Data Classification Policy
Version 1.0 · effective 23 September 2026
This is an English translation provided for convenience. In the event of any discrepancy, the Polish version prevails.
Every piece of information we process is assigned a classification level. The level determines who may access it, where it may be stored, how it is protected and how it is deleted. The Policy applies to all people and systems working for the Platform.
1. Classification levels
| Level | Definition | Examples |
|---|---|---|
| P0 — Public | intended for publication; disclosure causes no harm | the signaltoinsight.com site, legal documents, public API documentation, marketing material |
| P1 — Internal | intended for the team; disclosure causes minor harm | technical documentation, work plans, aggregated statistics without personal data |
| P2 — Confidential | disclosure may harm a Customer, an individual or the company | all Customer Data, User account data, logs containing IP addresses, contracts, billing data |
| P3 — Restricted | disclosure enables takeover of accounts or systems, or causes serious harm | OAuth tokens and API keys, vault secrets, encryption and signing keys, sign-in codes, special-category data, reports of unpatched vulnerabilities |
Where the level is not obvious, the higher one applies. Customer Data is always at least Confidential regardless of its content — we do not assess Customer content in order to lower its protection.
2. Handling rules
| P0 | P1 | P2 | P3 | |
|---|---|---|---|---|
| Access | anyone | team | authorised people, by role and Workspace | system or designated people only; access logged |
| Storage | any | company systems | production systems in the EEA or sub-processors under contract | encrypted only (AES-256-GCM) or in a secrets manager |
| Transmission | any | company channels | encrypted only (TLS) | encrypted only; never in e-mail, chat, tickets or repositories |
| Logs | unrestricted | unrestricted | minimal, with a defined retention period | never logged; identifier or hash only |
| Test environments | yes | yes | no — synthetic or demo data only | no |
| Deletion | any | standard | permanent, per retention periods | immediate revocation and permanent deletion |
3. Data and artificial intelligence
P2 data may be sent to AI model providers only at a User’s instruction, to the extent the task requires, and only to providers contractually barred from training on submitted data. P3 data is never sent to AI models.
4. Breach of these rules
Disclosure of P2 or P3 information beyond its permitted scope is a security incident and is handled under the Information Security Policy. A P3 secret that reached a prohibited place is treated as compromised and revoked, even if no use of it has been detected.
5. Review
The classification of new kinds of data is set when designing the feature that introduces them. The Policy is reviewed at least annually.