Peak Presences

    Security & Data Protection

    Last updated: September 30, 2026

    Peak Presences takes the protection of customer information seriously. This page describes the reasonable safeguards we apply to protect information collected through our website and AI automation services. No system can be guaranteed to be completely secure, and we do not represent that our practices eliminate all risk.

    1. Protection of Customer Information

    We apply reasonable administrative, technical, and organizational safeguards designed to protect customer information against unauthorized access, alteration, disclosure, or destruction.

    2. Access Controls

    Access to systems and customer information is limited to authorized personnel who require access to perform their responsibilities. Access rights are reviewed and adjusted as roles and responsibilities change.

    3. Authentication

    We use authentication controls for access to internal systems and tools, including unique credentials for authorized users. Where appropriate, we encourage or require multi-factor authentication.

    4. Secure Transmission and Encryption

    Our website is served over HTTPS using TLS to help protect data in transit between your browser and our servers. Where appropriate, we apply encryption to sensitive information.

    5. Restricted Administrative Access

    Administrative and configuration access is restricted to a small number of authorized individuals and is granted on a least-privilege basis.

    6. Vendor and Service-Provider Management

    We work with third-party service providers, such as CRM, messaging, and hosting providers, to operate our services. We seek to engage providers that maintain reasonable security practices and limit their use of customer information to providing services on our behalf.

    7. Logging and Monitoring

    Where implemented, logging and monitoring help us detect and respond to unusual activity. We avoid placing sensitive personal information in application logs where reasonably possible.

    8. Data Minimization

    We seek to collect and retain only the information reasonably necessary to operate our website and provide our services. Additional details are described in our Privacy Policy.

    9. Secure Handling of API Credentials

    API keys, tokens, and integration credentials are handled as sensitive secrets. They are not exposed in client-side code, public repositories, or logs. Access to credentials is restricted to authorized personnel and systems.

    10. Environment Variables and Secrets

    Sensitive configuration, including environment variables and secrets, is kept out of the public-facing application bundle. Secrets are not committed to source repositories in plaintext.

    11. Incident Response

    We maintain a reasonable approach to identifying and responding to potential security incidents. If a confirmed incident affecting customer information occurs, we work to assess and respond appropriately, including notifying affected parties where required.

    12. Responsible Data Retention

    We retain personal information only as long as reasonably necessary to provide our services, comply with legal obligations, and document consents such as SMS opt-in records.

    13. Employee and Contractor Access

    Employees and contractors with access to customer information are expected to handle it in accordance with our security expectations. Access is granted on a need-to-know basis and may be revoked when no longer required.

    14. Customer Responsibility

    Customers are responsible for protecting their own account credentials, third-party platform credentials, and any information they share with us. We recommend using strong, unique passwords and enabling multi-factor authentication where available.

    15. No Certification Claims

    We do not claim any specific security certification unless we have verifiable evidence that it has been obtained. We do not represent that our services are certified under SOC 2, ISO 27001, HIPAA, PCI DSS, or GDPR, and we do not represent that any data is "100% secure."

    16. Reporting Security Concerns

    If you believe you have identified a security vulnerability or have a security concern, please contact us at [INSERT BUSINESS SUPPORT EMAIL] or through our contact page. We take reports seriously and will review them promptly.