← Back to Legal

Security Policy

Security Policy

Effective Date: August 6, 2026

Last Updated: August 6, 2026

Service Provider: EasyCity Systems Ltd.

1. Introduction

This Security Policy describes the security measures we implement to protect Zolar (the "Platform") and your data. This policy is operated by EasyCity Systems Ltd. ("we", "us", or "our").

We are committed to maintaining the confidentiality, integrity, and availability of your information. This policy outlines our security practices and how we protect your data.

Security Commitment

We implement industry-standard security measures to protect your data and ensure the security of the Platform.

2. Data Encryption

2.1 Encryption in Transit

We encrypt data in transit using:

  • TLS 1.2/1.3: All data transmitted between your device and our servers is encrypted
  • HTTPS: All web traffic uses HTTPS with valid SSL certificates
  • Secure Protocols: Only secure protocols are used for data transmission

2.2 Encryption at Rest

We encrypt data at rest using:

  • AES-256: Sensitive data is encrypted using AES-256 encryption
  • Database Encryption: Database storage is encrypted
  • File Storage Encryption: File storage is encrypted
  • Key Management: Encryption keys are securely managed and rotated

3. Access Control

3.1 Authentication

We implement authentication controls including:

  • Password Requirements: Strong password requirements for user accounts
  • Password Hashing: Passwords are hashed using secure algorithms
  • Multi-Factor Authentication: MFA is available for sensitive operations
  • Session Management: Secure session management with timeout

3.2 Authorization

We implement authorization controls including:

  • Role-Based Access: Access is based on user roles and permissions
  • Least Privilege: Users have minimum necessary access
  • Permission Bundles: Defined permission bundles for different user types
  • Access Reviews: Regular reviews of access permissions

3.3 Admin Access

Admin access is controlled by:

  • Admin Roles: Specific admin roles with defined permissions
  • Admin Authentication: Enhanced authentication for admin accounts
  • Admin Logging: All admin actions are logged
  • Admin Monitoring: Admin access is monitored and audited

4. Network Security

4.1 Firewall Protection

We implement firewall protections including:

  • Web Application Firewall: WAF to protect against web attacks
  • Network Firewalls: Network-level firewalls to restrict access
  • Ingress Rules: Strict ingress rules for server access
  • Egress Rules: Controlled egress rules for outbound connections

4.2 DDoS Protection

We implement DDoS protection including:

  • DDoS Mitigation: DDoS mitigation services
  • Rate Limiting: Rate limiting on API endpoints
  • Traffic Analysis: Real-time traffic analysis
  • Attack Detection: Automated attack detection and response

5. Application Security

5.1 Secure Development

We follow secure development practices including:

  • Code Review: Code reviews for security vulnerabilities
  • Static Analysis: Static code analysis for security issues
  • Dependency Scanning: Scanning of third-party dependencies
  • Security Testing: Regular security testing

5.2 Vulnerability Management

We manage vulnerabilities through:

  • Patch Management: Regular patching of software and dependencies
  • Vulnerability Scanning: Regular vulnerability scanning
  • Prioritization: Prioritization of critical vulnerabilities
  • Remediation: Timely remediation of identified vulnerabilities

5.3 Input Validation

We implement input validation including:

  • Server-Side Validation: All inputs are validated on the server
  • Output Encoding: Output encoding to prevent XSS
  • Parameterized Queries: Parameterized queries to prevent SQL injection
  • File Upload Validation: Validation of file uploads

6. Data Protection

6.1 Data Minimization

We practice data minimization by:

  • Collecting only necessary data
  • Retaining data only as long as necessary
  • Anonymizing data where possible
  • Pseudonymizing sensitive data

6.2 Data Backup

We implement data backup including:

  • Regular Backups: Daily backups of critical data
  • Geographic Redundancy: Backups stored in multiple locations
  • Backup Encryption: Backups are encrypted
  • Backup Testing: Regular testing of backup restoration

6.3 Data Retention

We implement data retention including:

  • Retention Policies: Defined retention policies for different data types
  • Automatic Deletion: Automatic deletion of expired data
  • User Deletion: Ability for users to request data deletion
  • Legal Compliance: Compliance with legal retention requirements

7. Incident Response

7.1 Incident Detection

We detect incidents through:

  • Monitoring: 24/7 security monitoring
  • Alerting: Automated alerting for security events
  • Log Analysis: Analysis of security logs
  • Anomaly Detection: Detection of anomalous behavior

7.2 Incident Response

We respond to incidents by:

  • Response Team: Dedicated incident response team
  • Response Plan: Documented incident response plan
  • Containment: Rapid containment of incidents
  • Eradication: Removal of threats
  • Recovery: Recovery from incidents

7.3 Incident Notification

We notify incidents by:

  • User Notification: Notification of affected users
  • Regulatory Notification: Notification to regulatory authorities as required
  • Timely Notification: Notification within required timeframes
  • Clear Communication: Clear communication about incidents

8. Compliance

8.1 Regulatory Compliance

We comply with:

  • GDPR: General Data Protection Regulation
  • NDPR: Nigeria Data Protection Regulation
  • POPIA: Protection of Personal Information Act (South Africa)
  • DPA Kenya: Data Protection Act (Kenya)
  • DPA Ghana: Data Protection Act (Ghana)

8.2 Security Standards

We follow security standards including:

  • ISO 27001: Information security management
  • OWASP: OWASP security guidelines
  • NIST: NIST cybersecurity framework

9. Third-Party Security

9.1 Third-Party Vetting

We vet third parties by:

  • Security assessments of third-party services
  • Review of third-party security practices
  • Contractual security requirements
  • Regular monitoring of third-party security

9.2 Third-Party Data Protection

We protect data with third parties by:

  • Data processing agreements with third parties
  • Encryption of data shared with third parties
  • Limiting data shared with third parties
  • Monitoring third-party data handling

10. User Security Responsibilities

10.1 User Responsibilities

Users are responsible for:

  • Keeping passwords secure and confidential
  • Not sharing account credentials
  • Using strong passwords
  • Enabling multi-factor authentication where available
  • Keeping devices secure and updated
  • Reporting security concerns

10.2 Reporting Security Issues

To report security issues:

  • Email security@easycitysystems.com.ng
  • Provide details of the security concern
  • We will investigate and respond promptly

11. Updates to This Policy

11.1 Right to Modify

We reserve the right to modify this policy to reflect changes in security practices or requirements. Changes will be effective 30 days after posting to the Platform.

11.2 Notification

We will notify you of material changes by:

  • Emailing you at your registered email address
  • Posting a notice on the Platform
  • Updating the "Effective Date"

11.3 Continued Use

Your continued use of the Platform after changes to this policy constitutes acceptance of the updated terms.

12. Contact Information

12.1 Security Inquiries

For security-related inquiries, contact us at:

  • Email: security@easycitysystems.com.ng
  • Phone: [To be provided]
  • Address: EasyCity Systems Ltd., [Full Address to be provided]

13. Related Policies

This policy should be read together with our:

14. Acknowledgment

By using Zolar, you acknowledge that you have read, understood, and agreed to this Security Policy. You acknowledge that we implement security measures as described in this policy but cannot guarantee absolute security.