Legal · BETIHUT-LEGAL-SEC
Information Security Statement
- Entity
- AUTOMAIZE SOLUTIONS LTD
- Reg. No.
- HE 480609
- Effective
- 18 August 2026
- Status
- Version 1.3 · Effective
This Information Security Statement describes the technical and organisational measures that AUTOMAIZE SOLUTIONS LTD, as the sole current Betihuti operator and temporary mobile-app publisher, applies to protect personal data and the integrity of the Betihuti service (the "Service").
These measures are maintained in accordance with Article 32 GDPR and applicable national data-protection law, and are reviewed periodically and updated to reflect changes in risk, technology and applicable law.
1.Purpose and scope
- 1.1This Statement applies to the systems, applications and infrastructure operated by us to provide the Service, and to the personal data processed through them, including safety records, medical-fitness outcomes, incident and near-miss reports, uploaded certificates and assistant transcripts.
- 1.2It describes our security posture at a summary level; it does not disclose information that could compromise the security of the Service.
2.Governance and responsibility
- 2.1We maintain an information-security programme with defined ownership and accountability, supported by internal policies governing acceptable use, access management and incident response.
- 2.2Security measures are reviewed periodically and following any significant change to the Service or the threat landscape.
3.Encryption
- 3.1Personal data is encrypted in transit using current versions of the Transport Layer Security (TLS) protocol.
- 3.2Personal data, including occupational health data, incident reports and uploaded certificates, is encrypted at rest using industry-standard cryptographic algorithms.
4.Access control
- 4.1Access to personal data is granted on a least-privilege, need-to-know basis and is subject to single sign-on and multi-factor authentication.
- 4.2Access rights are reviewed periodically and revoked promptly when no longer required, and access to production systems is logged for review.
5.Infrastructure and network security
- 5.1The Service runs on reputable cloud providers operating certified data centres, with logically isolated environments and segregation between production and non-production systems.
- 5.2We apply network controls, regular patching and hardening of systems, and we keep production data within the European Economic Area by default.
6.Data minimisation and retention
- 6.1We collect only the personal data necessary for the relevant assessment and retain it on a defined retention schedule, after which it is deleted or anonymised.
- 6.2You may request export or deletion of your personal data as described in our Privacy Notice.
7.Logging and monitoring
- 7.1We log relevant security events and monitor our systems for anomalous or unauthorised activity, using alerting to support timely detection and response.
8.Incident response and breach notification
- 8.1We maintain a documented incident-response process designed to detect, contain, investigate and remediate security incidents.
- 8.2Where we act as a processor, we will notify the relevant controller without undue delay after becoming aware of a personal data breach affecting their data, with the information they need to meet their own obligations under Articles 33 and 34 GDPR.
9.Secure development
- 9.1We follow secure-development practices, including code review and dependency management, and we separate development, testing and production environments.
10.Personnel and confidentiality
- 10.1Personnel with access to personal data are bound by confidentiality obligations and receive guidance appropriate to their role.
11.Sub-processor and vendor management
- 11.1We engage sub-processors only under written contracts imposing data-protection and security obligations consistent with Article 28 GDPR, and we conduct due diligence on vendors that process personal data. The current list is published in our Sub-processor Notice.
12.Business continuity and resilience
- 12.1We maintain backups and resilience measures designed to support the availability and recoverability of the Service and of personal data.
13.Responsible disclosure
- 13.1We welcome responsible disclosure of security vulnerabilities. If you believe you have identified a vulnerability affecting the Service, please contact us at security@betihuti.com so that we can investigate and remediate it. We ask that you allow us a reasonable period to respond before any public disclosure.
14.Contact
- 14.1Security questions and vulnerability reports may be sent to security@betihuti.com; privacy and data-protection questions may be sent to our Privacy Lead at privacy@betihuti.com.
