Policy Center

Data Security and Handling Statement

Effective date: July 25, 2026

This statement summarizes ProTek's standard practices for protecting customer information during repair, data transfer, data recovery, managed IT, cybersecurity, backup, and related technical services.

1. Core Principles

  • Customer information is treated as confidential.
  • Access is limited to authorized personnel with a legitimate service need.
  • ProTek seeks to collect and retain only information reasonably necessary for the service, security, business operations, and legal obligations.
  • Customer data is not browsed or reviewed beyond what is reasonably necessary to perform authorized work.

2. Access Controls

ProTek uses individual user accounts, role-based permissions, administrative access restrictions, and multi-factor authentication where supported and appropriate. Privileged actions are limited to authorized personnel and are documented in service records or audit logs where applicable.

3. In-Lab File Handling

During standard in-lab data transfer and data recovery services:

  • customer file content is processed within ProTek's controlled facility unless another method is authorized;
  • working data is stored on approved encrypted storage systems;
  • transfers occur over secured internal networks or direct device connections;
  • customer data is logically separated from other customer data;
  • recovery systems are not used for unrelated general-purpose activity; and
  • temporary working copies are deleted under the 30-day retention rule unless an exception applies.

4. Physical Security and Chain of Custody

Customer devices and storage media are checked in, labeled, photographed when appropriate, and stored in designated areas. Access to nonpublic work and storage areas is restricted. Device movement and off-site handling are documented when required by the service.

5. Credentials

Credentials are requested only when necessary. Employees may not store client credentials in personal tools, share them without authorization, or forward them to personal accounts. Suspected credential exposure must be reported immediately. Access is revoked or rotated when roles change, employment ends, or compromise is suspected.

6. Backups and Diagnostics

When feasible and authorized, technicians attempt to protect customer data before diagnostics or stress testing that could increase failure risk. Backup integrity is checked by reviewing copied structure, file sizes, and readability. If backup is not possible or a drive shows signs of imminent failure, work is paused and escalated for customer direction.

7. Cloud and Service Providers

Business records and managed-service data may be processed by approved service providers for hosting, communications, security, payments, backups, and support. Providers receive only the information reasonably necessary for their function and are subject to contractual, technical, or account-level safeguards appropriate to the service.

8. Employee Safeguards

Employees and authorized contractors are subject to confidentiality obligations, acceptable-use rules, credential controls, security training, and disciplinary measures for violations. Customer screenshots, photos, ticket information, or data may not be published or placed in personal storage without authorization.

9. Incident Response

Suspected unauthorized access, loss, disclosure, or security incidents are escalated promptly. ProTek investigates, contains, documents, and mitigates incidents and provides notifications when required by contract or law.

10. Limitations

No security program eliminates all risk. This statement describes standard practices and does not guarantee against every threat, failure, or loss. Specific client agreements may impose additional controls.

11. Contact

Security and data-handling questions may be sent to support@protek.team.