Security Policy
This Security Policy describes the technical and organisational measures implemented by Druino to protect customer data, transactions, and digital deliveries on druino.co.uk.
Company: Druino
Scope: Website & Transactions
Last updated: February 2026
1. Security Commitment
Druino is committed to maintaining a high level of security to protect personal data, payment information, and digital products against unauthorised access, loss, misuse, or disclosure. Our security practices align with industry standards and applicable legal requirements, including the UK GDPR and the Data Protection Act 2018.2. Website & Network Security
We use technical safeguards to protect our Website and infrastructure, including:- Secure HTTPS connections with SSL/TLS encryption
- Firewall and intrusion prevention systems
- Regular system updates and security patches
- Monitoring for suspicious activity
3. Payment Security
All payments are processed through trusted, PCI-DSS compliant third-party payment providers. Druino does not store full payment card numbers, CVV codes, or sensitive authentication data. Payment security measures include:- Encrypted payment processing
- Fraud detection and risk assessment tools
- Transaction monitoring and verification
4. Data Access Controls
Access to personal data is limited to authorised personnel only and is granted on a need-to-know basis.- Role-based access controls
- Strong authentication and password policies
- Restricted administrative access
5. Data Storage & Retention
Personal data is stored securely and retained only for as long as necessary to fulfil business, legal, and regulatory requirements. Data is deleted or anonymised when it is no longer required.6. Digital Product Security
Software license keys and digital products are delivered through secure systems designed to prevent unauthorised access or duplication.- Controlled delivery via verified email addresses
- Order validation and fraud prevention checks
- Audit trails for delivery events
7. Third-Party Security
We work only with reputable third-party service providers (such as hosting, payment processors, and analytics providers) that maintain appropriate security standards. Third parties are required to process data in accordance with contractual obligations and applicable data protection laws.8. Incident Response & Breach Management
In the event of a data security incident or breach, we follow documented incident response procedures to contain, investigate, and remediate the issue.- Immediate assessment and containment
- Notification to affected parties where required by law
- Reporting to regulatory authorities when legally required
9. User Responsibilities
While we take extensive measures to secure our systems, users also play a role in protecting their information.- Keep login credentials confidential
- Use secure devices and networks
- Notify us immediately of suspected unauthorised access
10. Policy Updates
This Security Policy may be updated from time to time to reflect changes in technology, threats, or legal requirements. The “Last updated” date above indicates when this Policy was most recently revised.11. Contact Information
Email:
support@druino.co.uk
Phone:
+44 20 8040 4209
Address:
71–75 Shelton Street, London, England, WC2H 9JQ, United Kingdom
This Security Policy forms part of our Privacy Policy,
GDPR Compliance Statement, and Terms of Service.
Druino • 71–75 Shelton Street, London, England, WC2H 9JQ • United Kingdom
