Last update 14.07.2026
Effective date: 30.06.2026
Our Commitment
Dataslab is committed to protecting the confidentiality, integrity and availability of information entrusted to us by our customers, partners, employees and other stakeholders.
Information security is an integral part of our business operations, software development processes and delivery of data, analytics and artificial intelligence solutions. We apply a risk-based approach to information security and continuously improve our security practices in line with applicable legal, regulatory, contractual and industry requirements.
Information Security Management
Dataslab maintains an Information Security Management System designed with reference to the principles and requirements of ISO/IEC 27001:2022.
Our information security framework includes governance, documented policies, defined responsibilities, risk assessment, access management, incident response, business continuity, supplier management, employee awareness and continuous monitoring.
Senior management is responsible for supporting the information security framework, allocating appropriate resources and ensuring that security objectives remain aligned with the Company’s business strategy.
Security and Privacy by Design
Information security and privacy requirements are considered throughout the entire lifecycle of our products and services.
Dataslab applies secure development practices, including:
● security requirements during solution design;
● controlled access to development and production environments;
● code review, testing and vulnerability management;
● secure configuration and change management;
● logging, monitoring and traceability;
● protection of development, testing and production data;
● segregation of duties and environments where appropriate.
Our solutions may be deployed on-premises, in private cloud environments or within customer-controlled infrastructure, depending on customer requirements and the agreed delivery model.
Data Protection
Dataslab processes information only for authorised and legitimate purposes and in accordance with applicable data protection requirements, including the General Data Protection Regulation where relevant.
Access to information is granted according to business need, the principle of least privilege and defined authorisation procedures.
Information is classified and protected according to its sensitivity, value and contractual or regulatory requirements. Appropriate technical and organisational measures are applied to prevent unauthorised access, disclosure, alteration, loss or misuse.
AI and Data Platform Security
As a provider of data and artificial intelligence solutions, Dataslab recognises the specific security and privacy risks associated with AI systems, machine learning, large language models, retrieval-augmented generation and enterprise data platforms.
We apply measures intended to support:
● controlled access to models, datasets and knowledge repositories;
● protection of customer data from unauthorised use;
● separation of customer environments and information;
● traceability of system activities;
● secure integration with external systems;
● monitoring of AI-related risks and misuse scenarios;
● human oversight where appropriate;
● use of data only for agreed purposes.
Customer data is not used for unrelated model training or other secondary purposes without appropriate authorisation.
Access Control and Personnel Security
Access to Dataslab systems and information resources is provided only to authorised individuals and is reviewed periodically.
Employees and contractors are required to comply with confidentiality, data protection and information security obligations. Security responsibilities are communicated during onboarding and reinforced through awareness activities, internal guidance and role-specific training.
Incident Management
Dataslab maintains procedures for identifying, reporting, assessing and responding to information security incidents.
Suspected incidents are investigated and managed according to their severity, potential impact and applicable legal or contractual obligations. Where required, affected customers or relevant authorities are informed in accordance with established notification procedures.
Lessons learned from incidents, tests and reviews are used to improve our security controls and response capabilities.
Business Continuity and Resilience
Dataslab applies business continuity and resilience measures appropriate to the nature of its operations and services.
These measures may include backup and recovery procedures, redundancy, restoration testing, continuity planning and defined responsibilities for responding to disruptions.
Specific availability, recovery and continuity requirements are agreed with customers as part of contractual and service arrangements.
Third-Party Security
Suppliers, subcontractors and service providers that may access Dataslab information or systems are assessed according to the level of risk associated with their services.
Relevant information security, confidentiality and data protection requirements are incorporated into contractual arrangements where appropriate.
Compliance and Continuous Improvement
Dataslab regularly reviews its information security framework, risks, controls and objectives.
Internal reviews, audits, monitoring, testing and management oversight are used to identify opportunities for improvement and to respond to changes in technologies, threats, business processes and regulatory requirements.
This Statement reflects Dataslab’s commitment to responsible information security management. It does not disclose confidential details of internal controls, system architecture or security procedures.
Cookies Policy
We use cookies to operate this Site, understand how it is used, and support our marketing activities. Accept all, reject all, or set your own preferences.
Your trusted
partner