Data Protection
Data Protection Policy
Community Benchmark is committed to protecting the confidentiality, integrity, and availability of customer data. We design our products and business processes with security and privacy in mind and continually evaluate our practices to align with current industry standards.
Privacy by DesignProtecting customer information is a fundamental design principle of the Community Benchmark platform.Our benchmarking services are built to prevent the disclosure of individual winery performance. Customer information is only presented in aggregated form, and benchmark reporting is generated only from groups containing a minimum of four participating wineries.Community Benchmark does not store:
- Customer credit card information
- Winery customer personally identifiable information (PII)
- Consumer payment information
Our systems collect and retain only the information necessary to provide our services.For additional information regarding how customer information is collected and used, please refer to our Privacy Policy.
Data SecurityCommunity Benchmark employs multiple layers of administrative, technical, and physical safeguards to protect customer information from unauthorized access, disclosure, alteration, or destruction.These safeguards include encryption, secure authentication, access controls, continuous monitoring, and secure cloud infrastructure.
EncryptionData in TransitAll communications between users and the Community Benchmark platform are encrypted using HTTPS protected by Transport Layer Security (TLS).
- TLS 1.2 and TLS 1.3 are supported.
- TLS 1.0 and TLS 1.1 are not supported.
- All database connections are encrypted using TLS 1.2 or higher.
Data at RestCustomer data stored within our production database is encrypted at rest using industry-standard AES-256 encryption.Encryption keys are managed and regularly rotated by our managed cloud infrastructure providers.
Authentication & Access ControlCommunity Benchmark protects customer accounts through modern authentication and authorization practices, including:
- Secure password hashing and storage
- Role-based access controls
- Industry-standard authorization tokens
- Principle of least privilege for internal administrative access
Access to customer information is restricted to authorized personnel whose responsibilities require such access.
Application SecurityCommunity Benchmark develops software using secure software development practices designed to protect against common web application vulnerabilities.Security controls include protection against risks such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- Broken Authentication
- Broken Access Control
- Security Misconfiguration
- Insecure Deserialization
- XML External Entity (XXE) attacks
- Vulnerable software components
User input is validated and sanitized throughout the application, and modern development frameworks provide additional built-in security protections.
Infrastructure SecurityCommunity Benchmark is hosted on professionally managed cloud infrastructure providers that maintain enterprise-grade physical and network security.Our hosting providers maintain security controls including:
- Physical data center security
- Network firewalls
- Infrastructure monitoring
- Operating system patching
- Redundant storage
- Encrypted storage volumes
- Automated weekly full backups
- Daily incremental backups
- Point-in-time recovery capabilities for up to three days
Backup data is encrypted and protected using the same security standards as production systems.
Logging & MonitoringCommunity Benchmark maintains application logging and monitoring systems designed to detect operational issues and potential security events.Application errors are transmitted securely to authorized personnel for investigation.Sensitive system information is never exposed to end users through production error messages.
Third-Party Service ProvidersCommunity Benchmark performs the majority of data processing activities internally. Where appropriate, we engage carefully selected third-party service providers to support our operations, including services such as:
- Cloud hosting
- Database infrastructure
- Customer support
- Payment processing
- Professional consulting services
We require service providers to maintain appropriate security controls and, where applicable, execute contractual agreements governing the protection and confidentiality of customer data.
Data Retention & DeletionCustomer data is retained for the duration of the customer relationship unless otherwise required by contract or applicable law.Upon termination of services or receipt of a valid deletion request, customer data is deleted in accordance with Community Benchmark’s data retention and backup lifecycle procedures.
Security Monitoring & MaintenanceCommunity Benchmark regularly reviews and updates its software, infrastructure, and security controls to address newly identified vulnerabilities and evolving security best practices.We use commercially reasonable efforts to:
- Maintain supported software versions
- Apply security patches in a timely manner
- Remove unnecessary software components
- Continuously improve our security posture
Customer ResponsibilitiesCustomers are responsible for protecting their account credentials and ensuring that authorized users follow appropriate security practices within their own organizations.
ContactQuestions regarding Community Benchmark’s data protection and security practices may be directed to:Community Benchmark support@communitybenchmark.com
Recent Comments