The list below represents Duda’s Technical and Organizational Measures as of September 10, 2026. Duda reserves the right to revise these technical and organizational measures at any time, without notice, so long as any such revisions will not materially reduce or weaken the protection provided for personal data that Company processes in providing its various services. Duda shall take the following technical and organizational security measures to protect personal data:
-
Information security governance
-
The Company has appointed an Information Security manager who reports directly to a Company senior executive.
-
A set of information security policies and standards are documented, approved and regularly maintained.
-
The company has Cyber insurance.
-
-
HR control
-
Background checks for new employees are in use where lawful under local law.
-
Company's employees are committed to compliance with the principles of privacy protection and information security.
-
Employees with access to personal data are subject to confidentiality based on non-disclosure agreements (NDA) or equivalent clauses.
-
Upon termination, employee access rights are revoked and a reminder about their security obligations is made.
-
-
Information Security training and awareness
-
The company sets security related goals as company goals and acts to raise awareness to information security and privacy issues.
-
Periodic security and privacy training and awareness sessions are carried out for all employees.
-
-
Network and cloud security
-
The company’s cloud environment is hosted and supported by AWS. For further information regarding physical security please refer to AWS security controls.
-
Customer data is encrypted at rest and in transit using industry-standard encryption mechanisms.
-
Use of firewalls (both network and application) and authentication systems.
-
Administrative access to production environments is restricted to authorized personnel and protected using multi-factor authentication and secure access mechanisms.
-
Production environments are logically segregated from development and test environments.
-
Security monitoring and threat detection controls are deployed across relevant production infrastructure.
-
Customer data transmitted over public networks is protected using industry-standard encrypted communication protocols.
-
-
Confidentiality of processed personal data
-
Personal data stored and processed by the company is suitably secured according to best business practices commensurate with similar companies in similar industries.
-
Access to client personal data is limited to a need-to-know basis.
-
Authentication credentials are protected using appropriate security controls, including secure password hashing where applicable.
-
Anonymisation/Pseudonymisation of personal and/or sensitive data wherever applicable in accordance with technical or business needs to provide the service and/or comply with the law.
-
The company will not provide users’ PII and/or business data unless proper verification of the identity of the account owner is established.
-
Customer Data will only be stored for as long as Company and the Customer has an active agreement and as long as it serves the purposes for which the data was collected.
-
Secured process for deletion of personal data by the end of the retention period and/or on-demand.
-
Subprocessors undergo a vendor information security and privacy review based on the sensitivity of data and/or the personal data they access and are required to comply with vendor security requirements.
-
-
Security, Integrity, and availability of processing systems
-
Company laptops are equipped with anti-malware and anti-virus software.
-
Company laptops are equipped with a management solution which enforces the company's laptops security policy.
-
Regular vulnerability scanning and security testing of source code, software dependencies, and relevant cloud infrastructure.
-
Software updates process (i.e patch management) in place to fix identified vulnerabilities in a timely manner in accordance with risk assessment.
-
The use of logging, monitoring, and alerting systems.
-
Advanced systems to mitigate denial of service (DoS/DDoS) attacks.
-
-
Restore systems and data availability in the event of physical or technical incident
-
The use of high-availability cloud-computing zones in multiple geo-locations.
-
Disaster recovery (DR) procedures are well documented and regularly reviewed and updated.
-
Regular backups are securely stored in a separate cloud environment and could be restored as needed.
-
-
Evaluating the effectiveness of technical and organizational measures
-
Periodic and on-demand penetration-tests.
-
Duda maintains an Information Security Management System certified against ISO/IEC 27001:2022.
-
Duda has completed a SOC 2 Type II examination covering the Security, Availability, and Confidentiality Trust Services Criteria for the Duda Website Builder platform.
-
-
Marketing Automation
-
Access to Marketing Automation functionality and associated customer data is restricted based on authorized user permissions.
-
Marketing Automation supports campaign and delivery activity logging and controls for managing opt-out and suppression requirements through supported workflows.
-
Contact, campaign, consent, suppression, and related Marketing Automation data are subject to applicable data retention and deletion controls.
-
-
Artificial Intelligence
-
Use of third-party artificial intelligence services is subject to Duda's security, privacy, and supplier assessment requirements.
-
Where Customer Personal Data is processed by approved AI providers, Duda applies data minimization, access controls, and contractual and/or technical controls designed to prevent such data from being used to train general-purpose or cross-customer AI models, unless otherwise expressly authorized.
-