
Policy
Client Information Management Policy
FORFIRM treats Client Information as a core trust asset. Client Data is handled through confidentiality, access control, logical segregation and secure transfer principles.
Purpose
The purpose of this Client Information Management Policy is to define the corporate requirements, structural rules, and operational safeguards for receiving, storing, processing, transferring, and disposing of information and data sets entrusted to the Company by its clients. This policy ensures high-quality service delivery, safeguards commercial confidentiality, prevents unauthorized data leakage, and supports the Unified Management System in compliance with ISO 9001 and ISO/IEC 27001:2022 standards.
Applicability
This policy applies to all assets, documentation, databases, source code, specifications, and personal data provided by or generated for external clients during the lifecycle of a commercial contract or project engagement. It is strictly mandatory for all employees, account managers, developers, project team members, and third-party contractors handling client-related repositories.
Client Information Protection Commitment
The Company recognizes client data protection and organizational discretion as core prerequisites for professional integrity and operational quality. The Company commits to handling all client assets with the highest level of security, strictly applying logical data segregation, ensuring that client information is used exclusively for authorized contractual purposes, and never mixed or cross-referenced across different client environments.
Compliance Obligations
The Company guarantees that all client information systems and processing data flows adhere to applicable national and international regulatory frameworks. This includes absolute compliance with the Swiss Federal Act on Data Protection (nLPD), specific industry secrecy laws, and bilateral non-disclosure or data processing agreements (DPAs) executed with individual clients.
Continual Improvement
The Company is committed to the continual improvement of its client data handling technologies. Access control matrix models, secure collaboration platform architectures, encrypted file transfer capabilities are routinely analyzed and upgraded to counter evolving data exposure threats. Forfirm applies poka-yoke methodologies to avoid the leakage of information from any repository, to maintain confidentiality on each handled data.
Client Information Management Principles and Performance Management
The Company enforces operational excellence regarding client data lifecycle through specific structured principles: • Logical Data Segregation (Tenant Isolation): Client environments, shared drives, communication groups, and source code repositories must be completely logically isolated. Cross-client access is strictly prohibited. A project team member assigned to "Client A" must not have systemic visibility or access permissions to any asset belonging to "Client B" • Classification and Labeling: All information received from a client is classified by default as "Confidential" or "Restricted" unless explicitly marked as public. Storage repositories and digital folders containing client deliverables must follow defined organizational tagging and access frameworks • Secure Information Transfer: Client files and metrics must never be shared using unauthorized personal communication channels or unvetted public file-sharing platforms. All data-in-transit interactions must utilize enterprise-approved, encrypted channels (e.g., secure corporate SFTP, TLS-encrypted cloud vaults, or client-specified secure portals) • Retention and Secure Disposal: Client data must be retained only for the duration specified in the respective service agreement or legal mandate. Upon contract termination, completion of project delivery, or formal request by the client, all corresponding data sets must be securely deleted or returned in accordance with verified data destruction standards (wiping/purging), ensuring no residual traces remain in backups beyond the authorized lifecycle
Roles and Responsibilities
• Executive Management establishes high-level commercial compliance rules, authorizes core system infrastructure tools, and handles critical client governance escalations • Project Managers & Account Executives are responsible for ensuring correct folder access provisioning at project kick-off, monitoring team data sharing practices, and verifying client data deletion at project closure • All Personnel are responsible for executing daily duties in compliance with this policy, ensuring clean desk and clean screen principles, and never downloading client information onto non-authorized local or personal storage devices
Awareness, Training and Culture
The Company establishes an organizational culture highly sensitive to client trust. Personnel undergo targeted training concerning client data handling rules, the severe risks of cross-contamination, safe email distribution methodologies, and the explicit legal consequences of unauthorized information dissemination.
Communication and Stakeholder Engagement
This policy is transparently communicated to prospective and active corporate clients during audits, onboarding phases, or RFP responses to demonstrate the Company’s commitment to information security. Any sub-contractor or external resource involved in client delivery must contractually accept equivalent data isolation obligations before receiving access.
Monitoring, Review and Continuous Alignment
The Company monitors client repository access logs, folder permission configurations, and data transport flows regularly. This policy is reviewed at least annually by the Security Team, Quality Manager, and Executive Management to ensure absolute alignment with new operational models, international security benchmarks, and client SLA variations.
