Security & Monitoring Policy
Practical security responsibilities for the store and business software users.
Last updated: 28 September 2026
Scope
This policy covers website and account security, support communications, proportionate investigation of misuse, and the responsibilities connected with GMITrend software. Monitoring in this policy means security-related review of our own website or services; it is not a separate managed cybersecurity or infrastructure-monitoring service.
Safe communications
The store uses HTTPS to protect web traffic in transit. Check the domain before signing in or paying. HTTPS does not make a compromised device or a phishing message safe. Do not send passwords, private keys, full card details or unredacted business databases by ordinary support email.
Access and authorisation
Use strong, unique credentials and restrict access to people who need it. Where a product offers additional account controls, use them according to its documentation. Notify us if you suspect an exposed key or unauthorised access. Permission and user limits must reflect the purchased product.
Data minimisation
Send only information needed to resolve a problem. Redact personal, payroll and customer details from screenshots where possible. If a case needs a confidential file, first agree an appropriate transfer and access method. Support permission for a particular investigation is not permission for unrelated use of the file.
Store and product responsibilities
GMITrend is responsible for reasonable care in the systems and services it supplies. Customers remain responsible for their own devices, authorised users, source-data accuracy and business continuity. Product-specific hosting, access control, backup and export provisions depend on the product you buy; a software licence should not be assumed to include every hosted-service feature.
Security reviews may involve relevant access attempts, technical errors, order events and reports of misuse. Any review must be proportionate, limited to authorised information and handled in line with the Privacy Policy. Purchasing a product does not authorise monitoring somebody else’s systems.
Backups and updates
Keep independent copies of records you need to retain and follow supported update guidance. A software licence is not a backup service unless the product expressly includes one. Do not assume a 12-month licence creates permanent storage. Before expiry, review the product’s stated export and access process.
Payment information
Enter card details only through the payment method offered by the checkout. Payment-provider authentication is separate from product activation. Customer support must not request card security codes or ask you to bypass a bank’s verification. No claim of PCI certification or processor endorsement is made by this policy.
Incidents and reporting
Report a suspected issue to [email protected] with the affected URL/product, approximate time, steps to reproduce and redacted evidence. Do not exploit a suspected weakness or access another person’s information. We will assess the report, take proportionate action on systems under our control and provide notifications where the law requires them.
Investigation may require temporary restriction of affected access. It does not remove mandatory remedies if the purchased service cannot be supplied.
Contact
GMITrend
41, Meadow Drive, Saltash PL12 6XJ UK
Email: [email protected]