Security & Compliance

Security & Compliance

This document outlines the security, privacy and compliance measures adopted by DSGN® S.R.L. to protect data, systems and stakeholders. It is intended to demonstrate the Provider’s structured, professional and compliance-oriented operational model.


1. Security by Design

DSGN® S.R.L. adopts a security-by-design and security-by-default approach across all projects, services and infrastructures.

Security considerations are integrated from the earliest design stages and continuously monitored throughout the service lifecycle.


2. Infrastructure Security

The Provider operates on enterprise-grade infrastructure, owned or managed directly, or provided by selected and certified third-party vendors.

Key security measures include, but are not limited to:

  • Virtual Private Servers (VPS), cloud and dedicated environments;
  • Geographic redundancy and fault-tolerant architecture;
  • Automated daily backups with off-site replication;
  • On-demand restore and disaster recovery procedures;
  • Content Delivery Network (CDN);
  • Load balancers and traffic optimization systems;
  • Web Application Firewall (WAF);
  • Network firewalls and intrusion prevention systems;
  • Anti-DDoS protection;
  • Secure access via SSH keys and restricted IPs;
  • Enforced HTTPS with SSL/TLS certificates;
  • HTTP Strict Transport Security (HSTS);
  • Continuous monitoring and automated alerting.

3. Application and Platform Security

For web platforms, e-commerce systems and custom applications, DSGN® S.R.L. applies:

  • Regular software and dependency updates;
  • Secure configuration of CMS, plugins and extensions;
  • Access hardening and credential rotation;
  • Segregation between development, staging and production environments;
  • Periodic vulnerability assessments.

4. Payment Security and PCI Compliance

Where payment processing is involved, DSGN® S.R.L. relies exclusively on PCI-DSS compliant third-party providers (e.g. Stripe, PayPal).

At no time does DSGN® S.R.L. store, process or access full payment card data on its own infrastructure.


5. Data Protection and Privacy Compliance

DSGN® S.R.L. processes Personal Data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable privacy regulations.

Privacy measures include:

  • Data minimization and purpose limitation;
  • Processing within the European Union, unless otherwise specified;
  • No unauthorized data transfers;
  • Encryption in transit and, where applicable, at rest;
  • Logical separation of customer data;
  • Defined data retention periods;
  • Documented procedures for data breach management.

6. Access Control and Internal Governance

Access to systems and data is strictly regulated through:

  • Role-based access control (RBAC);
  • Compartmentalized permissions based on job function;
  • Least-privilege principle;
  • Individual credentials for each collaborator;
  • Logging and traceability of administrative actions;
  • Immediate revocation of access upon role termination.

7. Third-Party Risk Management

Third-party providers are selected based on reliability, security posture and compliance guarantees.

Where applicable, data transfers outside the EU are governed by:

  • adequacy decisions;
  • Standard Contractual Clauses (SCCs);
  • EU–US Data Privacy Framework.

8. Compliance Monitoring

Security and compliance measures are periodically reviewed and updated to reflect:

  • technological evolution;
  • regulatory changes;
  • emerging security threats.

9. Transparency and Accountability

DSGN® S.R.L. promotes transparency towards clients and partners and remains available to provide additional compliance-related information upon request.


Last updated: 12th December 2025