Security Statement

Last updated: May 18, 2026

This Security Statement describes administrative, technical, and organizational safeguards used by MyChairHQ to protect the Platform and user data.

1. Security Program

MyChairHQ maintains a security program designed to protect the confidentiality, integrity, and availability of the Platform and personal information. Security measures are risk-based and may evolve as the Platform, providers, and threat environment change.

2. Technical Safeguards

MyChairHQ uses safeguards that may include:

  1. HTTPS/TLS encryption for data in transit;
  2. secure authentication and session controls;
  3. role-based, least-privilege, or need-to-know access where supported;
  4. logging and monitoring for security events, errors, performance, and abuse;
  5. rate limiting, caching controls, and abuse-prevention mechanisms;
  6. secure hosting and managed infrastructure providers;
  7. vulnerability remediation and software updates;
  8. secure configuration practices for production systems;
  9. backup and recovery practices appropriate to Platform operations; and
  10. incident response procedures.

3. Administrative Safeguards

MyChairHQ may use administrative controls such as confidentiality obligations, limited personnel access, provider review, support-access procedures, policy enforcement, security reviews, and operational monitoring.

4. Provider Security

MyChairHQ relies on third-party providers for hosting, payments, SMS, email, AI, media, calendar, caching, error monitoring, and job processing. MyChairHQ selects providers based on business and security needs and requires provider commitments appropriate to their role.

5. Professional Responsibilities

Professional is responsible for:

  1. using strong, unique passwords;
  2. maintaining secure devices and networks;
  3. limiting admin access;
  4. removing former staff promptly;
  5. protecting exported data;
  6. verifying payment, calendar, and messaging settings;
  7. avoiding Sensitive Data unless permitted;
  8. reporting suspected unauthorized access promptly; and
  9. training staff on privacy, security, and customer-data handling.

6. Security Incidents

If MyChairHQ confirms a security incident affecting personal information, MyChairHQ will notify affected parties as required by applicable law, the Privacy Policy, and the Data Processing Addendum. Notifications may include available facts, affected data categories, mitigation steps, and recommended actions. A notification is not an admission of fault or liability.

7. Vulnerability Reporting

Security concerns may be reported to security@mychairhq.com. Reports should include a description of the issue, affected URL or feature, steps to reproduce, potential impact, and contact information. Do not access, copy, alter, destroy, exfiltrate, or disclose data that does not belong to you. Do not perform denial-of-service testing or social engineering.

8. No Absolute Security

No system is completely secure. MyChairHQ cannot guarantee that unauthorized access, data loss, outages, or security incidents will never occur.