Security & Data Protection Statement
C2A · 1BY0 SOLUTIONS · Last updated: September 2026
High-level statement of controls. Not a certification. Lawyer and security review recommended for enterprise contracts.
1. Purpose
This statement summarises how 1BY0 SOLUTIONS protects personal and customer data in C2A (Connect to Action).
2. Tenant isolation
C2A is multi-tenant. Lead and integration data are scoped to the owning customer account so one organisation cannot access another’s workspace under normal application controls.
3. Access control
- Authenticated access for web and mobile clients
- Role-based access (e.g. App Admin vs staff/executive) within a workspace
- Integration tokens stored with encryption at rest where implemented
4. Transport & storage
- HTTPS/TLS for public endpoints (c2a.app / API)
- Production data hosted on secured servers/cloud infrastructure
- Application and access logs for security and troubleshooting
5. Application security practices
- Least-privilege design for APIs and webhooks
- Webhook endpoints limited to intended providers
- Dependency and server patching as part of operations
6. Personnel
Access to production systems is limited to authorised personnel with a need to know.
7. Incident response
Suspected security incidents should be reported to support@c2a.app (subject: “Security incident — C2A”). We will investigate and notify affected customers as required by applicable law and contracts.
8. Customer responsibilities
- Protect account credentials and staff access
- Configure Meta/WhatsApp/RCS connections lawfully
- Use strong passwords and revoke access for departed staff
9. Related documents
© 2026 1BY0 SOLUTIONS