We collect analytics and preference data to personalise your quiz experience and measure how meal prep content performs across our platform.

Decline
Bithavo Lurax
Bithavo Lurax Meal prep quizzes & interactive learning

Security Policy

Last Updated: February 8, 2025

Bithavo Lurax is committed to maintaining the security, integrity, and confidentiality of all data processed through bithavolurax.com. This Security Policy describes the technical and organizational measures we apply to protect our platform and the information entrusted to us by our users.


1. Scope

This policy applies to all systems, infrastructure, software, and processes operated by Bithavo Lurax that support the delivery of our online educational platform. It covers all data processed on behalf of users, including account information, learning progress, quiz results, and communication records.


2. Data Protection Principles

We handle all user data in accordance with the following core principles:


3. Infrastructure Security

3.1 Hosting and Network

Our platform is hosted on infrastructure that includes industry-standard physical and logical security controls. Network traffic is monitored continuously, and access to internal systems is restricted through firewall rules, network segmentation, and access control lists.

3.2 Encryption

All data transmitted between users and our platform is encrypted using Transport Layer Security (TLS). Data stored on our servers is encrypted at rest using recognized encryption standards. Encryption keys are managed securely and rotated on a defined schedule.

3.3 Server Hardening

All production servers are configured following security hardening guidelines. Unnecessary services, ports, and software are disabled or removed. Operating systems and software dependencies are kept up to date with security patches applied promptly.


4. Access Control

4.1 Principle of Least Privilege

Access to systems, databases, and sensitive data is granted only to personnel who require it to perform their job functions. Permissions are reviewed regularly and revoked promptly when no longer needed.

4.2 Authentication

All administrative access to internal systems requires strong authentication. Multi-factor authentication is enforced for privileged accounts. Passwords must meet defined complexity requirements and are stored using one-way cryptographic hashing.

4.3 User Account Security

User accounts on the platform are protected by session management controls including secure token handling, session expiration, and protection against session fixation. Users are encouraged to use strong, unique passwords for their accounts.


5. Application Security

5.1 Secure Development Practices

Security is integrated into our software development lifecycle. Development teams follow secure coding guidelines to mitigate common vulnerabilities including those identified in recognized security frameworks and industry standards.

5.2 Vulnerability Management

We conduct periodic security assessments including vulnerability scanning and code reviews. Identified vulnerabilities are prioritized and remediated according to their severity. Critical issues are addressed on an expedited basis.

5.3 Third-Party Dependencies

Third-party libraries and components used in our platform are monitored for known security vulnerabilities. Updates and patches are applied in a timely manner to reduce exposure to known risks.


6. Monitoring and Logging

Our systems maintain detailed logs of authentication events, administrative actions, data access, and system errors. Logs are stored securely and retained for a defined period to support security investigations and audit requirements. Automated monitoring tools alert our team to anomalous or suspicious activity in real time.


7. Incident Response

7.1 Detection and Containment

We maintain an incident response process to detect, classify, and contain security incidents promptly. Upon detection of a potential security event, our team initiates investigation procedures to assess the nature and scope of the incident.

7.2 Notification

In the event of a security incident that affects user data, we will notify affected users and relevant parties within a reasonable timeframe and in accordance with applicable obligations. Notifications will include a description of the incident, the data involved, and the steps being taken to address the situation.

7.3 Post-Incident Review

Following resolution of any security incident, we conduct a post-incident review to identify root causes, evaluate the effectiveness of our response, and implement improvements to prevent recurrence.


8. Physical Security

Physical access to data centers and server infrastructure is restricted to authorized personnel only. Facilities used to host our systems maintain physical security controls including access logging, surveillance, and environmental protections against fire, flood, and power disruption.


9. Employee Security

All personnel with access to user data or internal systems are subject to security awareness training. Employees are informed of their responsibilities regarding data protection and acceptable use of company resources. Access rights are reviewed upon changes in employment status and revoked immediately upon termination.


10. Third-Party Service Providers

We work with third-party service providers who may process or store data on our behalf. All such providers are evaluated for their security practices prior to engagement. We require third parties to maintain appropriate security standards and to process data only as instructed and for defined purposes.


11. Backup and Recovery

User data and system configurations are backed up on a regular schedule. Backups are stored securely and tested periodically to verify that data can be restored successfully. Recovery procedures are documented and reviewed to ensure business continuity in the event of system failure or data loss.


12. Responsible Disclosure

We welcome reports from security researchers and users who identify potential vulnerabilities in our platform. If you believe you have discovered a security issue, please contact us at info@bithavolurax.com before disclosing it publicly. We are committed to investigating all reports promptly and working toward resolution in good faith.


13. Changes to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this page. We encourage users to review this policy periodically to stay informed about how we protect their information.


14. Contact Us

If you have questions or concerns about this Security Policy or our security practices, please contact us using the details below:

Contact Method Details
Company Bithavo Lurax
Email info@bithavolurax.com
Phone +380362245731
Address Shveds'ka St, 2, Poltava, Poltava Oblast, Ukraine, 36000
Website bithavolurax.com