Data hosting and security FAQ
User security
Can Clever Logger users have various levels of access?
Are any patient identifiers saved with the data?
Is any company financial information saved with the data?
Does the data include any personal information?
Usernames and email addresses may be classified as personal information.
No sensitive or health information is collected.
No passwords are stored. Clever Logger uses one-time passcode login.
Does Clever Logger protect customer information and personally identifiable information (PII)?
Clever Logger does not collect or store sensitive information or Protected Health Information (PHI).
User email and name are the only personal information collected.
Access is protected through controls, encryption in transit, and encryption at rest.
Will customer data be extracted for third parties, such as marketing?
Will anonymised customer data be used?
Anonymised customer data may be used internally for debugging and testing.
Anonymised error logs and performance metrics may be sent to Sentry. This can be disabled with browser extensions or firewall rules.
How long is temperature and humidity data stored?
Data is stored for at least two years and is currently stored indefinitely.
Customers can export temperature data as CSV, XLSX or PDF.
Retention beyond two years can be arranged upon request.
What data is accessible within the system?
Temperature and humidity logs, usernames, email addresses, device IP addresses, Wi-Fi SSID name, and organisation contact details if entered.
No passwords are accessible within the system.
Is Clever Logger compliant with data privacy regulations?
What kind of security processes do you have in place?
Computers used to administer Clever Logger apply operating system and software patches within two weeks.
Cloud platform patches are tested and prioritised.
Third-party software is regularly reviewed for security patches.
Operating system and application patches from AWS are applied as soon as notifications are received.
Gateways update to the latest firmware or operating system automatically if security patches are available.
Location
Where is the registered head office of the service provider?
Which countries are the cloud services delivered from?
In which legal jurisdictions is data stored and processed?
Development
Who has access to infrastructure, hardware, software, code, and data?
The Lead Developer has full system access.
Other developers only access the code they are working on.
Version control is managed within Git.
Are all privileged users and developers uniquely identifiable?
Do privileged users and developers follow the principle of least privilege and role-based access control?
Yes. Developers without production system requirements do not have access.
Cloud accounts, such as AWS, are fully segregated with unique credentials.
What is the password policy for privileged users and developer workstations?
All staff use a password manager and are encouraged to generate complex passwords.
Password audits are conducted periodically.
Passwords are audited and reset upon termination of employment.
How frequently are operating systems and applications patched for privileged users and developer workstations?
How is data on privileged user and developer workstations sanitised during service termination, repair, or disposal?
Developers do not store local copies of data.
Data is accessed remotely with 2FA.
Access can be removed remotely if hardware is lost or employment is terminated.
How is segregation between development/testing and production implemented?
Development occurs on local machines.
Builds are tested on a staging server.
Only the senior developer has access to deploy to production.
Does Clever Logger routinely back up all data?
Does Clever Logger have separate development and live environments?
Does Clever Logger have a formal incident response and management process?
Does the SLA include an expected and minimum availability performance percentage over a clearly defined period?
Define outsourced or subcontracted services that impact security and availability.
AWS is used for databases, API nodes, and file storage.
Cloudflare provides DNS and DDoS protection.
Are third-party services ISO27001 compliant?
AWS provides compliance information through AWS Compliance.
Cloudflare provides compliance information through Cloudflare Compliance.