Last updated: July 23, 2026

Information Security Policy

HeroDash is a global customer-service SaaS platform operated by Callnovo USA, Inc. (formerly Upcross Solutions, Inc.) and built on the Callnovo brand's customer-service expertise serving cross-border e-commerce enterprises since 2004. As an authorized TikTok Shop Partner (ISV) and a registered Amazon Selling Partner API (SP-API) developer, HeroDash may process customer, conversation, and order data on behalf of these platforms and their sellers in order to deliver the contracted customer-service functionality.

This Information Security Policy is a public statement of the security program and controls that HeroDash has adopted to protect that data. It is governed by senior management and implemented through an Information Security Management System (ISMS) aligned with the ISO/IEC 27001 standard. This policy supplements, and should be read together with, our Privacy Policy.

1. Purpose and Scope

The purpose of this policy is to define the principles and controls HeroDash uses to protect the confidentiality, integrity, and availability of information assets, including personal data processed on behalf of our customers and the platforms and sellers we serve.

This policy applies to all HeroDash employees, contractors, systems, networks, and third parties that access or process data within the scope of our services, across all locations in which we operate.

2. Governance and Responsibilities

Information security is owned and supported by senior management, who allocate the resources required to maintain and continually improve our ISMS.

Security roles and responsibilities are formally defined. A Data Protection Officer (DPO) oversees data protection and privacy compliance, and designated personnel are responsible for operating, monitoring, and reviewing security controls.

Our ISMS is aligned with ISO/IEC 27001 and is subject to regular internal audits, management reviews, and continual improvement.

3. Security Policy Framework

We maintain a set of formally approved, documented, and regularly reviewed security policies and procedures, including:

• Information Security Policy (this document and its supporting standards).

• Access Control Policy.

• Data Classification and Encryption Policy.

• Acceptable Use and Endpoint Security Baseline.

• Incident Response Policy.

• Vulnerability and Threat Management Procedure.

• Personal Data Protection Policy.

These policies are reviewed at least annually and after any significant change, and are communicated to relevant personnel.

4. Access Control

Access to systems and personal data is granted strictly on a least-privilege, need-to-know basis using role-based access control (RBAC).

Multi-factor authentication (MFA) is enforced for access to sensitive systems and administrative functions. Each user has a unique account; shared credentials are prohibited.

Access is provisioned through a formal joiner-mover-leaver process, reviewed periodically, and revoked promptly when no longer required or upon termination.

5. Data Classification and Encryption

Information is classified according to its sensitivity, and handling, storage, and transmission requirements are applied to each classification level.

Personal and sensitive data is encrypted in transit using TLS 1.2 or higher and at rest using industry-standard algorithms such as AES-256. Encryption keys are managed securely and access to them is restricted.

6. Network Security and Segregation

Our production environment is logically segregated into separate network zones (for example, public, application, and data tiers), with firewalls and security-group rules restricting traffic between them.

We deploy protective measures and continuously monitor network traffic to detect and prevent network-based threats. Administrative access to infrastructure is restricted and protected.

7. Endpoint Security and Baseline

All company endpoints run anti-virus / endpoint security software (Bitdefender Endpoint Security), centrally managed with real-time protection, automatic updates, and periodic scans.

We enforce a security baseline for daily operations, including automatic screen locking, strong password and account-lockout policies, full-disk encryption, and timely operating-system and software patching.

8. Logging, Monitoring, and Detection

Security-relevant events across our systems and networks are logged and monitored to support detection, investigation, and timely response.

Logs are protected against tampering and retained for a period consistent with operational and legal requirements.

9. Vulnerability and Threat Management

We operate a vulnerability and threat management process that includes regular vulnerability scanning, risk-based prioritization, and timely patching of identified weaknesses.

We perform periodic security testing and track remediation to completion. Emerging threats are assessed and addressed as part of ongoing risk management.

10. Secure Development and Credential Protection

Software is developed following a secure development lifecycle that includes code review and separation of development, testing, and production environments.

API keys, application secrets, and platform credentials (including TikTok Shop app keys and secrets) are stored securely, restricted to authorized personnel, and never exposed in client-side code or public repositories.

11. Incident Response and Breach Notification

We maintain a documented Incident Response Policy with clearly assigned roles, responsibilities, and escalation paths.

In the event of a security incident or personal data breach, we will contain and remediate the incident and notify affected platforms, sellers, individuals, and supervisory authorities without undue delay, in accordance with applicable law and our contractual commitments.

12. Data Protection and Privacy

We maintain an internal Personal Data Protection Policy, reviewed and updated at least annually, governing how personal data is collected, processed, stored, retained, and deleted.

Where we act as a service provider, we process personal data only on the documented instructions of the relevant merchant or platform, and we assist them in responding to data subject access, correction, and deletion requests. We do not use platform or seller data for any purpose beyond delivering the contracted services.

13. Data Retention and Deletion

Personal data is retained only for as long as necessary to provide our services and to meet legal and contractual obligations.

Upon a valid deletion request or at the end of the contractual relationship, we will return or securely delete all collected customer data in our possession in accordance with the controller's instructions and within a reasonable period.

14. Data Residency and International Transfers

Personal data processed in connection with our TikTok Shop services is primarily stored and processed in the United States of America.

Where personal data is transferred across borders, we apply appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms, where applicable) so that the data continues to receive an adequate level of protection.

15. Third-Party and Sub-processor Management

We engage sub-processors only where necessary to deliver our services and after assessing their security and privacy practices.

Sub-processors are bound by written agreements (including Data Processing Agreements where applicable) requiring them to protect personal data and to use it only for the purposes we specify. A current list of sub-processors is available on request from our DPO.

16. Personnel Security and Awareness

Employees and contractors are bound by confidentiality obligations and are subject to appropriate screening consistent with applicable law and their role.

Personnel receive security awareness training so that security practices are understood and followed in daily operations.

17. Business Continuity and Backup

We maintain backup and recovery procedures for critical systems and data, and we take measures to ensure the resilience and availability of our services.

18. Compliance and Certifications

Our information security program is designed in alignment with the ISO/IEC 27001 framework. We align our practices with applicable data protection laws and regulations, including the GDPR and the CCPA/CPRA, as well as the data security requirements of the platforms we partner with, including TikTok Shop and Amazon (including the Amazon Acceptable Use Policy and Data Protection Policy).

Additional documentation about our security controls can be provided to partners and platforms under appropriate confidentiality arrangements.

19. Policy Review and Contact

This policy is reviewed at least annually and updated as needed to reflect changes in our practices, technology, or legal obligations.

For security or data protection inquiries, or to request supporting documentation, please contact our Data Protection Officer at hello@herodash.ai.