Web Security Policy

Vitaleux Website Security Policy

Effective Date: 25 June 2025

At Vitaleux, we are committed to protecting the privacy and security of every customer who interacts with our website. This policy outlines the technical and organisational measures we take to ensure your data is secure and your shopping experience remains safe.


1. Introduction

Vitaleux places a high priority on website security. We actively implement measures to prevent unauthorised access, ensure data integrity, and protect personal information shared with us through our platform.


2. Data Protection

  • Encryption: All data transmitted between your browser and our website is encrypted using SSL/TLS (RSA 2048-bit with SHA256), protecting sensitive data such as personal and payment details.
  • User Data: We collect only the personal data necessary to:
    • Process orders
    • Provide customer support
    • Manage user accounts
    This includes your name, address, email, and payment-related information, all handled in compliance with the UK GDPR and other applicable regulations.
  • Payment Information: We do not store any credit or debit card data on our servers. All transactions are securely processed through PCI-DSS-compliant payment gateways, such as PayPal.

3. Access Control

  • User Accounts: Customers are encouraged to use strong, unique passwords for their accounts.
  • Password Management: We offer secure password reset and recovery options and encourage customers to update their passwords regularly.

4. Security Monitoring & Threat Prevention

  • Firewalls & Intrusion Detection: Our site is protected by advanced firewall systems that monitor and block unauthorised access attempts.
  • Malware Scanning: We perform daily malware scans and vulnerability checks. Any threats identified are immediately investigated and resolved.

5. Incident Response

  • Data Breach Procedure: In the unlikely event of a data breach, Vitaleux will act swiftly to:
    • Contain the breach
    • Notify affected users within 72 hours, where required
    • Implement corrective measures to prevent recurrence
  • Data Backup: All essential data is regularly backed up to ensure business continuity and restore operations quickly in case of any failure or attack.

6. Customer Responsibility

  • Password Security: Customers are responsible for keeping their account credentials secure. We recommend avoiding password reuse across platforms.
  • Reporting Suspicious Activity: If you notice unauthorised access or suspicious behaviour on your account, please notify us immediately.

7. Third-Party Services

We use Veeqo to manage our shipping and inventory operations. All third-party providers used by Vitaleux are required to maintain industry-standard security protocols to protect your data.


8. Compliance

Vitaleux complies with the General Data Protection Regulation (GDPR) and the UK Data Protection Act. We are committed to transparency, lawful processing, and safeguarding of personal data.


9. Continuous Improvement

Security is not a one-time effort—it’s an ongoing process. We regularly:

  • Review our security policies
  • Update our systems to guard against emerging threats
  • Train our team on best practices for data protection

10. Contact Us

If you have any questions about our web security policy, contact us at:

Emailcustomersupport@vitaleux.co.uk
Websitehttps://vitaleux.co.uk