DTS Connex
Data Security and Privacy
1. Purpose and Scope
This page describes how International Financial Services, Inc., doing business as DTS Connex (“DTS”), protects the confidentiality, integrity, and availability of data processed in conjunction with the Application Services provided under the Standard Application Services Terms. It applies to Customer data created, stored, processed, or transmitted by DTS through the Application Services, including data managed within DTS’ cloud-based systems and supporting third-party services. Capitalized terms used but not defined on this page have the meanings given in the Standard Application Services Terms.
2. Data Security
2.1 Risk-Based Protection
DTS designs and implements data security controls based on the sensitivity of the data, the criticality of the systems involved, and the potential impact to business operations, customers, and individuals if data were compromised, altered, or unavailable.
2.2 Access Controls
DTS restricts access to data based on business need-to-know and least-privilege principles. Logical access controls, authentication mechanisms, and role-based permissions are used to prevent unauthorized access to information.
2.3 Integrity Controls
DTS implements controls to help protect data from unauthorized modification or destruction, including access restrictions, change management processes, validation checks within applications, and logging of data access and changes where appropriate.
2.4 Availability, Backup, and Recovery
DTS implements measures to support the availability of data and systems required for the Application Services, including use of resilient cloud infrastructure, backup and recovery processes, and monitoring to detect and respond to availability issues.
2.5 Encryption
Data is protected during transmission using encrypted communication protocols. Encryption is used for data at rest where appropriate based on risk and system design.
2.6 Secure Storage and Processing
Data is stored and processed in approved systems and environments. Use of unauthorized storage locations or services for customer data is restricted.
2.7 Monitoring and Detection
DTS monitors systems and data access activity to identify potential security events, unauthorized access, or data integrity issues. Identified issues are investigated and addressed in accordance with DTS’ incident response procedures.
2.8 Third-Party Service Providers
When third-party service providers are used to store or process data, DTS considers data security requirements as part of vendor selection and oversight, consistent with shared responsibility models and contractual expectations.
2.9 Incident Response and Recovery
Data security incidents are managed through established incident response procedures. Recovery actions are taken to restore data availability and integrity following an incident. Notification of data breaches involving Customer’s Confidential Information is addressed in the Standard Application Services Terms.
3. Privacy
3.1 Personal Data
In operating the Application Services, DTS may collect and process personal information related to customers and business contacts, such as contact information, account details, and other data necessary to operate the services. Personal data is treated as confidential unless explicitly classified otherwise.
3.2 Collection and Use
Personal data is collected only for legitimate business purposes and only to the extent necessary. DTS avoids collecting unnecessary or excessive personal information, and data is used solely for the purposes for which it was collected or for compatible operational needs.
3.3 Access to Personal Data
Access to personal data is restricted to individuals with a legitimate business need, is granted based on job role, and follows least-privilege principles. Unauthorized access, use, or disclosure is prohibited.
3.4 Safeguards
Personal data is protected using appropriate administrative, technical, and physical safeguards, including encryption where appropriate, secure storage, and access controls. Systems handling personal data are monitored to detect unauthorized activity.
3.5 Sharing
Personal data is not shared externally except as required to deliver services, meet contractual obligations, or comply with legal requirements. When third parties are involved, reasonable steps are taken to ensure appropriate data protection practices are in place.
3.6 Retention and Disposal
Personal data is retained only for as long as necessary to meet business, legal, or contractual requirements. When no longer required, data is securely deleted or destroyed in accordance with DTS’ record retention practices.
3.7 Individual Requests
DTS respects reasonable requests from individuals to access, correct, or delete their personal information where appropriate and feasible. Requests are handled in a controlled and secure manner and may be directed to help@dtsconnex.com.
3.8 Incident Handling
Suspected or confirmed exposure of personal data is reported and handled in accordance with DTS’ incident response procedures, including steps to mitigate impact and notify affected parties when required.
4. De-Identified Data
DTS’ collection and use of aggregated and anonymized data derived from Customer’s use of the Application Services is governed by the De-Identified Data provisions of the Standard Application Services Terms.
5. Updates to This Page
DTS reviews and updates its security and privacy practices as its services, technology, and applicable requirements evolve. Updates to this page are made in accordance with the Updates to Terms provisions of the Standard Application Services Terms, and the “Last Updated” date above reflects the current version.