Cookies & Privacy

We use cookies to keep the site working, understand how it is used and improve your experience. You can accept all or choose which ones to enable.Cookie Policy.

Back to About

Policy

Client Information Management Policy

FORFIRM treats Client Information as a core trust asset. Client Data is handled through confidentiality, access control, logical segregation and secure transfer principles.

Purpose

The purpose of this Client Information Management Policy is to define the corporate requirements, structural rules, and operational safeguards for receiving, storing, processing, transferring, and disposing of information and data sets entrusted to the Company by its clients. This policy ensures high-quality service delivery, safeguards commercial confidentiality, prevents unauthorized data leakage, and supports the Unified Management System in compliance with ISO 9001 and ISO/IEC 27001:2022 standards.

Applicability

This policy applies to all assets, documentation, databases, source code, specifications, and personal data provided by or generated for external clients during the lifecycle of a commercial contract or project engagement. It is strictly mandatory for all employees, account managers, developers, project team members, and third-party contractors handling client-related repositories.

Client Information Protection Commitment

The Company recognizes client data protection and organizational discretion as core prerequisites for professional integrity and operational quality. The Company commits to handling all client assets with the highest level of security, strictly applying logical data segregation, ensuring that client information is used exclusively for authorized contractual purposes, and never mixed or cross-referenced across different client environments.

Compliance Obligations

The Company guarantees that all client information systems and processing data flows adhere to applicable national and international regulatory frameworks. This includes absolute compliance with the Swiss Federal Act on Data Protection (nLPD), specific industry secrecy laws, and bilateral non-disclosure or data processing agreements (DPAs) executed with individual clients.

Continual Improvement

The Company is committed to the continual improvement of its client data handling technologies. Access control matrix models, secure collaboration platform architectures, encrypted file transfer capabilities are routinely analyzed and upgraded to counter evolving data exposure threats. Forfirm applies poka-yoke methodologies to avoid the leakage of information from any repository, to maintain confidentiality on each handled data.

Client Information Management Principles and Performance Management

The Company enforces operational excellence regarding client data lifecycle through specific structured principles: • Logical Data Segregation (Tenant Isolation): Client environments, shared drives, communication groups, and source code repositories must be completely logically isolated. Cross-client access is strictly prohibited. A project team member assigned to "Client A" must not have systemic visibility or access permissions to any asset belonging to "Client B" • Classification and Labeling: All information received from a client is classified by default as "Confidential" or "Restricted" unless explicitly marked as public. Storage repositories and digital folders containing client deliverables must follow defined organizational tagging and access frameworks • Secure Information Transfer: Client files and metrics must never be shared using unauthorized personal communication channels or unvetted public file-sharing platforms. All data-in-transit interactions must utilize enterprise-approved, encrypted channels (e.g., secure corporate SFTP, TLS-encrypted cloud vaults, or client-specified secure portals) • Retention and Secure Disposal: Client data must be retained only for the duration specified in the respective service agreement or legal mandate. Upon contract termination, completion of project delivery, or formal request by the client, all corresponding data sets must be securely deleted or returned in accordance with verified data destruction standards (wiping/purging), ensuring no residual traces remain in backups beyond the authorized lifecycle

Roles and Responsibilities

• Executive Management establishes high-level commercial compliance rules, authorizes core system infrastructure tools, and handles critical client governance escalations • Project Managers & Account Executives are responsible for ensuring correct folder access provisioning at project kick-off, monitoring team data sharing practices, and verifying client data deletion at project closure • All Personnel are responsible for executing daily duties in compliance with this policy, ensuring clean desk and clean screen principles, and never downloading client information onto non-authorized local or personal storage devices

Awareness, Training and Culture

The Company establishes an organizational culture highly sensitive to client trust. Personnel undergo targeted training concerning client data handling rules, the severe risks of cross-contamination, safe email distribution methodologies, and the explicit legal consequences of unauthorized information dissemination.

Communication and Stakeholder Engagement

This policy is transparently communicated to prospective and active corporate clients during audits, onboarding phases, or RFP responses to demonstrate the Company’s commitment to information security. Any sub-contractor or external resource involved in client delivery must contractually accept equivalent data isolation obligations before receiving access.

Monitoring, Review and Continuous Alignment

The Company monitors client repository access logs, folder permission configurations, and data transport flows regularly. This policy is reviewed at least annually by the Security Team, Quality Manager, and Executive Management to ensure absolute alignment with new operational models, international security benchmarks, and client SLA variations.