Security

Information Security Policy

Effective Date: January 1, 2026

This Information Security Policy outlines the principles, safeguards, responsibilities, and controls used by Padi to protect information assets, customer data, systems, and business operations.

01

Purpose

The purpose of this Information Security Policy is to establish the principles, responsibilities, and controls that guide the protection of information assets managed by Padi. This Policy supports the confidentiality, integrity, and availability of information and systems used to provide our Services.

02

Scope

This Policy applies to all employees, contractors, consultants, vendors, service providers, systems, applications, infrastructure, devices, and information assets owned, operated, or managed by Padi in connection with the delivery of its products and services.

03

Information Security Objectives

Padi is committed to protecting information assets from unauthorised access, disclosure, modification, destruction, disruption, or misuse. Our security programme is designed to preserve confidentiality, maintain data integrity, and ensure service availability.

04

Governance and Accountability

Management is responsible for overseeing information security practices and ensuring appropriate safeguards are implemented. All personnel are expected to understand and comply with applicable security requirements relevant to their responsibilities.

05

Risk Management

Padi maintains processes for identifying, assessing, monitoring, and managing risks that may impact information systems, customer data, business operations, or regulatory compliance obligations.

06

Access Control

Access to systems, applications, and information assets is granted based on business need and the principle of least privilege. Access rights are reviewed periodically and revoked when no longer required.

07

Authentication and Account Security

Users are responsible for protecting account credentials and maintaining appropriate password security. Additional authentication controls may be implemented where appropriate to strengthen account protection.

08

Asset Management

Information assets, systems, software, devices, and infrastructure components are managed throughout their lifecycle. Appropriate safeguards are applied to protect assets from loss, theft, misuse, or unauthorised modification.

09

Data Classification and Handling

Information is classified and handled according to its sensitivity and business value. Appropriate controls are applied to ensure that confidential and sensitive information is protected throughout its lifecycle.

10

Encryption

Padi employs encryption and related safeguards where appropriate to protect sensitive information during transmission, storage, and processing.

11

Secure Development Practices

Security considerations are incorporated into software development, testing, deployment, and maintenance activities. Systems are designed and maintained with security best practices in mind.

12

Monitoring and Logging

Systems and infrastructure may be monitored to detect operational issues, unauthorised activities, security events, and potential threats. Relevant logs may be retained for security, auditing, and compliance purposes.

13

Vulnerability Management

Padi maintains processes for identifying, assessing, prioritising, and remediating vulnerabilities that may affect the security of systems, applications, infrastructure, or customer data.

14

Incident Response

Padi maintains procedures for identifying, reporting, investigating, containing, mitigating, and recovering from information security incidents. Incidents are reviewed to improve future prevention and response efforts.

15

Business Continuity and Resilience

Appropriate measures are implemented to support operational resilience and continuity of critical services in the event of disruptions, failures, or security incidents.

16

Third-Party Security

Padi evaluates relevant security considerations when engaging vendors, partners, subprocessors, and service providers that may access or process information related to the Services.

17

Training and Awareness

Personnel may receive security awareness training and guidance to help ensure understanding of information security responsibilities, threats, and best practices.

18

Compliance

Padi seeks to comply with applicable legal, regulatory, contractual, and industry requirements relating to information security, privacy, and data protection.

19

Policy Review

This Information Security Policy is reviewed periodically and may be updated to reflect changes in business operations, technology, legal obligations, threats, or security practices.

20

Contact Information

Questions regarding this Information Security Policy may be directed to [email protected].