Security Policy
Last updated: 20 February 2025
Luckyvibeworld is committed to protecting the security and integrity of the information processed through luckyvibeworld.com. This Security Policy describes the technical and organisational measures we apply to safeguard our platform, your account, and any data you entrust to us.
1. Scope
This policy applies to all systems, services, and infrastructure operated by Luckyvibeworld, including our website, online learning platform, user accounts, and any integrations or third-party services connected to our core platform.
2. Infrastructure Security
2.1 Hosting and Network
Our platform is hosted on reputable cloud infrastructure providers that maintain recognised industry certifications. Network-level controls including firewalls, intrusion detection systems, and traffic filtering are in place to monitor and restrict unauthorised access.
2.2 Data Encryption
All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Sensitive data stored on our systems is encrypted at rest using industry-standard encryption algorithms. We do not store payment card data directly on our infrastructure.
2.3 System Hardening
Production systems are configured according to security hardening guidelines. Unnecessary services and ports are disabled. Operating systems and software dependencies are kept up to date with security patches applied on a regular and timely basis.
3. Access Control
3.1 Internal Access
Access to production systems and user data is restricted to authorised personnel who require it to perform their role. Access rights are granted on a principle of least privilege and reviewed periodically. All internal access to sensitive systems requires multi-factor authentication.
3.2 User Authentication
User accounts are protected by password-based authentication. Passwords are stored using strong one-way hashing algorithms with salting. We encourage all users to choose strong, unique passwords and to enable any additional authentication options made available through their account settings.
3.3 Session Management
User sessions are managed with secure, time-limited tokens. Sessions are invalidated upon logout and expire automatically after a period of inactivity to reduce the risk of unauthorised access.
4. Application Security
4.1 Secure Development
Security considerations are integrated into our development process. Code changes are reviewed before deployment. We apply protections against common web application vulnerabilities including those described in the OWASP Top Ten, such as injection attacks, cross-site scripting, and cross-site request forgery.
4.2 Dependency Management
Third-party libraries and dependencies used in our platform are monitored for known vulnerabilities. Updates and patches are applied promptly when security issues are identified in components we rely on.
4.3 Testing
We conduct periodic security assessments of our platform, including vulnerability scanning and code review. Critical components are subject to more frequent evaluation.
5. Data Handling and Retention
Data collected through our platform is handled in accordance with our Privacy Policy. We retain data only for as long as necessary to fulfil the purposes for which it was collected or as required by applicable obligations. Data that is no longer required is securely deleted or anonymised.
6. Third-Party Services
We may use third-party providers for specific functions such as payment processing, analytics, and communications. These providers are selected with care and are required to maintain appropriate security standards. We do not share user data with third parties beyond what is necessary for the operation of our platform.
7. Incident Response
7.1 Detection and Response
We maintain processes for detecting, investigating, and responding to security incidents. In the event of a confirmed security breach that affects user data, we will take prompt action to contain the incident, assess its impact, and remediate the cause.
7.2 Notification
Where a security incident results in a risk to users, we will notify affected individuals in a timely manner through appropriate channels, providing relevant information about the nature of the incident and recommended steps they may take.
8. Vulnerability Disclosure
If you believe you have discovered a security vulnerability in our platform, we encourage responsible disclosure. Please contact us at contact@luckyvibeworld.com with a description of the issue. We ask that you do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it. We will acknowledge receipt of your report and keep you informed of our progress.
9. Physical Security
Our platform operates on cloud infrastructure where physical security controls, including restricted access to data centres, surveillance, and environmental protections, are maintained by our infrastructure providers in accordance with their own certified security programmes.
10. Employee Responsibilities
All personnel with access to platform systems or user data are subject to confidentiality obligations and receive guidance on security practices relevant to their role. Access is revoked promptly when an individual's role changes or their engagement with Luckyvibeworld ends.
11. Continuity and Backups
We maintain regular backups of platform data to support recovery in the event of system failure or data loss. Backup processes are tested periodically to verify that data can be restored reliably. Contingency plans are in place to minimise disruption to platform availability.
12. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When material changes are made, we will update the date at the top of this page. We encourage you to review this policy periodically.
13. Contact
If you have questions or concerns about the security of our platform, please contact us:
Luckyvibeworld
40B Pearson St, Charlestown NSW 2290, Australia
contact@luckyvibeworld.com
+61 7 3210 0390