Security Policy
Last updated: 10 September 2026
This Security Policy describes the measures taken to protect the confidentiality, integrity, and availability of data processed through this platform. By using this service, you acknowledge the practices described in this document.
1. Scope
This policy applies to all systems, infrastructure, applications, and data managed by or on behalf of this platform. It covers all users, including learners, instructors, administrators, and any third parties who interact with the service.
2. Data Protection Principles
All personal and session data is handled according to the following principles:
- Data is collected only to the extent necessary to deliver the service.
- Data is stored securely and retained only for as long as required.
- Access to data is restricted to authorised personnel with a legitimate need.
- Data is not sold, rented, or disclosed to third parties except as required to operate the service or as required by law.
3. Infrastructure Security
3.1 Hosting and Network
The platform is hosted on infrastructure that employs industry-standard physical and network security controls. These include perimeter firewalls, intrusion detection systems, and network segmentation to isolate sensitive components.
3.2 Encryption in Transit
All data transmitted between users and the platform is encrypted using Transport Layer Security (TLS). Unencrypted connections are redirected automatically to secure equivalents.
3.3 Encryption at Rest
Sensitive data stored on platform servers is encrypted at rest using established encryption standards. Database backups are encrypted prior to storage.
3.4 Availability and Redundancy
The platform maintains redundant infrastructure to support continuous availability. Regular backups are performed and tested to ensure data can be recovered in the event of a failure.
4. Access Control
4.1 Authentication
User accounts are protected by password-based authentication. Passwords are stored using one-way cryptographic hashing with an appropriate salt. Users are encouraged to choose strong, unique passwords and to change them periodically.
4.2 Multi-Factor Authentication
Where available, users are encouraged to enable multi-factor authentication to add an additional layer of protection to their accounts.
4.3 Administrative Access
Access to administrative systems and production environments is restricted to authorised personnel only. Administrative sessions require strong authentication and are logged for audit purposes. Access privileges are reviewed regularly and revoked when no longer required.
4.4 Principle of Least Privilege
Personnel are granted only the minimum level of access necessary to perform their responsibilities. Role-based access controls are applied across all internal systems.
5. Application Security
5.1 Secure Development Practices
Security considerations are integrated throughout the development lifecycle. Code changes are reviewed prior to deployment, and dependencies are monitored for known vulnerabilities.
5.2 Vulnerability Management
The platform undergoes periodic security assessments, including vulnerability scanning. Identified issues are prioritised and remediated according to their severity.
5.3 Patch Management
Operating systems, server software, and application dependencies are kept up to date with security patches applied in a timely manner.
5.4 Input Validation
All user-supplied input is validated and sanitised to protect against common web application vulnerabilities, including injection attacks and cross-site scripting.
6. Session Security
User sessions are managed using secure, randomly generated tokens. Sessions expire after a period of inactivity and are invalidated upon logout. Session tokens are transmitted only over encrypted connections and are not exposed in URLs.
7. Monitoring and Logging
Platform systems generate logs of security-relevant events, including authentication attempts, access to sensitive resources, and administrative actions. Logs are stored securely and reviewed periodically to detect anomalous activity. Log data is retained for a period sufficient to support incident investigation.
8. Incident Response
8.1 Detection and Response
Procedures are in place to detect, investigate, and respond to security incidents. The response process includes containment, assessment of impact, remediation, and post-incident review.
8.2 User Notification
In the event of a security incident that may affect user data, affected users will be notified in a timely manner with information about the nature of the incident and the steps being taken in response.
8.3 Reporting Security Issues
Users and researchers who identify potential security vulnerabilities are encouraged to report them promptly by contacting help@gesturestage.com. Reports are reviewed and addressed as a priority. Please do not publicly disclose potential vulnerabilities before they have been investigated and resolved.
9. Third-Party Services
The platform may use third-party services to support its operation, including payment processing, communications, and analytics. Third-party providers are selected with regard to their security practices and are bound by appropriate data processing agreements. The platform does not control the security practices of external services and recommends reviewing the security and privacy policies of any third-party services accessed through links on this platform.
10. Physical Security
Data processing infrastructure is hosted in facilities that implement physical access controls, including restricted entry, surveillance, and environmental protections against fire, flood, and power disruption.
11. Employee and Contractor Obligations
All personnel with access to platform systems or user data are subject to confidentiality obligations. Personnel receive security awareness guidance and are required to follow internal security policies. Access is revoked promptly upon the conclusion of employment or engagement.
12. User Responsibilities
Users share responsibility for the security of their accounts. Users are expected to:
- Use a strong and unique password for their account.
- Keep their login credentials confidential and not share them with others.
- Log out of their account when using shared or public devices.
- Report any suspected unauthorised access to their account immediately.
- Keep the contact details associated with their account current and accurate.
13. Data Retention and Deletion
User data is retained for the period necessary to provide the service and meet applicable obligations. Upon account closure, personal data is deleted or anonymised within a reasonable timeframe, subject to any retention requirements that may apply.
14. Changes to This Policy
This Security Policy may be updated from time to time to reflect changes in practices, technology, or requirements. The date at the top of this page indicates when the policy was last revised. Continued use of the platform following any update constitutes acceptance of the revised policy. Users are encouraged to review this page periodically.
15. Contact
Questions or concerns regarding this Security Policy may be directed to:
| Contact Method | Details |
|---|---|
| help@gesturestage.com | |
| Phone | +353 71 964 4210 |
| Address | Clash Industrial Estate, Clash East, Tralee, Co. Kerry, V92 RWV5, Ireland |
| Website | gesturestage.com |