Data Protection & Security
DJF IT Cyberworks Ltd takes a security-conscious approach to the design, development and operation of websites, digital systems, integrations and automation. This statement explains the principles we apply when protecting business information, client systems and personal data.
01 // Our Security Commitment
Security is considered throughout the lifecycle of the systems and services we develop.
We aim to use proportionate technical and organisational controls based on the nature of the project, the information involved and the risks that reasonably apply.
Access to administrative systems, infrastructure and credentials is restricted where reasonably practicable.
We aim to request and process only the information reasonably necessary for the relevant service or project.
Secure connections and encrypted transport technologies are used where appropriate.
Important systems, configurations and automated processes remain subject to human oversight where appropriate.
02 // Secure Development Practices
When developing websites and digital systems, we aim to follow practical security principles appropriate to the project.
These may include:
- Reducing unnecessary code, services and dependencies.
- Keeping sensitive credentials out of publicly accessible frontend code where practicable.
- Applying server-side validation to functions that require trusted processing.
- Restricting administrative functionality and sensitive system operations.
- Using appropriate input validation, access controls and request limits.
- Reviewing integrations and system behaviour before production deployment.
03 // Access Control & Credentials
Access credentials should be provided only to people who reasonably require them for the relevant purpose.
Where appropriate, administrative access may be restricted using passwords, account permissions, authentication controls or other technical safeguards.
Passwords, API keys, authentication tokens and other secrets should not be intentionally exposed in public website code, public repositories or publicly accessible documentation.
Clients are responsible for protecting credentials supplied to them and should notify DJF IT promptly if they believe a credential associated with a supported system has been compromised.
04 // Data Minimisation
We aim to minimise the amount of personal or confidential information required to provide our services.
Clients and website users should avoid sending passwords, payment-card information or highly sensitive personal information unless specifically requested through an appropriate secure process.
Where information is no longer reasonably required, it may be deleted, anonymised or securely disposed of in accordance with applicable retention requirements.
05 // Encryption & Secure Connections
DJF IT aims to use encrypted network connections such as HTTPS/TLS for public-facing web services where appropriate.
Secure transport helps protect information while it moves between a user's device, website infrastructure and relevant service providers.
Encryption is one part of a wider security approach and does not by itself guarantee that a system is immune from every possible threat.
06 // Hosting & Infrastructure
Websites and systems may be operated using professional hosting, cloud or infrastructure providers.
The exact infrastructure depends on the requirements of the project and may include web hosting, databases, email services, domain services, cloud platforms and external APIs.
Security is therefore a shared responsibility between DJF IT, the client and the relevant infrastructure or service providers.
07 // Third-Party Services & APIs
Some projects require integration with third-party platforms, APIs, payment providers, communications systems, hosting services or cloud technologies.
These services operate their own infrastructure and security controls and remain subject to their own terms, policies and technical limitations.
We aim to limit integrations to the access and data reasonably required for their intended purpose.
08 // AI Systems & Automation
Systems supplied or operated by DJF IT may incorporate artificial intelligence, automated workflows or specialist third-party technology services.
Where AI or automation processes information, we aim to design the workflow so that the system receives only information reasonably necessary for its intended function.
Sensitive credentials and privileged server-side functions should not be exposed to public AI interfaces.
AI-generated output may require human review, particularly where information could affect important business, financial, legal, safety or operational decisions.
09 // Backups & Recovery
Backup and recovery arrangements depend on the hosting environment, project scope and any maintenance or support service agreed with the client.
Where backup services form part of an agreed service, reasonable measures may be used to help reduce the risk of permanent data loss.
No backup or recovery mechanism can guarantee recovery from every possible event, and clients should maintain appropriate copies of business-critical information where reasonably necessary.
10 // Monitoring & Security Logs
Technical systems may generate logs required for security, diagnostics, abuse prevention, troubleshooting and system reliability.
Depending on the system, this may include technical information such as timestamps, request information, error records, browser or network information.
We aim to avoid retaining technical information for longer than is reasonably necessary for its intended operational or security purpose.
11 // Vulnerability Management
No internet-connected system can be guaranteed to be completely free from vulnerabilities.
Where DJF IT becomes aware of a security issue affecting a system that we actively support, we will assess the issue and take proportionate action where reasonably required within the scope of the service.
Depending on the circumstances, action may include configuration changes, access restriction, software updates, credential replacement or liaison with relevant service providers.
12 // Security Incident Response
Suspected security incidents are assessed according to their nature, severity and potential impact.
Where appropriate, steps may include:
- Identifying and containing the affected component.
- Restricting or replacing compromised credentials.
- Reviewing relevant technical information.
- Applying corrective or preventative measures.
- Informing affected clients or relevant third parties where reasonably required.
- Taking any notification action required by applicable law.
13 // Personal Data Breaches
Where an incident involves personal data, DJF IT will assess whether the incident constitutes a personal data breach and what action is required under applicable data-protection law.
Where notification to a client, regulator or affected individual is legally required, appropriate steps will be taken in accordance with the applicable requirements.
14 // Client Responsibilities
Security depends on both the system provider and the people using the system.
Clients should:
- Use strong and unique passwords.
- Enable additional authentication controls where available and appropriate.
- Avoid unnecessarily sharing administrator credentials.
- Remove access for users who no longer require it.
- Keep devices used to access business systems reasonably secure.
- Notify DJF IT of suspected compromise relating to a system that we support.
- Maintain appropriate backups of critical business information where required.
15 // Data Protection
Security measures form part of our wider approach to data protection.
Further information about the categories of personal information we may process, purposes, lawful bases, retention and individual rights is available in our Privacy Policy .
Information about website cookies and optional analytics is available in our Cookie Policy .
16 // Security Is Risk-Based
Different projects carry different levels of risk. The controls appropriate for a simple informational website may differ from those required for a system handling accounts, payments, business data or third-party integrations.
Security arrangements may therefore be adjusted according to the nature, complexity and scope of each project.
IMPORTANT: This statement describes DJF IT Cyberworks Ltd's general security approach. It does not represent a guarantee that any website, software platform, infrastructure provider or connected system is completely immune from cyber attack, technical failure, human error or previously unknown vulnerabilities.
17 // Reporting a Security Concern
If you believe you have identified a security issue affecting djfit.pro or a system actively supported by DJF IT, please contact us directly.
Email: hello@djfit.pro
Please provide sufficient information for us to understand and investigate the issue, but do not send passwords, private keys or unnecessary sensitive information by ordinary email.
18 // Review & Updates
This statement may be reviewed and updated as our services, systems, technology or applicable requirements change.
The latest version will be published on this page together with its revision date.
Security Contact
DJF IT CYBERWORKS LTD
16760496
England and Wales
34 Selworthy Drive
Crewe
England
CW1 3RR