✨ Try our newest product, Automagical Nudge (...automate Gmail followups!). here

1. Introduction

This Information Security Policy outlines the commitment of Automagical Apps ("the Company") to protect the confidentiality, integrity, and availability of all information assets related to our business operations, including the development and delivery of our Google Workspace add-ons. This policy applies to all employees, contractors, and third-party vendors who have access to Company information or systems.

2. Purpose

The purpose of this policy is to establish a framework for maintaining a strong security posture that:

3. Scope

This policy applies to all information assets owned, managed, or accessed by Automagical Apps, including but not limited to:

4. Definitions

5. Roles and Responsibilities

6. Information Security Objectives

7. Data Security and Handling

7.1 User PII

Automagical Apps does not collect, retain, or store user PII within its add-ons or backend systems.

7.2 Licensing Data

Email addresses used for licensing are hashed using SHA256 with unique salt and stored without retaining the original data.

7.3 Usage Data

Aggregated, anonymized usage data (e.g., button clicks by domain) is collected for analytics. No PII is included.

7.4 Data Storage

All data is stored on Google Cloud and Firestore, with encryption and security controls enforced by the platform.

8. Risk Management

Regular risk assessments will be conducted to:

Results are reviewed annually or when systems undergo significant changes.

9. Third-Party Security

Automagical Apps partners with world-class cloud providers that meet internationally recognized standards:

Google Workspace

We leverage the full suite of built-in security features, including:

Google Cloud Platform (GCP) and Firestore

Backend infrastructure benefits from:

OpenAI

Interactions with OpenAI services occur via secure APIs, and no user-identifiable data is transmitted.

Stripe

Handles all payment processing for individual licenses purchased online. Payment information is collected and processed directly by Stripe; Automagical Apps does not store any payment card details. Stripe's security measures and compliance standards can be reviewed in their documentation.

Google Cloud and Google Workspace are SOC 2 Type II certified, along with ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 compliance. Vendor security is reassessed periodically.

We periodically assess the security practices of our third-party vendors to ensure they meet our security and compliance standards.

10. Access Control

10.1 Least Privilege

Access is restricted to what's needed by role.

10.2 Authentication

Password complexity enforced; MFA required where feasible.

10.3 Account Lifecycle

Prompt provisioning and deprovisioning as roles change.

10.4 Remote Access

Enforced via Google Identity, VPN, or secure endpoint; devices must use secure configurations.

11. Security Awareness and Training

Security training is mandatory upon onboarding and refreshed annually.

Topics include phishing, password hygiene, data handling, and incident reporting.

12. Incident Response

Automagical Apps is dedicated to promptly identifying, managing, and mitigating information security incidents to protect our assets, maintain business continuity, and comply with legal and regulatory requirements. All employees, contractors, and third-party vendors are required to report suspected security incidents immediately to the Designated Security Officer (DSO). The DSO will coordinate the response, which includes:

This structured approach aligns with industry best practices, including those outlined in the NIST Cybersecurity Framework and ISO/IEC 27001. Detailed procedures are documented in our internal Incident Response Plan.

13. Business Continuity and Backups

14. Physical Security

15. Security Monitoring and Logging

We utilize advanced monitoring via:

Logs are:

16. Audit and Compliance

17. Enforcement

Violations of this policy may result in disciplinary actions, including termination, legal action, or vendor agreement termination.

18. Policy Review and Updates

This Information Security Policy is reviewed at least annually or upon significant operational changes to ensure its effectiveness and relevance. The Designated Security Officer is responsible for maintaining and updating this policy.

Updates to this policy are communicated company-wide and, when applicable, to our users and partners through our website and/or products, ensuring transparency and awareness of our security practices.

19. Contact Information

Questions or concerns can be directed to:

Security Contact: John McGowan – security@automagicalapps.com

Phone: +1 970 457 4648

20. Approval

This policy is approved by executive management and effective as of June 14, 2024.

21. Data Subject Rights

At Automagical Apps, we are committed to protecting your privacy. In alignment with our policy, we do not collect, retain, or store any personally identifiable information (PII) through our add-ons or backend systems. As a result, no personal data is processed under normal operations.

However, if you believe that personal data has been inadvertently collected or processed in error, or if you have any questions regarding our data handling practices, please refer to our Privacy Policy or contact us at security@automagicalapps.com.