Purpose
The purpose of this policy is to ensure that Rosco’s Security protects all customer data, contact information, system access credentials, video footage, and personally identifiable information (PII) with the highest level of confidentiality, integrity, and security.
This policy supports legal compliance and professional standards within the physical security and IT systems industry.
Scope
This policy applies to:
- All Rosco’s Security employees and subcontractors
- All customer-owned security systems under our service or installation
- Data collected, transmitted, stored, or accessed by Rosco’s Security for:
- Surveillance systems
- Access control systems
- Network security appliances
- Remote support tools and portals
- SMS and Email Communication
Information We Collect
We may collect information including:
- Contact Name
- Company name
- Email address
- Telephone number
- Service address
- Billing information
- Project information
- Communications with our company
Data Handling Principles
Rosco’s Security adheres to the following principles:
Protection Objective | Actions |
Confidentiality | Only authorized personnel may access system data. |
Integrity | Data must remain accurate and protected against unauthorized changes. |
Availability | Access must be preserved for properly authorized clients. |
Customer data must never be shared with third parties without written authorization.
Access Credentials & Authorization Control
- Administrative credentials must be secured and never emailed in plain text
- Password changes performed by Rosco’s Security will be documented and delivered securely
- Credentials will only be shared with client-designated authorized contacts
- Any credential resets or privilege changes require:
- Written request and
- Identity verification of an authorized client representative
- Written request and
SMS & Email Communication
We use the customer information to:
- Respond to inquiries
- Schedule appointments
- Deliver estimates and proposals
- Perform contracted services
- Send invoices and service documentation
- Provide customer support
- Send service-related SMS notifications (when consent has been provided)
- Improve our services
If you opt in to receive SMS messages from Rosco's Security, you may receive messages regarding:
-
- Appointment confirmations
- Technician arrival notifications
- Work order updates
- Project status
- Preventive maintenance reminders
- Customer support
- Managed service notifications
- Account-related communications
Message frequency varies depending on the services provided.
Message and data rates may apply. You may opt out at any time by replying STOP.
For assistance, reply HELP or contact us at:
Sharing of Information
Rosco's Security does not sell, rent, or share your personal information or mobile phone number with third parties for marketing purposes.
We may share information only with trusted service providers when necessary to operate our business or as required by law.
Remote Access Security
- When remote access is enabled:
- VPN, encrypted cloud access, or secure remote tools must be used
- Direct exposure of devices to public internet must be avoided or minimized
- Multi-factor authentication (MFA) will be used whenever supported
- VPN, encrypted cloud access, or secure remote tools must be used
- Remote access may be disabled if security vulnerabilities are identified.
Video Data Sensitivity
- Video surveillance data may contain sensitive operational information, or proprietary activities
- Video exports are restricted to authorized client contacts
- Chain-of-custody procedures apply when footage is provided for legal or investigative purposes
- Video surveillance data may contain sensitive operational information, or proprietary activities
- Retention limits are defined during installation and must be acknowledged by the client
Device & Network Security
- All devices delivered or configured must operate with latest stable firmware
- Default passwords must be replaced with secure passphrases
- Systems must be designed to prevent unauthorized network access (VLANs, firewalls, etc.)
- System logs may be reviewed for diagnostics and cyber security responses
Incident Response
- Security incidents affecting customer data are escalated immediately to Operations Management and documented.
- Clients will be notified promptly if:
- Data breach is suspected or confirmed
- Unauthorized access attempts are detected
- A vulnerability is found that requires urgent mitigation
- Data breach is suspected or confirmed
Client Ownership of Data
- Clients retain full ownership of:
- Recorded video
- Access logs
- Credential databases
- System configurations
- Recorded video
- Rosco’s Security accesses this information only as required for service or support.
Policy Violations
- Any employee or subcontractor who violates this policy may face disciplinary action and removal from projects.
- If client data exposure results from negligence or unauthorized disclosure, additional legal measures may be pursued.
