1. Security Objectives
House Nexus aims to protect information from unauthorized access, misuse, disclosure, alteration, loss, or disruption while preserving the ability to deliver responsive customer service.
Security controls are intended to be proportionate to the nature of the information, operational risk, available technology, legal requirements, and business stage.
2. Data Classification and Handling
Information may include customer name, phone number, address, appliance details, service notes, cart selections, communication history, technician details, vendor records, and business contact information.
Sensitive information not needed for service delivery should not be requested through general enquiry forms. Payment credentials, passwords, government IDs, and private documents should not be shared through open support channels unless a specific secure process is provided.
3. Access Control
Access to customer or operational information should be limited to authorized personnel, technicians, vendors, or systems that require the data for booking, dispatch, support, billing, warranty, compliance, or business administration.
Administrative access should use appropriate authentication, role limitation, and removal when access is no longer needed. Shared credentials should be avoided where practical.
4. Technical and Operational Controls
House Nexus uses practical controls such as HTTPS-ready deployment, environment-based configuration, restricted secret handling, secure form handling, validation, monitoring tools, backup practices, and controlled vendor access where applicable.
Secrets such as API keys, SMS provider credentials, payment credentials, admin tokens, and database service keys must not be committed to public code or exposed in client-side JavaScript.
5. Vendor and Third-Party Security
House Nexus may use third-party platforms for hosting, analytics, communication, maps, OTP, payments, error monitoring, CRM, or email. Only relevant information should be shared with such providers for a defined operational purpose.
Vendor access and integrations should be reviewed periodically, especially when they involve customer data, communication history, or service records.
6. Incident Response
Suspected unauthorized access, data exposure, system misuse, credential compromise, phishing, malware, or operational data loss should be escalated promptly to the responsible business or technical contact.
Response may include containment, credential rotation, log review, provider notification, customer communication where appropriate, remediation, and preventive process improvement.
7. Retention and Disposal
Customer and operational information should be retained only as long as needed for service delivery, warranty support, complaint handling, legal compliance, business records, fraud prevention, and operational analysis.
Where records are no longer required, they should be deleted, anonymized, archived securely, or otherwise handled according to business and legal requirements.