1. Purpose

eCareersGrad Ltd is committed to protecting the confidentiality, integrity and availability of the information, systems and services used to deliver our products and support our customers.

This policy establishes the principles by which information security is managed throughout the organisation and provides a framework for protecting business information, customer data and technology assets.

2. Scope

This policy applies to:

  • all employees, contractors and third parties authorised to access eCareersGrad systems or information
  • information processed or stored by eCareersGrad whether electronic or paper-based
  • cloud services, websites, applications and supporting technology used to deliver our services
  • third-party suppliers that process or host information on behalf of eCareersGrad.

3. Information Security Principles

eCareersGrad aims to ensure that:

  • Information is protected against unauthorised access, disclosure, alteration or destruction
  • Information remains accurate, complete and fit for purpose
  • Systems and services remain available to authorised users when required
  • Security risks are identified and managed appropriately
  • Security controls are reviewed and improved as our business and technology evolve.

Our approach is informed by recognised information security good practice, including the principles contained within ISO/IEC 27001.

4. Roles and Responsibilities

The Founder and Director of eCareersGrad has overall responsibility for information security and for ensuring appropriate technical and organisational measures are implemented.

Everyone with authorised access to eCareersGrad systems is responsible for:

  • protecting information entrusted to them
  • following established security procedures
  • using strong passwords and secure authentication methods
  • reporting suspected security incidents promptly
  • complying with this policy and applicable data protection legislation.

5. Access Control

Access to systems and information is granted only where there is a legitimate business requirement and is restricted to authorised users.

Administrative accounts are protected using strong passwords and multi-factor authentication.

Access rights are reviewed periodically and removed when no longer required.

6. Protection of Information

eCareersGrad implements appropriate technical and organisational measures to safeguard information, including:

  • encrypted communications using HTTPS/TLS
  • secure cloud hosting through managed infrastructure
  • role-based administrative access
  • regular software maintenance and security updates
  • automated backups and recovery procedures
  • monitoring of platform security and service availability.


Where confidential information is stored or transferred, appropriate safeguards are applied to reduce the risk of unauthorised disclosure.

7. Vulnerability Management

Security vulnerabilities are monitored through managed hosting services, software vendor notifications and vulnerability monitoring tools.

Security updates for operating systems, WordPress core, themes and plugins are applied according to their risk and operational impact with critical security updates prioritised wherever practical.

Installed software is reviewed periodically to minimise unnecessary components and reduce the attack surface.

8. Incident Management

Suspected information security incidents are investigated promptly and managed in accordance with the eCareersGrad Incident Response Plan.

The objectives of the incident response process are to:

  • contain the incident
  • minimise business impact
  • investigate the root cause
  • restore services safely
  • implement corrective actions where appropriate.

Where required by law or contractual obligation, affected customers and relevant regulatory authorities will be notified in accordance with applicable legislation.

9. Data Protection

eCareersGrad processes personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Access to personal data is limited to authorised personnel with a legitimate business need, and personal information is retained only for as long as necessary to fulfil legal, contractual and operational requirements.

10. Third-Party Services

eCareersGrad relies on selected third-party providers to support the delivery of its services.

Suppliers are chosen based on their suitability, reliability and ability to support secure service delivery. Third-party services are reviewed periodically to ensure they remain appropriate for business and security requirements.

11. Business Continuity

Business continuity arrangements are supported through regular automated backups, resilient cloud infrastructure and documented recovery procedures.

Recovery processes are reviewed periodically to help ensure that services can be restored within an appropriate timeframe following a significant disruption.

12. Compliance

Failure to comply with this policy may result in the removal of system access, contractual action or other appropriate measures.

eCareersGrad will review this policy annually, or sooner if there are significant changes to the organisation, technology, legal requirements or the threat landscape.

eCareersGrad Ltd – March 2026