Security Policy
Last updated: September 20, 2025
Field Notes Daily is committed to protecting the security of our platform, our users' data, and the integrity of all information processed through our services. This Security Policy describes the technical and organizational measures we apply to safeguard our systems and your information.
1. Scope
This policy applies to all systems, infrastructure, applications, and services operated by Field Notes Daily, including our website at fieldnotesdaily.eu, our online learning platform, and any associated tools or integrations used to deliver our masterclass content.
2. Data Protection Principles
We apply the following core principles to all data we handle:
- Confidentiality: Access to personal and sensitive data is restricted to authorized personnel only.
- Integrity: We take measures to ensure that data is accurate, complete, and protected from unauthorized modification.
- Availability: We work to ensure our services remain accessible and resilient against disruption.
- Minimization: We collect and retain only the data necessary for the purposes described in our Privacy Policy.
3. Infrastructure Security
3.1 Hosting and Network
Our platform is hosted on infrastructure that applies industry-standard physical and network security controls. These include perimeter firewalls, intrusion detection systems, and network segmentation to isolate sensitive components.
3.2 Encryption in Transit
All data transmitted between users and our platform is encrypted using TLS (Transport Layer Security). We enforce HTTPS across all pages and services and do not permit unencrypted connections.
3.3 Encryption at Rest
Sensitive data stored on our systems is encrypted at rest using recognized encryption standards. This includes user credentials, payment-related tokens, and personal account information.
3.4 System Hardening
Servers and services are configured following security hardening guidelines. Unnecessary services, ports, and protocols are disabled. Operating systems and software dependencies are kept up to date with security patches.
4. Access Control
4.1 Principle of Least Privilege
Access to systems, databases, and user data is granted on a need-to-know basis. Employees and contractors receive only the minimum level of access required to perform their responsibilities.
4.2 Authentication
Internal access to production systems requires strong authentication. Multi-factor authentication is enforced for administrative access. Default credentials are never used and are changed upon initial setup.
4.3 Access Reviews
Access permissions are reviewed periodically and revoked promptly when an individual's role changes or their engagement with Field Notes Daily ends.
5. Application Security
5.1 Secure Development Practices
Our development process incorporates security considerations at each stage. Code changes undergo review before deployment. We follow recognized secure coding guidelines to reduce the risk of common vulnerabilities including injection attacks, cross-site scripting, and insecure authentication flows.
5.2 Dependency Management
Third-party libraries and dependencies used in our platform are monitored for known vulnerabilities. Updates and patches are applied in a timely manner.
5.3 Testing
We conduct security testing as part of our development and release processes. This includes automated scanning and periodic manual review of critical components.
6. Monitoring and Logging
Our systems generate logs of significant events including authentication attempts, administrative actions, and system errors. Logs are retained for a defined period and reviewed to detect anomalous or potentially harmful activity. Alerts are configured to notify responsible personnel of events that may indicate a security incident.
7. Incident Response
We maintain an internal process for identifying, assessing, and responding to security incidents. In the event of a confirmed breach or security event affecting user data, we will:
- Contain and investigate the incident promptly.
- Assess the scope and potential impact on affected users.
- Notify affected users and relevant authorities where required and within applicable timeframes.
- Take corrective action to prevent recurrence.
If you believe you have identified a security issue affecting our platform, please contact us at info@fieldnotesdaily.eu so we can investigate and respond appropriately.
8. Third-Party Services
We use third-party service providers to support the operation of our platform, including payment processing, email delivery, and analytics. We select providers that maintain their own security programs and we enter into agreements that include appropriate data protection obligations. We do not sell user data to third parties.
9. Employee Responsibilities
All personnel with access to our systems or user data are expected to:
- Follow this policy and related internal security guidelines.
- Use strong, unique credentials for all systems.
- Report suspected security incidents or vulnerabilities without delay.
- Handle user data with care and discretion.
Personnel receive guidance on security practices relevant to their roles.
10. Physical Security
Our administrative offices and any facilities handling sensitive information apply physical access controls appropriate to the environment. Workstations are locked when unattended and sensitive materials are handled and disposed of securely.
11. Business Continuity
We maintain backup procedures to support recovery in the event of data loss or system failure. Backups are stored securely and tested periodically to verify their integrity and usability.
12. Policy Review
This Security Policy is reviewed at least annually and updated as necessary to reflect changes in our practices, technology, or applicable requirements. Continued use of our platform following an update constitutes acceptance of the revised policy.
13. Contact
If you have questions about this Security Policy or wish to report a security concern, please contact us:
Field Notes Daily
4160 Clark St, Montreal, Quebec H2W 1G2, Canada
Phone: +1 418 226 6225
Email: info@fieldnotesdaily.eu
Website: fieldnotesdaily.eu