Security at Bliko

Ensuring our customers' data remains secure is our top priority.

This security page offers an in-depth look at the comprehensive set of security practices we employ to achieve this aim.

Bliko has implemented an Information Security Management System in line with the ISO/IEC 27001 standard requirements. This system is designed to ensure the continuity of information systems, minimize the risk of damage, and guarantee the achievement of our set objectives, which you can find here:

Security Policy

Data Protection

Bliko takes the protection of its customers' data very seriously and complies with GDPR, UK-GDPR, LGPD, CCPA, and LFPDPPP.

Bliko can act as both a Data Controller and a Data Processor of personal data under the General Data Protection Regulation 2016/679 (hereinafter, "GDPR"). For example, Bliko will be the Data Controller of personal data when a Client enters into a contract directly with us for the processing of the Client's data. However, in most cases, due to the nature of our business, Bliko does not have a direct relationship with the data subjects and solely processes the end-user's personal data on behalf of the clients and according to their instructions. Therefore, if you are an employee using our platform, we act solely as Data Processors of your data. Our Clients decide the purposes for which they use our Platform, as well as the means of data collection to the extent of our platform's functionalities. For users navigating our website, Bliko will be the Data Controller for the data collected here, such as cookies, or any data that is relevant to enjoy our content.

Certifications

To demonstrate our commitment to protecting our customers' personal data, Bliko has invested in obtaining and maintaining certifications in the following standards:

Bliko is certified under ISO/IEC 27001:2013 and renewed its certification in March 2023. Currently, this represents the highest level of the global information security standard available, providing our clients with assurance that we adhere to stringent international standards in security.

Product Security

At Bliko, we ensure that the product meets rigorous information security standards:

All our services run in the cloud. We do not host or run our own routers, load balancers, DNS servers, or physical servers.

All of our customers' data is stored on Amazon Web Services (AWS) servers in Frankfurt, Germany, a suite of cloud services that ensures maximum security. Companies such as Netflix or Airbnb trust AWS to manage the data of millions of users.

The Amazon Web Services data center is protected by three physical layers of security. Additionally, the facilities are protected against impacts and are only accessible via a non-transferable personal card and PIN.

You can read more about their security practices here: AWS Security

Internal Security

At Bliko, we ensure the implementation of internal policies and protocols to comply with internationally recognized security standards.

  • We manage accounts centrally.

  • We rely on a password management system.

  • We use named accounts with 2FA implemented.

  • We rotate passwords every 90 days.

  • We conduct onboarding and offboarding of new employees using a checklist that accounts for the best security practices.

  • We ensure that access privileges adhere to the principle of least privilege.

Service Level Agreement (SLA)

This Service Level Agreement ("SLA") governs the use of Bliko under the provisions of the Terms of Service.

Bliko will make every effort to be available with a monthly uptime percentage of at least 99.50%. Subject to SLA Exclusions, if we fail to meet the Service Commitment, the customer will be eligible to receive a Service Credit. This means we guarantee that the customer will not experience more than 21.56 minutes per month of Downtime.

Terms and Contracts

Here you can find all the terms and agreements that govern your relationship with Bliko:

Here you can find our updated privacy policy.

Confidentiality

Bliko and the client agree to keep confidential the existence and content of all documentation and information provided, transmitted, or disclosed, and not to make it public without the prior written authorization of the other party.

By way of illustration but not limitation, Confidential Information shall be understood as information referring to customer data, its existence, structure, promotion and sales plans, source and object codes of computer programs, systems, techniques, inventions, processes, patents, trademarks, registered designs, copyrights, know-how, trade names, technical and non-technical data, drawings, sketches, financial data, plans for new products, data related to customers or potential customers as well as any other information used in the business scope of Bliko and the Client.