAN), CVV codes, PIN data, Magnetic stripe data


4. Network Security

Didii maintains secure systems and network infrastructure to protect its website and internal services.

Security practices include:

  • – Secure hosting environments

  • – Firewall and network protection controls

  • – Regular vulnerability monitoring and security updates

  • – Malware protection and intrusion prevention measures

  • – Secure system configuration and patch management

Where applicable, vulnerability scans may be performed periodically to identify and remediate security risks.


5. Data Protection and Storage

Didii takes reasonable steps to protect stored information from unauthorized access or disclosure.

Security controls include:

  • – Secure hosting infrastructure

  • – Access controls and authentication

  • – Encryption where appropriate

  • – Limited data retention policies

  • – Regular system updates and security monitoring

Customer data is stored only where necessary for legitimate business operations such as order fulfillment, customer support, and account management.


6. Data Classification

Information handled by Didii may be classified into the following categories:

Confidential Information

  • Customer personal information

  • Business operational data

  • Authentication credentials

  • Payment transaction references

Internal Information

  • Internal procedures and documentation

  • Operational business data

Public Information

  • Website content

  • Public product listings

  • Marketing materials

Access to confidential information is restricted to authorized personnel only.


7. Access Control

Access to company systems and sensitive information is limited based on job responsibilities and operational necessity.

Security measures include:

  • Unique user accounts for system access

  • Strong password requirements

  • Role-based access control

  • Secure authentication procedures

  • Revocation of access when employment or contracts end

Administrative access to website infrastructure is restricted to authorized personnel only.


8. Acceptable Use of Systems

Individuals with access to company systems must use them responsibly and only for authorized business purposes.

Users must:

  • Maintain password confidentiality

  • Protect sensitive information

  • Avoid installing unauthorized software

  • Avoid transmitting sensitive information through unsecured channels

  • Immediately report suspected security issues

Unauthorized or illegal use of company systems is strictly prohibited.


9. Physical Security

Where applicable, Didii implements physical safeguards to protect systems and information assets.

Security practices include:

  • Controlled access to workspaces and equipment

  • Secure storage of physical records

  • Protection of devices used to access company systems

Employees must ensure that devices containing company information are not left unattended or accessible to unauthorized individuals.


10. Data Transmission Security

Sensitive information transmitted electronically must be protected using secure communication protocols.

Security controls include:

  • HTTPS encryption for website communications

  • Secure transmission channels for administrative access

  • Prohibition of sending cardholder data via email or messaging systems


11. Data Retention and Disposal

Data is retained only as long as necessary for business or legal requirements.

When data is no longer required, it will be securely destroyed using appropriate methods including:

  • Secure deletion of electronic data

  • Shredding or destruction of physical documents

These procedures ensure that confidential information cannot be reconstructed or recovered.


12. Security Awareness

Didii promotes information security awareness among employees and contractors.

Security practices include:

  • Employee awareness of data protection responsibilities

  • Training or guidance on secure system usage

  • Internal procedures for identifying and reporting security threats


13. Security Incident Response

Didii maintains procedures for responding to security incidents involving systems or data.

In the event of a suspected breach:

  1. The incident must be reported immediately to management.

  2. Systems involved may be isolated to prevent further compromise.

  3. The issue will be investigated and mitigated.

  4. Relevant service providers, including the payment processor, may be notified where required.

  5. Additional security measures may be implemented to prevent recurrence.


14. Third-Party Service Providers

Didii may rely on third-party service providers to support website operations and payment processing.

Such providers may include:

  • Payment processors

  • Hosting providers

  • Technology vendors

All providers handling sensitive information must maintain appropriate security standards and comply with applicable regulations.

Payment card processing is performed through Elavon, which is responsible for the secure handling of payment card data.


15. Policy Review

This Information Security Policy is reviewed at least annually or whenever significant changes occur in:

  • Technology infrastructure

  • Regulatory requirements

  • Business operations

Updates may be made to maintain compliance and improve security practices.