All legal documents

Grey Collective Inc.

Security Statement

1. Our Commitment to Security

Grey Collective Inc. (“Grey Collective”, “we”, “us” or “our”) is committed to protecting the confidentiality, integrity and availability of information entrusted to us.

We recognise that information security is fundamental to maintaining the trust of our clients, business partners and stakeholders.

Reasonable technical, organisational and administrative safeguards are implemented to protect information against unauthorised access, disclosure, alteration, destruction and misuse.

2. Information Security

Grey Collective adopts a security-focused approach to the design, development and management of its digital services.

Reasonable security measures may include, where appropriate:

  • Secure authentication procedures;
  • Access controls;
  • Encryption technologies;
  • Secure data transmission;
  • Regular software updates;
  • Security monitoring;
  • Secure development practices;
  • Role-based access controls;
  • Password protection;
  • Confidentiality obligations;
  • Data minimisation principles.

Security measures are reviewed and updated periodically to reflect evolving risks and industry practices.

3. Data Protection

Grey Collective processes Personal Information in accordance with applicable privacy and data protection legislation.

Reasonable steps are taken to protect Personal Information against:

  • accidental loss;
  • unauthorised disclosure;
  • unlawful processing;
  • alteration;
  • destruction;
  • misuse.

Further information regarding the processing of Personal Information is available in our Privacy Policy.

4. Secure Development

Grey Collective is committed to developing digital solutions using generally accepted professional and security-focused development practices.

Where reasonably practicable, projects are developed with consideration for:

  • secure coding principles;
  • input validation;
  • access management;
  • authentication;
  • software updates;
  • dependency management;
  • error handling;
  • security best practices.

Security remains an ongoing process rather than a one-time event.

5. Third-Party Services

Grey Collective may utilise reputable third-party providers to assist in the delivery of its services.

Such providers may include:

  • cloud infrastructure providers;
  • hosting providers;
  • payment providers;
  • domain registrars;
  • communication platforms;
  • analytics providers;
  • artificial intelligence providers;
  • software vendors.

While Grey Collective carefully selects third-party providers, it does not own or control their infrastructure and cannot guarantee the security, availability or performance of third-party systems.

6. Client Responsibilities

Clients play an important role in maintaining security.

Clients are responsible for:

  • maintaining secure passwords;
  • protecting account credentials;
  • safeguarding access to their systems;
  • maintaining backups where applicable;
  • reviewing deliverables before implementation;
  • applying updates where appropriate;
  • complying with applicable security best practices.

Grey Collective shall not be liable for security incidents arising from the Client’s failure to implement reasonable security measures.

7. Security Limitations

Although Grey Collective implements reasonable safeguards, no website, software application, digital platform or internet-based service can be guaranteed to be completely secure.

Accordingly, Grey Collective makes no representation or warranty that any service or deliverable will be free from:

  • cyberattacks;
  • hacking;
  • malware;
  • ransomware;
  • phishing;
  • denial-of-service attacks;
  • zero-day vulnerabilities;
  • unauthorised access;
  • data breaches;
  • system failures; or
  • other cybersecurity threats.

Clients acknowledge and accept the inherent risks associated with internet-based technologies.

8. Security Incidents

In the event that Grey Collective becomes aware of a security incident affecting information under its control, reasonable steps will be taken, where appropriate, to:

  • investigate the incident;
  • contain the incident;
  • minimise potential harm;
  • restore affected systems where reasonably practicable;
  • comply with applicable legal obligations;
  • notify affected parties where required by law.

9. Responsible Vulnerability Reporting

Grey Collective appreciates the responsible disclosure of genuine security vulnerabilities.

If you believe you have identified a legitimate security vulnerability relating to Grey Collective’s systems or services, you are encouraged to notify us promptly by email.

Reports should include sufficient technical information to allow investigation.

Grey Collective requests that any suspected vulnerability be reported privately and not disclosed publicly until it has been investigated and, where appropriate, addressed.

Grey Collective reserves the right to determine the appropriate response to any reported vulnerability.

10. Business Continuity

Grey Collective takes reasonable steps to support the continuity of its business operations.

However, events beyond our reasonable control may affect the availability of services, including:

  • power failures;
  • internet outages;
  • failures of third-party providers;
  • natural disasters;
  • cyber incidents;
  • government actions;
  • other force majeure events.

Grey Collective shall not be liable for interruptions resulting from such events.

11. No Guarantee

While Grey Collective is committed to maintaining high standards of information security, no security measure can eliminate all risks.

Accordingly, Grey Collective does not guarantee that its systems, services or deliverables will be immune from security incidents or unauthorised access.

To the fullest extent permitted by applicable law, Grey Collective disclaims all warranties relating to absolute security.

12. Changes to this Security Statement

Grey Collective reserves the right to amend this Security Statement at any time to reflect changes in technology, security practices, legal requirements or business operations.

Any revised version shall become effective upon publication.

13. Contact Information

For security enquiries or to report a suspected security vulnerability, please contact:

Grey Collective Inc.

Email: greycollectiveinc@gmail.com

Country of Operation: Republic of South Africa

14. Governing Law

This Security Statement shall be governed by and interpreted in accordance with the laws of the Republic of South Africa.

Nothing contained in this Security Statement limits any rights or obligations that cannot lawfully be excluded under applicable legislation.

End of Security Statement