Cybersecurity Policy

Last updated: August 12, 2026

At VAssist, protecting the confidentiality, integrity, and availability of information is a key priority. This Cybersecurity Policy describes the reasonable administrative, technical, and organizational measures we use to help protect client, company, and user information.

1. Purpose

The purpose of this Cybersecurity Policy is to establish security practices designed to protect information from unauthorized access, disclosure, alteration, misuse, loss, or destruction.

We continuously work to maintain a secure environment for our clients and business operations by implementing reasonable security controls and generally accepted security practices appropriate to our business.

2. Scope

This Policy applies to systems, devices, software, platforms, accounts, and information used by VAssist in connection with our Services, including:

  • Email systems.
  • Cloud storage platforms.
  • Client documents and files.
  • Customer relationship management (CRM) systems.
  • Payment and billing platforms.
  • Communication and collaboration tools.
  • Project management software.
  • Virtual assistant platforms.
  • Marketing and productivity tools.
  • Third-party integrations used to provide our Services.

This Policy applies to employees, contractors, virtual assistants, consultants, and other authorized personnel who access company or client information on behalf of VAssist.

3. Information We Protect

VAssist takes reasonable measures to protect information that may include:

  • Client names and contact information.
  • Business information.
  • Billing and payment details.
  • Client documents and communications.
  • Account credentials temporarily provided for authorized service delivery.
  • Website usage information, such as IP addresses and browser information.
  • Internal business records.
  • Information received from trusted third-party service providers.

We do not sell personal information to third parties.

4. Access Control

Access to company and client information is granted only to authorized personnel who require access to perform their assigned responsibilities.

Our access management practices may include:

  • Role-based access where appropriate.
  • Strong password requirements.
  • Limited sharing of credentials.
  • Timely removal of unnecessary access.
  • Confidentiality obligations for team members.
  • Multi-factor authentication (MFA) whenever supported.

Client credentials are used only for authorized purposes related to providing the requested Services.

5. Password and Authentication

To reduce the risk of unauthorized access, VAssist encourages and follows secure authentication practices, including:

  • Using strong and unique passwords.
  • Updating passwords when compromise is suspected.
  • Using secure password management tools where appropriate.
  • Enabling multi-factor authentication whenever available.
  • Responding promptly to suspected unauthorized account access.

6. Device Security

Devices used to access company or client information are expected to meet reasonable security standards.

Depending on the device and circumstances, security measures may include:

  • Password, PIN, or biometric protection.
  • Updated operating systems and applications.
  • Antivirus or endpoint protection.
  • Secure internet connections.
  • Avoiding unsecured public Wi-Fi when handling sensitive information.
  • Secure deletion of confidential information when it is no longer required.

Employees and contractors are responsible for taking reasonable steps to protect devices used to perform work on behalf of VAssist.

7. Data Storage and Protection

We use commercially reasonable measures to protect information stored within systems used to provide our Services.

These measures may include:

  • Storing information in approved cloud platforms or secure environments.
  • Limiting access to confidential information.
  • Avoiding unnecessary local storage of sensitive files.
  • Encrypting information where appropriate and supported by the applicable platform.
  • Retaining information only as long as reasonably necessary for business or legal purposes.
  • Securely deleting or anonymizing information when it is no longer required.

8. Email and Communication Security

To reduce communication-related security risks, VAssist follows reasonable secure communication practices.

  • Verifying recipients before sharing confidential information.
  • Avoiding the transmission of sensitive information through unsecured channels where reasonably possible.
  • Identifying and reporting suspected phishing attempts.
  • Avoiding suspicious links, downloads, or attachments.
  • Taking reasonable steps to protect confidential client communications.

9. Third-Party Service Providers

VAssist relies on trusted third-party providers to support our operations and deliver our Services. These providers may include hosting providers, cloud storage platforms, payment processors, communication platforms, productivity tools, and other technology providers.

We seek to work with reputable providers that maintain appropriate security and privacy practices. However, each third-party service operates under its own terms, privacy policies, and security practices.

VAssist is not responsible for the cybersecurity practices, security incidents, or availability of independent third-party websites or services that are outside our reasonable control.

10. Confidentiality

Employees, contractors, and authorized personnel working on behalf of VAssist are expected to maintain the confidentiality of client and company information.

Confidential information may only be accessed, used, or disclosed when reasonably necessary to perform authorized work or when required by applicable law.

Confidentiality obligations continue after an employment or contractual relationship ends, subject to applicable agreements and law.

11. Data Retention and Disposal

We retain information only for as long as reasonably necessary to:

  • Deliver our Services.
  • Meet legal and regulatory obligations.
  • Resolve disputes.
  • Enforce applicable agreements.

When information is no longer required, we may securely delete, anonymize, or otherwise dispose of it using reasonable security practices.

Requests regarding data deletion may be submitted to support@vassist.io .

12. Security Incident Response

If we become aware of a cybersecurity incident that may affect company or client information, we will take reasonable steps to:

  • Identify and assess the incident.
  • Contain unauthorized access where reasonably possible.
  • Secure affected systems and accounts.
  • Investigate the potential cause and impact.
  • Restore affected services where reasonably possible.
  • Notify affected clients when required by applicable law or contractual obligations.
  • Implement reasonable corrective measures to reduce future security risks.

Examples of security incidents may include:

  • Unauthorized account access.
  • Compromised credentials.
  • Malware or ransomware attacks.
  • Data breaches.
  • Phishing attacks.
  • Loss or theft of devices containing sensitive information.

13. Employee and Contractor Responsibilities

Individuals working on behalf of VAssist are expected to:

  • Protect client and company information.
  • Use secure passwords and authentication methods.
  • Report suspicious activity or potential security incidents promptly.
  • Access only the information necessary for their assigned responsibilities.
  • Follow applicable client-specific security requirements.
  • Maintain confidentiality at all times.

Failure to comply with this Policy may result in appropriate action, which may include removal of access, suspension of work, termination of a contractual relationship, or other measures as appropriate.

14. Policy Limitations

While VAssist implements reasonable and commercially accepted security measures, no system, network, device, or method of electronic transmission or storage can be guaranteed to be completely secure.

Accordingly, we cannot guarantee absolute protection against every cybersecurity threat, attack, unauthorized access, data loss, or other security incident.

15. Policy Updates

We may revise this Cybersecurity Policy from time to time to reflect changes in technology, legal requirements, business practices, or security standards.

The updated version becomes effective when published on our Website unless otherwise stated.

We encourage clients and users to review this Policy periodically for any updates.

16. Contact Us

If you have questions regarding this Cybersecurity Policy or wish to report a security concern, please contact VAssist using the information below.