Splister: Data Loss Prevention Policy

Effective date
10 August 2026
Version
1.1

This policy sets out how we prevent, detect, and respond to the loss, corruption, or unauthorised disclosure of protected information within the Splister service. It supplements and does not replace our Privacy Policy or Terms of Service.

1. Scope and definitions

This policy applies to all systems, data, personnel, and contractors involved in operating Splister on behalf of NWR Products, Voordijk 500, 2993 BE Barendrecht, the Netherlands.

  • Data at rest. Data stored in databases, file storage, backups, or on devices.
  • Data in transit. Data moving across networks, including between our systems and those of our providers.
  • Data in use. Data actively being processed or accessed by a person or system.
  • Protected information. Personal data as defined in the GDPR and the UAVG; customer content and Service Data; authentication credentials and store access tokens; billing and financial records; and our own confidential business and technical information.

2. Our commitment

We commit to:

  • protecting the confidentiality, integrity, and availability of protected information;
  • limiting access to protected information to those who need it to perform their role;
  • detecting incidents promptly and responding to them without delay;
  • reducing the likelihood and impact of data loss through preventive controls;
  • meeting our obligations under the GDPR, the UAVG, and the requirements of the platforms we integrate with.

3. Preventive controls

Access control. Access to production systems is restricted to authorised personnel, granted on a least-privilege basis, and reviewed at least every six months. Multi-factor authentication is required for all administrative access. Access is revoked immediately when a person's role ends.

Credential protection. User passwords are stored only as salted hashes. Store access tokens and other third-party credentials are encrypted at rest. Secrets are held in a dedicated secret store, never in source code or in version control. Secrets are rotated when a person with access departs and whenever compromise is suspected.

Encryption. All connections use TLS. Databases and file storage are encrypted at rest.

Environment separation. Development, staging, and production environments are separated. Production data is not copied into development environments; testing uses synthetic or anonymised data.

Change control. Changes to production are made through version-controlled, reviewed code. Database migrations are reviewed before being applied.

Third-party management. Providers with access to protected information are assessed before use and are bound by a data processing agreement. We do not send credentials, billing data, or access tokens to AI providers.

Endpoint security. Devices used to access production systems must have disk encryption, automatic screen lock, and current security updates enabled.

4. Backup and recovery

  • Automated backups of production databases are taken daily, with point-in-time recovery available.
  • Backups are encrypted and stored separately from primary systems.
  • Backup retention is 35 days.
  • Restore procedures are tested at least twice a year, and the result of each test is recorded.
  • Generated files in object storage are retained according to the retention terms in our Privacy Policy.

Recovery objectives. In the event of a major failure we aim for a recovery point objective (RPO) of 24 hours and a recovery time objective (RTO) of 24 hours. These are targets for internal planning and are not a contractual service level.

5. Monitoring and detection

We monitor for:

  • failed and unusual authentication attempts;
  • unusual volumes of data access, export, or generation activity;
  • errors and anomalies in application and infrastructure logs;
  • availability and integrity failures reported by our providers.

Administrative access to production data is logged in our own database, retained for 12 months, and protected against alteration. Application and infrastructure logs are held by our log provider in Frankfurt (EU) and are deleted after 30 days.

6. Incident response

6.1 Reporting. Anyone who becomes aware of an actual or suspected incident must report it immediately to support@splister.com. Suspected incidents must be reported even where the reporter is unsure whether an incident has occurred.

6.2 Containment and assessment. On receipt of a report we will, without delay: record the incident; contain it, including revoking credentials and isolating affected systems where necessary; assess what data is involved, how many people are affected, and the likely consequences.

6.3 Notification.

  • Where the incident is a personal data breach likely to result in a risk to individuals, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it.
  • Where the breach is likely to result in a high risk to individuals, we notify those individuals without undue delay.
  • Where the incident affects customer Service Data for which the customer is the controller, we notify that customer promptly with the information they need to meet their own obligations.
  • Where an incident affects a connected platform, we notify that platform in accordance with its requirements.
  • Suspected criminal activity is reported to the relevant authorities.

6.4 Remediation and review. After every incident we identify the root cause, implement corrective measures, and record the outcome. Significant incidents are reviewed by management, and this policy is updated where the incident reveals a gap.

7. Responsibilities

Overall responsibility for this policy sits with the management of NWR Products.

All personnel and contractors with access to protected information must:

  • comply with this policy;
  • complete a briefing on data protection and security before receiving access, and a refresher at least annually;
  • sign a confidentiality undertaking before receiving access;
  • report incidents immediately;
  • never transfer protected information to personal accounts, devices, or unapproved services.

Failure to comply may result in withdrawal of access, disciplinary measures, or termination of the contract, and may be reported to the relevant authorities where the law requires.

8. Data minimisation and deletion

We collect only the data we need, retain it only as long as necessary in accordance with the retention schedule in our Privacy Policy, and delete or anonymise it once the purpose has ended. Deletion requests are actioned in live systems immediately and propagate through backups within the backup retention period.

9. Review

This policy is reviewed at least annually, and additionally whenever there is a significant change in our systems, providers, or legal obligations, or following a significant incident. The version and effective date above reflect the current version.