SeyleaseCRM-AUA-v1.0

Security & control baseline

CRM Security, Access & Responsible Use

This page summarises the operational controls expected around the Seylease Sales CRM. It is written for authorised users and administrators and should be read together with Seylease's approved information-security, records and compliance policies.

1. Access control

  • CRM access uses individual authenticated accounts; public self-registration is not enabled.
  • Permissions are role-based for CEO, Sales Representative and Finance Viewer responsibilities.
  • Database row-level security and application guards are used to reinforce role restrictions.
  • Inactive accounts are prevented from using the CRM and access should be reviewed when responsibilities change.

2. Confidential files and links

Sales Reference attachments are stored privately and are opened through temporary authorised links. A temporary link or downloaded copy must still be treated as confidential and must not be shared outside its authorised purpose.

3. Data classification boundary

This CRM is intended for sales outreach, follow-up and opportunity information. It is not the approved system of record for full KYC/AML files, identification documents, bank statements, salary records, detailed credit assessment files or other highly sensitive financial documentation unless Seylease formally expands the system's purpose and controls.

4. Secure use by staff

  • Do not share passwords or leave an authenticated session available to an unauthorised person.
  • Use only devices and networks that meet Seylease's approved working practices.
  • Do not copy CRM data into personal email, personal cloud storage or unapproved applications.
  • Keep free-text notes relevant, factual and appropriate for an auditable business record.

5. Auditability and changes

Significant CRM actions and governance events may be retained in audit records. Operational records should normally be corrected, progressed, archived or closed through the available workflow rather than altered in a way that obscures legitimate history.

6. Retention and disposal

Retention must follow Seylease's approved records-retention schedule and applicable legal/regulatory requirements. Where a record is no longer required, disposal should follow an approved process rather than ad hoc deletion by an end user.

7. Incident response

Suspected account compromise, unauthorised disclosure, lost exported information, inappropriate access or other material security/privacy incidents must be escalated promptly through Seylease's designated internal process so that containment, assessment and any required notifications can be handled appropriately.

8. Regulated financial-institution context

Seylease operates within the Seychelles financial regulatory environment. CRM access, data handling and internal controls must therefore support prudent governance, confidentiality, consumer-data protection and management oversight appropriate to a regulated financial institution.

Administrator note

Technical controls do not replace staff responsibility. Access rights, account status, approved hosting configuration and security settings should be reviewed as part of the production and ongoing governance process.