DoGood

Policy

Information Security Policy

Version 1.0Effective 2024-10-05

In our net-zero research, consulting and environmental programs, clients and partners trust us with sensitive data. This policy explains how we handle and protect it.

Beware of impersonation emails.

DoGood Company never asks for passwords, verification codes or payment details by email. If you receive a suspicious message, don’t reply or open attachments — let us know at contactus@dogood.eco.

01Purpose

This policy sets out the basic principles by which DoGood Company Inc. (“the Company”) protects information about clients, partners and program participants that it handles while delivering net-zero research and consulting and planning and running environmental activities.

02Scope

This policy applies to all Company staff, to external people working on our projects (such as subcontractors and freelancers), and to every information system, cloud service and document the Company uses for its work.

03Information classification

We classify information into three levels and manage each accordingly.

  • Public — information intended for publication, such as this website and published reports
  • Internal — material used to run the Company and its projects
  • Confidential — energy use, emissions and financial data provided by clients, contract information, and personal data

04Handling client data

  • Client data is used only for the purposes set out in the contract, and is never used for other purposes or shared with third parties.
  • We request only the minimum information a project needs.
  • Where needed, we sign a non-disclosure agreement (NDA) before a project starts.
  • Confidential information is stored only in Company-approved storage, and shared externally only through access-restricted links or encrypted files.

05Access control

  • Access to confidential information is granted only to people working on the relevant project.
  • Two-factor authentication is required on work accounts.
  • Access is revoked without delay when a project ends or its team changes.

06Email communication

  • The Company’s official contact address is contactus@dogood.eco.
  • We never ask for passwords, verification codes or payment details by email.
  • If you receive an email you suspect is impersonating the Company, please don’t reply or open attachments, and let us know at our official address.

07This website and inquiry emails

  • This website runs without sign-ups, input forms, tracking cookies or analytics tools.
  • Names, affiliations and contact details in inquiry emails are used only to reply and to discuss your request.
  • They are deleted without delay once the conversation ends, unless the law requires us to keep them (for example, for a contract), in which case they are kept only for that period.

08Retention and disposal

When a project ends, client data is returned or irreversibly deleted as the contract specifies. On request, we confirm that deletion has taken place.

09Incident response

When we become aware of a security incident such as a data leak, we report it internally at once and assess its impact. We notify affected clients and stakeholders without delay, make any reports required by law, and take steps to prevent it from happening again.

10Training and review

The Company briefs its staff and project contributors on this policy and regularly reviews compliance with it.

11Responsible person and contact

Information security officer
Hidae Kim / CEO

12Amendments

This policy may be amended as laws or the Company’s work change. Any amendment is posted on this page with its effective date.

Revision history
VersionEffectiveChange
1.02024-10-05First issued