Data Security Policy

Navigora’s Information Security Policy

Information security refers to the protection of information, information systems, services and communications through administrative, technical and other measures. Information security aims to ensure the availability, integrity and confidentiality of information in both normal and exceptional circumstances.

Navigora’s business is based on the acquisition, management, processing and reliable delivery of information to customers. Several laws, customers and stakeholders set requirements related to information security for Navigora’s operations and information processing. Therefore, taking information security into account is important in Navigora online service and its business processes.

Access control

Navigora’s access control is defined as the rights to view, process and modify personal data. These rights are granted to persons who have a job-related need to process personal data. Access control principles are defined in a separate document.

In addition, access control is defined separately for software and technical devices, such as firewalls and servers. The user IDs and access rights of the systems are personal and in accordance with the job duties. When a person leaves Navigora, the access rights are removed. Access to Navigora’s office premises is only possible with a personal access permit.

Customers also have personal user IDs. Customers’ access rights are always defined according to needs. If access rights are granted to credit information, the customer must have a purpose of use in accordance with the Finnish Credit Information Act.

Data transmission protection

Networks and service systems are protected by firewalls. Traffic from the public network is limited to only the necessary addresses and ports.

Network traffic is monitored. In public networks, traffic is always TSL/SSL encrypted. The encrypted SFTP protocol is used for data transfer between partners and Navigora.

Technical architecture and data checks

The service environment is designed to be as fault-tolerant as possible at the device, network, server and service levels. Network connectivity to services is ensured by duplicating the service infrastructure on behalf of the provider, so if the primary network connection is interrupted, traffic is automatically transferred to the backup connection.

Reliable automatic backups, as well as duplicating both services and data stores, play a major role in minimizing the effects of serious disruptions and recovering from disruptions. Navigora monitors the operation of Navigora’s network services and online service infrastructure.

Production, test and development networks are separate. Internal systems can only be accessed from internal networks or through encrypted remote connections and strong authentication.

In connection with data collection, Navigora performs several checks to ensure the accuracy of the data.