1. Purpose
This Security Policy describes the technical and organisational measures TTL Media Private Limited ("Oye Creators", "we", "us") applies to protect the platform and the personal and business data processed through it. It supports our obligations under the Digital Personal Data Protection Act, 2023, the Data Processing Agreement and the Privacy & Cookies Policy.
2. Scope
This Policy applies to all information assets owned or operated by Oye Creators, including the web dashboard, the creator mobile applications, supporting APIs, databases, analytics systems and the devices and accounts used by our personnel to access them. It applies to all employees, contractors, interns and vendors who are granted access to those assets.
Vendors and subprocessors engaged to process data on our behalf are listed on the Vendor & Subprocessor List and are bound by contractual security obligations no less protective than this Policy.
3. Governance & Responsibility
- Overall accountability for information security rests with the management of TTL Media Private Limited.
- A designated security owner maintains this Policy, tracks risks and reviews access rights.
- Security incidents, questions and suspected vulnerabilities may be reported to Support@ttlmedia.in; reports made in good faith will not be penalised.
- Personnel receive security and data-protection guidance on joining and are bound by confidentiality obligations that survive the end of their engagement.
4. Access Control
- Access is granted on the principle of least privilege and only for a defined business purpose.
- Accounts are individual; shared logins are not permitted for administrative access.
- Multi-factor authentication is required for administrative and production access.
- Access rights are reviewed periodically and revoked promptly when a role changes or an engagement ends.
- Production credentials and API keys are stored in a managed secret store, rotated on a defined schedule and never committed to source control.
5. Risk Assessment & Incident Response
We assess risks to confidentiality, integrity and availability when introducing significant changes to the platform, and periodically thereafter. Identified risks are recorded, assigned an owner and tracked to closure.
Suspected incidents are triaged on receipt. Our response follows a defined sequence: contain, investigate, remediate, notify and review. Where a personal-data breach is likely to result in risk to affected individuals, we notify the Data Protection Board of India and affected data principals as required by the Digital Personal Data Protection Act, 2023, and notify affected Clients without undue delay so they can meet their own obligations. Breach notification duties between the parties are set out in the Data Processing Agreement.
6. Data Classification & Lifecycle
| Classification | Examples | Handling Rules |
|---|---|---|
| Public | Marketing materials, public blog posts | No special controls; published on public sites |
| Internal | Internal memos, non-sensitive logs | Access restricted to authenticated employees |
| Confidential | Personal profiles, campaign briefs | Encrypted at rest, strict RBAC, audit logging |
| Highly Confidential | Payment details, government IDs | AES-256 encryption, MFA for access, segregated backups |
Data Lifecycle:
- Collection: Only what's needed for matching, billing, reporting.
- Storage: Encrypted databases + hardened file servers.
- Use: Access limited by "least privilege."
- Archival: Moved to cold storage after 12 months, encrypted.
- Deletion: Secure deletion (cryptographic wipe) upon request or end-of-retention.
7. Technical Controls
7.1. Access Control:
- RBAC: Roles defined for Brands, Creators, Admins, DevOps.
- MFA: Mandatory for all admin/dev accounts.
- Password Policy: Minimum length 12, complexity, rotation every 90 days.
7.2. Cryptography:
- In Transit: TLS 1.2+ for all web and API traffic.
- At Rest: AES-256 for databases, file storage, backups.
- Key Management: HSM for master keys; periodic rotation.
7.3. Network & Infrastructure:
- Firewalls & Segmentation: Public DMZ for web servers; private subnets for databases.
- IDS/IPS: 24×7 monitored for anomalies.
- VPN & Bastion Hosts: Required for any remote admin access.
7.4. Endpoint & Application Security:
- Secure Coding: OWASP Top 10 mitigations, code reviews, static analysis.
- Penetration Testing: Bi-annual by third-party specialists.
- Patch Management: Critical patches applied within 72 hours.
8. Organizational Measures
- 8.1. Policies & Procedures: Defines acceptable use, change management.
- 8.2. Training & Awareness: Security induction, quarterly phishing drills.
- 8.3. Incident Response: IR Plan with roles, notifications.
- 8.4. Vendor Management: Due diligence, Data Processing Agreements.
9. Physical & Environmental Security
- Data centers with 24×7 surveillance, biometric access controls, fire suppression.
- Office badge access, visitor logs, locked server rooms.
10. Business Continuity & Disaster Recovery
- BCP/DR Plan: Annual exercises; RTO ≤ 4h, RPO ≤ 1h.
- Encrypted offsite backups; quarterly integrity tests.
11. Data Retention & Secure Disposal
- Personal Profiles: 2 years post-deactivation.
- Financial Records: 7 years per Indian tax laws.
- Secure erase for disks; shredding for paper.
12. Audit, Monitoring & Reporting
- Logging: All access, configuration changes.
- SIEM: Correlates logs, triggers alerts.
- Monthly dashboards on patch status, incidents, audit findings.
13. Roles & Responsibilities
Brands & Creators:
- Use strong, unique passwords.
- Report suspected account compromise.
Platform Administrators:
- Enforce policies, approve access requests.
- Lead incident response.
Employees:
- Follow security training.
- Handle data per classification rules.
14. Indemnification & Liability
Brands and Creators agree to indemnify and hold harmless Oye Creators, its officers, and employees against any claims, damages or losses arising from:
- Your negligence (e.g., sharing credentials).
- Misuse of the platform or breach of this Policy.
Liability is capped per our Terms of Service, except where prohibited by law.
15. Review & Updates
- Policy Review: Annually or upon legal/technical changes.
- Versioning: "Last Updated" date displayed on our website.
Questions or Concerns? Contact security@oyecreators.com.