Skip to main content
Back to Policies & Statements

ParagonQMS Policy Statement

Information Security Policy Statement

Aligned to ISO/IEC 27001:2022 and UK GDPR / Data Protection Act 2018Issue 1.0 — Draft for approval, June 2026Owner: Managing Director, ParagonQMS
ParagonQMS consultant managing secure client information at a workstation

Scope

All information assets owned, processed or held by ParagonQMS, including client documentation, audit evidence, personal data, internal records, the ParagonQMS client portal and the supporting systems, devices, cloud services and people used to deliver our services.

Our commitment

ParagonQMS is committed to protecting the confidentiality, integrity and availability of the information entrusted to us by clients, employees, associates and other interested parties. We operate an information security approach aligned to ISO/IEC 27001:2022, and we comply with the UK GDPR, the Data Protection Act 2018 and other applicable legal, regulatory and contractual requirements.

What we commit to

  • Treating client information as confidential and using it only for the purpose for which it was provided.
  • Applying access controls so that information is only available to those who need it to do their job.
  • Using reputable, suitably configured cloud services, devices and tools for storage, collaboration and communication.
  • Encrypting data in transit and at rest where supported by the platforms we use.
  • Maintaining backup, recovery and business continuity arrangements proportionate to the risk.
  • Reporting, investigating and learning from information security incidents and personal data breaches, and notifying affected parties and regulators where required.

Client information and the ParagonQMS portal

  • Client accounts on the ParagonQMS portal are protected by individual credentials and role-based access.
  • Documents uploaded to the portal remain the property of the client and are not shared with third parties without authorisation, except where required by law.
  • We retain client information only for as long as needed to deliver our services and meet legal, regulatory or certification-evidence requirements, after which it is securely deleted or returned.

People and suppliers

  • All ParagonQMS personnel and associates are subject to confidentiality obligations and receive information security and data protection awareness as part of their induction and ongoing development.
  • Suppliers and subprocessors that handle client information are reviewed for their security posture and are bound by appropriate contractual safeguards.

Responsibilities

The Managing Director is accountable for information security at ParagonQMS. All personnel, associates and subcontractors are responsible for following this policy, using ParagonQMS systems appropriately, and reporting suspected security events or data protection concerns promptly to portal@paragonqms.com so they can be assessed and acted on.

Review and authority

This policy statement is reviewed at least annually, and whenever significant changes occur to the business, its services, applicable legislation, or interested-party requirements. It is communicated to all ParagonQMS personnel and made available to clients, prospective clients and other interested parties.

Signed on behalf of ParagonQMS by the Managing Director. The controlled, signed version is held by ParagonQMS and available on request.

Questions about this policy? Contact admin@paragonqms.com (general enquiries) or portal@paragonqms.com (portal support).