At jettbet-ca.com, we prioritize the confidentiality, integrity, and availability of your data. This Security and Data Protection Policy outlines the measures we take to safeguard your information and the responsibilities of all parties involved.
1. Scope
This policy applies to all data processing activities on jettbet-ca.com, including information collected through our website, email communications, and any integrated third-party services.
2. Governance and Accountability
-
Data Protection Officer (DPO): Our appointed DPO oversees compliance with applicable security standards and data protection laws.
-
Roles and Responsibilities: All employees, contractors, and service providers are required to adhere to this policy and report any suspected security incidents immediately.
3. Data Classification
We categorize data into three sensitivity levels:
-
Public Data: Information intended for public consumption, such as marketing materials and blog posts.
-
Internal Data: Operational details and administrative records not shared publicly.
-
Restricted Data: Personally identifiable information (PII), account credentials, and financial transaction details.
4. Technical Security Controls
4.1 Encryption
-
In transit: All data exchanged between users and our servers is encrypted using industry-standard TLS (Transport Layer Security).
-
At rest: Sensitive data, including passwords and payment details, are encrypted using AES-256 or equivalent strong encryption algorithms.
4.2 Access Management
-
Role-Based Access Control (RBAC): Access to systems and data is granted strictly on a need-to-know basis.
-
Multi-Factor Authentication (MFA): Required for all administrative and privileged accounts.
-
Regular Access Reviews: Permissions and user roles are reviewed quarterly to ensure appropriateness.
4.3 Network Security
-
Firewalls and Intrusion Detection Systems (IDS): Deployed to monitor and block unauthorized network traffic.
-
Secure Configuration: Servers and network devices are hardened according to best-practice benchmarks (e.g., CIS).
-
Vulnerability Management: Regular scanning, patching, and penetration testing to identify and remediate security flaws.
4.4 Application Security
-
Secure Development Lifecycle: Code reviews, static analysis, and dynamic testing are integrated into our development process.
-
Web Application Firewall (WAF): Protects against common web threats such as SQL injection and cross-site scripting (XSS).
-
Third-Party Libraries: Regularly audited and updated to mitigate known vulnerabilities.
5. Organizational Security Measures
5.1 Security Awareness and Training
All staff undergo security training upon hire and receive annual refresher courses covering data protection principles, phishing prevention, and incident reporting procedures.
5.2 Acceptable Use Policy
Employees and contractors must follow our Acceptable Use Policy, which prohibits unauthorized access, data sharing, or installation of unapproved software.
5.3 Incident Response
-
Incident Response Plan: A documented procedure for identifying, containing, eradicating, and recovering from security incidents.
-
Notification: In the event of a data breach affecting personal data, we will notify affected individuals and relevant authorities within 72 hours, as required by law.
6. Data Protection and Privacy
6.1 Data Minimization
We collect only the minimum data necessary to provide our services and fulfill legal obligations. Unnecessary data is securely purged according to retention schedules.
6.2 Data Subject Rights
We respect your rights under applicable data protection regulations, including access, correction, deletion, and portability of your personal data.
6.3 Third-Party Processors
All vendors and service providers handling restricted data must sign a Data Processing Agreement (DPA) that enforces equivalent security standards and prohibits sub-processing without consent.
7. Physical Security
-
Data Centers: Hosted in Tier III+ facilities with 24/7 monitoring, biometric access controls, and environmental safeguards (fire suppression, climate control).
-
On-Site Controls: Office premises protected by access badges, CCTV surveillance, and visitor logging procedures.
8. Business Continuity and Disaster Recovery
-
Regular Backups: Automated backups of critical systems and data performed daily and stored off-site.
-
Disaster Recovery Plan: Detailed procedures and recovery time objectives (RTO/RPO) tested semi-annually to ensure rapid restoration of services.
9. Policy Review and Updates
This policy is reviewed at least annually or following significant changes to our systems, processes, or legal requirements. Updates will be published on this page with a revised effective date.
10. Contact Information
For questions or concerns regarding this Security and Data Protection Policy, please contact:
Address: JettBet Security Office, 123 Casino Avenue, Toronto, ON, Canada
Your trust in our commitment to security and data protection is paramount. We continually strive to uphold the highest standards to keep your information safe.




