Public security framework
Operator
Business name: e-Trading, s.r.o.
Registered office: Jelšová 4951/26, 949 01 Nitra, Slovak Republic
Company ID (IČO): 43 916 309
Tax ID (DIČ): 2022614913
Register: Commercial Register of the District Court Nitra, Section Sro, Insert No. 21920/N
Public contact: via the contact form on the Feedify website at /en/contact.
1. Our approach
Security is part of the design and operation of Feedify. The aim is to protect the confidentiality, integrity and availability of data and accounts in a manner proportionate to the risk, without disclosing in public documentation details that could reduce the security of the system.
2. Encrypted communication
Communication between the user and Feedify takes place over secure protocols. Sensitive integration and authentication values are protected using appropriate cryptographic mechanisms and are not stored in plaintext where this is not necessary.
3. Account protection and authentication
- passwords are not stored in readable form,
- Feedify supports two-factor authentication (2FA) as an additional layer of account protection,
- security-sensitive actions may require identity to be verified again or a second factor to be provided,
- session and access mechanisms are designed so that loss of a valid session does not result in access to internal content.
4. Separation of Client data and permissions
Feedify applies authorization according to company and Portal context. The aim is for a user to access only the data and services of their Client and for internal operations to respect the same permission boundaries.
5. Integrations and secret values
Where Feedify requires integration credentials or secret values, it handles them as sensitive data. Public documentation does not disclose storage methods, internal keys, tokens, identifiers or the mechanics of integration controls.
6. Security logging and audit
Relevant operational and security events may be logged for diagnostics, audit, client protection and incident response. Logging is designed so that it does not become an unnecessary store of passwords, secret values or full sensitive payloads.
7. Operations, monitoring and recovery
Feedify uses appropriate monitoring, maintenance and recovery procedures and infrastructure suitable for an online B2B service. Specific internal limits, topology and schedules are not disclosed for security and operational reasons.
8. Incident response
- an incident is assessed according to its impact and severity,
- the priority is to limit the impact, restore secure operation and identify the cause,
- if an incident involves personal data, it is handled in accordance with the GDPR and the applicable DPA,
- affected Clients are informed where required by the legal framework or where appropriate in view of the impact.
9. Client security responsibilities
- protect login credentials and devices,
- use a unique and appropriately strong password,
- enable 2FA, especially for an account with access to production data,
- do not provide Feedify access to persons who do not need it,
- keep data sources, SFTP and other external access secure and up to date,
- report any suspected account misuse without undue delay via the contact form.
10. Reporting a security issue
A security issue can be reported via the Feedify contact form using the Technical question topic. We recommend including a description, the affected function, the time of discovery and reproduction steps, without disclosing sensitive data in a public space.
11. Proportionality and changes
Security measures are continuously adapted to risks, the state of the art and the development of the service. This document describes the public framework and does not constitute a complete list of internal controls or an absolute guarantee that an incident can never occur.
Effective from: 10 September 2026.