NeedleAdsFree Consultation
Legal

ISMS Policy

Last updated: April 30, 2026

NeedleAds operates an Information Security Management System (ISMS) aligned with ISO/IEC 27001 principles. This policy explains how we protect client data, ad accounts, creative assets, and revenue intelligence entrusted to us.

1. Scope

This policy applies to every NeedleAds employee, contractor, and processor that handles client information, including ad platform credentials, product feeds, financial reporting, and creative assets.

2. Information Security Objectives

  • Preserve the confidentiality, integrity, and availability of client data.
  • Comply with contractual, regulatory, and platform requirements (Google, Meta, Amazon, Flipkart, Quick Commerce).
  • Detect, contain, and remediate security incidents quickly.
  • Continually improve controls through audits and risk reviews.

3. Access Control

Access to client systems is granted on a least-privilege basis. We use SSO, multi-factor authentication, and role-based permissions. Credentials are revoked immediately upon role changes or contract termination.

4. Data Handling

Client revenue data, margins, and operational metrics are classified as confidential. Data in transit is encrypted using TLS 1.2+ and data at rest is encrypted with industry-standard ciphers. We do not export or share client data with third parties except as instructed by the client or required by law.

5. Vendor & Sub-Processor Management

All vendors handling client information are reviewed for security posture, sign confidentiality agreements, and are reassessed annually.

6. Incident Response

We maintain a documented incident response plan. Verified security incidents impacting a client are disclosed within 72 hours alongside containment, root cause, and remediation details.

7. Training & Awareness

All NeedleAds team members complete information security and phishing-awareness training during onboarding and annually thereafter.

8. Continuous Improvement

The ISMS is reviewed at least annually—or after any material change in services, infrastructure, or threat landscape—to ensure controls remain effective.

9. Contact

Security questions, audits, or incident reports: contact@theneedleads.com.

078887 56880Free Consultation