This policy defines the measures put in place to protect corporate information and the information systems, services, and equipment owned or utilised by Overwrite Agency, hereby known as “Us” or “We”.

The objectives of the Information Security Policy are:

To secure Overwrite Agency’s and its clients’ assets against theft, fraud, malicious or accidental damage, breach of privacy or confidentiality;

To protect Overwrite Agency and its clients from damage or liability arising from the use of its facilities or services for purposes contrary to their intended use.

Note. This document contains definitions already outlined in the Agency Terms of Service document and also acts as an extension of that document. Read the latest ToS here: overwrite.agency/terms. It should also be read alongside our Privacy & Cookies Policy, which covers how we handle personal data more broadly.

Scope

This policy applies to all Overwrite Agency staff, its clients, or any other persons otherwise affiliated but not employed by Overwrite Agency, who may utilise its infrastructure and/or access its applications with respect to the security and privacy of information.

Data Protection

We take appropriate technical and organisational measures to help protect confidential information against unauthorised access, loss or destruction. These measures include:

Ensuring physical security of all devices used by Overwrite Agency employees;

Using firewalls, anti-virus software, malware detection systems and other security measures on all devices;

Storing passwords for all services in our preferred Zero-Knowledge Architecture Password Manager (a password storage system designed so that even the provider itself cannot access your stored passwords), with two-factor authentication (2FA, a second verification step beyond a password, such as a code sent to your phone) required to access;

Storing client confidential information and access credentials in our preferred Zero-Knowledge Architecture Password Manager, with 2FA required to access;

Implementing 2FA on all services used by Overwrite Agency, and passkeys (a more secure, phishing-resistant login method that replaces passwords entirely) where a service supports them;

Ensuring strictly need-to-know-only access to client data;

Encrypting sensitive information both in transit between locations as well as at rest when stored on servers;

Storing customer data in secure cloud-based servers with a reliable hosting provider;

Protecting against unauthorised changes by ensuring backups are regularly taken and stored securely offsite;

Applying security patches and updates to client websites and infrastructure promptly upon becoming aware of a relevant vulnerability.

Staff, Client, and Associate Access Control

Overwrite Agency provides its staff, clients, and associates with access to computing and communications services in support of their business and administrative activities. These facilities include access to solutions like email and/or internet services.

We have strict internal controls in place to limit access to confidential information as needed on a need-to-know basis only. This follows the principle of least privilege, meaning every staff member, client, or associate is only given the minimum level of access or permissions required to carry out their specific role, and no more. All personnel at Overwrite Agency must sign a confidentiality agreement which outlines their responsibility to keep data safe and private at all times while employed here or when they leave the company.

Where a staff member, client, or associate is assigned login credentials or system passwords, they are responsible for maintaining the use and security of any User IDs and all activity associated with that ID. Knowingly disclosing passwords to others will be deemed a breach of policy and could result in the termination of accounts.

To minimise this risk, each team member is enrolled on our preferred Zero-Knowledge Architecture Password Manager and must set up 2FA to complete setup. All Password Manager activity is logged, allowing us to maintain an audit trail for any activity related to client information should an audit be required in future. Again, all login credentials and other confidential information are provided on a strictly need-to-know basis.

In line with current guidance from the National Cyber Security Centre (NCSC) and NIST (the US National Institute of Standards and Technology, whose password standards are widely followed as best practice), we do not enforce mandatory periodic password changes, as this is now understood to encourage weaker, more predictable passwords. Instead, passwords are changed immediately where a compromise is suspected or confirmed, and immediately following any staff turnover where the departing employee’s access was at admin or ‘root’ level. We rely on strong, unique passwords generated and stored through our Password Manager, combined with mandatory 2FA, as the primary defence, and we move to passkeys wherever a service we use supports them.

We have preconfigured the recommended password strength requirements in the Password Manager; these are a minimum of 12 characters, with at least one uppercase and lowercase letter, number and special character, or a longer passphrase of equivalent strength.

Contract / Temporary Access

Where temporary access is required for a specific purpose such as, but not restricted to, contract workers and ‘test’ accounts, a user expiry date based on the completion date of the required tasks must be used to ensure the temporary account is not accessible after that date.

In the case of ongoing maintenance and support from third-party companies, access is only granted to the relevant facilities within the system and is restricted to only the systems for which they provide support.

Furthermore, Overwrite Agency’s password strength requirements set out above are enforced for contract workers and third-party companies, alongside the same approach to password changes, only on suspected or confirmed compromise, or immediately following the end of a contract.

Once contracts have ended with contract workers or third parties, all passwords are changed immediately and associated user accounts are deleted.

Client Offboarding and Access Removal

When our relationship with a client ends, in line with the offboarding process set out in our Terms of Service, we apply the same principle of least privilege in reverse: all access that was granted for the purpose of that relationship is removed.

This includes:

Revoking any Overwrite Agency staff access to the client’s hosting environment, servers, WordPress admin, database, DNS, and Cloudflare account or equivalent services;

Deactivating any Overwrite Agency owned software or plugin licences from the client’s website, as described in our Terms of Service;

Removing any client-created logins to Overwrite Agency’s own internal systems, where applicable;

Deleting any locally stored copies of client access credentials from our Password Manager once they are no longer required for handover purposes.

Where we have agreed to provide a transitional period of continued access, such as during a hosting migration, access will be removed at the end of that agreed period. Outside of any such agreed period, access removal takes place promptly following the end of the relationship.

Network Usage

Overwrite Agency provides staff, clients, and associates with access to computing and communications services in support of business solutions and administrative activities.

By working with Overwrite Agency, and signing the Employment or Contract of Work documents, all users agree to abide by all policies that relate specifically to the use of the equipment, services and facilities provided. Any breach of these policies will be deemed an infringement and dealt with accordingly, which could result in the suspension of access privileges, or in severe cases, account/service removal.

Interfering, in any way, with the Overwrite Agency systems or associated equipment, be it intentional or accidental, is not permitted. Any such interference will be acted upon, investigated, and may result in dismissal from the company.

Electronic Communications

Overwrite Agency encourages staff, clients, and associates to appropriately use electronic communication to achieve the mission and goals of their business and/or administrative duties.

Overwrite Agency promotes the use of online communication to enhance collaboration and share knowledge. We realise that implementing open dialogue where individuals can express their thoughts, whether they be novel or contested, is essential in today’s connected society, as it serves to advance democratic principles within the laws of our society.

Data Breaches

Overwrite Agency understands that data breaches can happen, even with the best security measures in place. How we respond depends on the role we hold in relation to the data affected:

Where the breach involves data we hold as a controller (for example, data about our own clients, staff, or website visitors, collected in the course of running our own business), we will assess the breach, take immediate action to contain it, and where required by law, notify the Information Commissioner’s Office (ICO) and any affected individuals without undue delay.

Where the breach involves data on a client’s website or system that we manage on their behalf, we act as a processor rather than a controller. In this case, our responsibility is to notify the affected client without undue delay so that they, as the data controller, can assess the situation and meet their own legal obligations, including any notification to the ICO or to their own customers. We will support our clients through this process and provide guidance on how to secure their systems.

We aim to make any such notification, in either capacity, within 24 hours of becoming aware of an incident, though the appropriate response in each case will depend on the nature and severity of the breach.

We keep an internal record of all data breaches we become aware of, including those that do not meet the threshold for notification, in line with our obligations under the UK GDPR.

Third-Party Partners

Overwrite Agency works with various third-party partners to provide hosting, storage, and other services to our clients. While we take care to select partners that have strong security and privacy practices, we cannot be held liable for errors or breaches that may occur at these partners. However, we will take immediate action if we are alerted to any issues and work with our partners to resolve them as quickly as possible.

Training & Education

We ensure our employees are equipped with the skills necessary to protect client data. We provide custom training courses and review best practices related to information security. Every employee undergoes an annual refresher on general awareness topics, as well as specific instructions before accessing protected customer datasets or applications containing sensitive personal details, ensuring that only authorised personnel access confidential information securely.

Liability Disclaimer

In case of a breach caused either directly by us or due to errors or breaches caused by another third-party provider, we may not be held liable for any damages incurred solely as a result of such breaches, unless determined otherwise under applicable law.

Reporting Concerns

Staff, clients, and associates are all encouraged to report potential violations related to confidentiality or data security directly via email to [email protected]. All concerns raised over potential violations shall be investigated promptly given the sensitivity of such matters.

Policy Updates

This document may be updated from time to time without notice to reflect changes taking place within our organisation, new laws, regulations, and relevant industry initiatives, including updates arising from the Data (Use and Access) Act 2025 and evolving NCSC and industry security guidance.