<- Trust Center
Security & Responsible Technology

Information Security Policy

Governance and control principles for protecting Flex systems and information.

Effective Date: 1 August 2026Last Updated: 14 July 2026Version: 2.0Document Owner: Flex Online (Pty) Ltd

1. Introduction

Information security is fundamental to the operation of the Flex Platform and to the trust placed in Flex Online (Pty) Ltd ("Flex", "we", "our" or "us") by our Customers and Platform Users.

This Information Security Policy describes the principles, governance framework and security objectives that guide the protection of information processed by the Flex Platform.

It should be read together with our:

  • Security Overview;
  • Privacy Policy;
  • Responsible AI Policy;
  • Platform Terms;
  • Acceptable Use Policy; and
  • Vulnerability Disclosure Policy.

2. Purpose

The purpose of this Policy is to establish the principles by which Flex seeks to protect:

  • Customer Content;
  • Personal Information;
  • confidential business information;
  • platform services;
  • software assets;
  • supporting infrastructure; and
  • operational processes.

Our objective is to maintain appropriate safeguards that support the confidentiality, integrity and availability of information throughout the operation of the Flex Platform.

3. Scope

This Policy applies to information processed by Flex in connection with:

  • the Flex Platform;
  • the Flex Website;
  • Customer services;
  • implementation and support activities;
  • cloud infrastructure;
  • software development;
  • operational administration; and
  • internal business processes supporting the delivery of Flex services.

The implementation of specific security controls may vary depending on:

  • the nature of the service;
  • contractual commitments;
  • applicable legal requirements;
  • Customer configuration; and
  • assessed operational risk.

4. Information Security Objectives

Flex's information security programme is designed to support the following objectives:

Confidentiality

Protect information against unauthorised access or disclosure.

Integrity

Protect information against unauthorised modification, corruption or destruction.

Availability

Maintain appropriate levels of system reliability and service continuity.

Accountability

Ensure that actions affecting information can be appropriately attributed, monitored and reviewed.

Resilience

Develop systems and operational processes capable of responding to evolving security threats and business requirements.

5. Governance

Flex maintains governance processes intended to support the ongoing management of information security.

These processes may include:

  • documented security practices;
  • defined operational responsibilities;
  • risk management activities;
  • change management;
  • security reviews;
  • incident management;
  • internal oversight;
  • supplier management; and
  • continual improvement initiatives.

Information security is considered throughout the lifecycle of the Flex Platform rather than as a separate operational activity.

6. Risk Management

Flex adopts a risk-based approach to information security.

Security measures are selected having regard to:

  • the sensitivity of the information being processed;
  • applicable legal and contractual obligations;
  • evolving cyber-security threats;
  • operational requirements;
  • business continuity considerations;
  • Customer expectations; and
  • proportionality of risk.

Security risks are reviewed periodically and appropriate mitigation measures are implemented where reasonably practicable.

7. Identity and Access Management

Access to information is managed according to the principle of least privilege.

Flex seeks to ensure that:

  • access is granted only where authorised;
  • permissions are appropriate to operational responsibilities;
  • privileged access is appropriately controlled;
  • access is reviewed where appropriate;
  • authentication controls are maintained; and
  • access is removed when no longer required.

Customers remain responsible for managing access permissions within their own implementation of the Flex Platform.

8. Protection of Information

Flex implements appropriate safeguards to protect information throughout its lifecycle.

Depending on the relevant service and operational requirements, these safeguards may include:

  • logical access controls;
  • encryption technologies;
  • secure communications;
  • audit logging;
  • monitoring;
  • secure backups;
  • change management;
  • secure deletion processes;
  • environment separation;
  • vulnerability management; and
  • secure configuration practices.

The specific implementation of controls may evolve as technology and security practices develop.

9. Secure Development

Security considerations form part of the design, development, testing and maintenance of the Flex Platform.

Our development practices seek to support:

  • secure software design;
  • code quality;
  • vulnerability remediation;
  • dependency management;
  • controlled software releases;
  • change control;
  • regression testing;
  • operational monitoring; and
  • continuous platform improvement.

10. Supplier and Third-Party Security

Flex may engage third-party service providers to support the operation of the Flex Platform.

Where appropriate, Flex seeks to ensure that such providers:

  • are appropriately assessed for the services they provide;
  • maintain suitable security measures;
  • are subject to confidentiality obligations;
  • process information only for authorised purposes; and
  • comply with applicable contractual obligations.

Customers remain responsible for third-party services or integrations that they independently select or enable.

11. Information Classification

Flex recognises that not all information carries the same level of risk.

Information should be handled in a manner appropriate to its nature and sensitivity.

Examples of information that may require enhanced protection include:

  • Personal Information;
  • Customer Content;
  • authentication credentials;
  • confidential commercial information;
  • security-related information; and
  • proprietary software and technical documentation.

12. Incident Management

Flex maintains processes for identifying, assessing, responding to and learning from information security incidents.

Where reasonably necessary, these processes include:

  • incident identification;
  • investigation;
  • containment;
  • recovery;
  • communication;
  • preservation of relevant evidence;
  • post-incident review; and
  • continuous improvement.

Where Personal Information is affected, Flex will respond in accordance with applicable law, contractual obligations and the Privacy Policy.

13. Business Continuity

Flex recognises the importance of maintaining the availability of the Flex Platform.

Business continuity planning may include:

  • secure backup processes;
  • recovery planning;
  • operational monitoring;
  • infrastructure resilience;
  • disaster recovery procedures; and
  • restoration testing where appropriate.

Business continuity arrangements are reviewed and refined as operational requirements evolve.

14. Compliance

Flex seeks to operate its information security programme in accordance with applicable legal, regulatory and contractual obligations.

These may include:

  • the Protection of Personal Information Act (POPIA);
  • the EU GDPR where applicable;
  • the UK GDPR where applicable;
  • contractual security commitments; and
  • other applicable legal or regulatory requirements.

The precise allocation of compliance responsibilities depends on whether Flex acts as the Responsible Party, Operator, controller or processor in relation to the relevant Processing activity.

15. Roles and Shared Responsibility

Information security is a shared responsibility.

Flex is responsible for:

  • governing the security of the Flex Platform;
  • maintaining platform security controls;
  • protecting infrastructure under our control;
  • responding to security incidents; and
  • continually improving security practices.

Customers are responsible for:

  • configuring appropriate access permissions;
  • protecting their own organisational environments;
  • ensuring lawful use of the Flex Platform;
  • complying with applicable legal obligations;
  • managing Customer Content; and
  • educating Platform Users.

Platform Users are responsible for:

  • protecting their credentials;
  • complying with applicable policies;
  • reporting suspected security concerns;
  • using the Flex Platform responsibly; and
  • protecting information to which they have authorised access.

16. Continuous Improvement

Information security is an ongoing process.

Flex continually reviews:

  • emerging threats;
  • evolving technologies;
  • Customer feedback;
  • operational experience;
  • legal developments;
  • industry practices; and
  • security risks

to strengthen the security posture of the Flex Platform over time.

17. Related Documents

This Policy should be read together with:

  • Security Overview;
  • Privacy Policy;
  • Responsible AI Policy;
  • Platform Terms;
  • Acceptable Use Policy;
  • Vulnerability Disclosure Policy; and
  • Website Terms.

18. Contact

Questions regarding this Information Security Policy may be directed to:

Flex Online (Pty) Ltd

Email: trust@flexonline.io

Website: www.flexonline.io