Information Security Policy — Kaizer CRM

KAIZER Salon · 1019 Avenue P, Unit 303, Brooklyn, NY 11223
Owner and person responsible for information security: Volha Safonava
Last updated: August 27, 2026 · Reviewed at least annually and after any material change

0. Approval

This policy is issued and approved by Volha Safonava, Owner of Kaizer inc, who holds management responsibility for the business and is accountable for information security. Approved on 27 August 2026. Approval is renewed at each review, and the policy is reviewed at least once a year and whenever something material changes — a new integration, a new class of data, a change of hosting, or an incident.

1. Scope and purpose

This policy covers Kaizer CRM, the salon-management application operated by KAIZER Salon, the server it runs on, and the data it holds: client contact details and service history, appointments, payment records, inventory and vendor records, and bank transactions imported for our own bookkeeping. The application is internal. It is not sold, not offered to the public, and has no consumer sign-up. Its users are the owner and a small number of named staff.

2. Responsibility

The owner is accountable for information security, approves who gets access, and decides on any change that affects how data is stored or shared. There is no separate security department; with three users and one server, the owner performs these duties directly.

3. Access control

4. Server and network

3a. Access control policy

Who may reach what, and how that is granted, changed and removed:

4a. Software lifecycle and end-of-life (EOL)

Software that no longer receives security updates is a liability, so we keep track of what we run and when its support ends:

5. Encryption and secrets

6. Third parties

The application exchanges data with a small number of named services, each for one purpose: Plaid for importing our own bank transactions; Square for card payments; Resend for sending email to our own clients; Google Calendar for staff schedules. No client or bank data is sold, shared for advertising, or used to build profiles.

7. Backups and recovery

8. Change management

Changes are prepared and tested against a copy of live data before they are applied. Each change is checked for syntax errors and verified after deployment. The database is backed up immediately before any change that alters its structure.

9. Retention and deletion

Records are kept only as long as there is a reason to keep them. How long that is, by type:

Data Kept for Why
Client card and service history While a client, then 3 years Repeat visits, aftercare, disputes
Signed contracts and consents 7 years Legal and liability record
Payments, invoices, purchases, inventory 7 years Tax and bookkeeping obligations
Bank transactions imported through Plaid 7 years Same books they belong to
Bank access tokens Until disconnected Deleted the moment a bank is unlinked
Leads that never became clients 2 years Follow-up window
Email and SMS logs 2 years Proof of what was sent
Sign-in codes 10 minutes Expire and are single-use
Remembered devices 30 days Expire on their own
Database backups 30 days Recovery from failure or mistake

Deletion on request. A client may ask us to correct or delete their personal data by writing to the address below. We answer within 30 days. We delete what we are free to delete and keep only what the law requires us to hold — signed contracts and the financial record of what was paid — telling the client plainly what was kept and why.

Deletion in the ordinary course. Disconnecting a bank or accounting integration deletes the stored access token at once and revokes the connection at the provider. Expired sign-in codes and remembered devices fall away automatically. Backups older than thirty days are removed automatically, so deleted data does not survive indefinitely in copies.

Review. The owner reviews this schedule at least once a year, together with the review of accounts and software, and adjusts it if the law or the way the salon works changes.

10. If something goes wrong

On any sign of unauthorised access, the owner will: revoke the affected credentials and tokens immediately; disconnect the affected integrations; change passwords and rotate keys; check the server and application logs to establish what was reached; restore from backup if data was altered; and notify affected clients and the relevant providers where required by law.

11. What we do not do

Stated plainly, so this document is not read as claiming more than is true: we do not hold SOC 2 or ISO certification, do not run automated vulnerability scanners, do not commission penetration tests, and do not operate a bug-bounty programme.

Contact: office@kaizersalon.com · +1 (347) 907-7077