1. Purpose

The purpose of this policy is to establish a structured and secure framework for managing relationships with third-party vendors, suppliers, and service providers that have access to GoPerfect systems, data, or services. This policy ensures that all third parties comply with our security, data privacy, and business continuity requirements.

2. Scope

This policy applies to all third-party entities that process, store, or have access to GoPerfect’s systems, infrastructure, customer data, and other confidential information. It includes:

3. Third-Party Selection & Due Diligence

Before onboarding a third-party supplier, GoPerfect conducts a due diligence process to assess security, compliance, and operational risks. This includes:

  1. Security Assessment:
  2. Legal & Compliance Review:
  3. Operational & Financial Risk Assessment:
  4. Incident Response & Business Continuity:
  5. Contractual Safeguards:

4. Data Security and Access Controls

GoPerfect enforces strict access controls for third-party suppliers based on the principle of least privilege (PoLP):

  1. User & Access Management: