Information Security Policy
Information Security Policy
Effective Date: 01/02/2026
This Information Security Policy applies to Bluestone Design Group Ltd (trading as Bluestone98), its employees, directors, contractors, freelancers, suppliers and third parties who access Bluestone98 systems, data or client information.
Bluestone98 is committed to protecting the confidentiality, integrity and availability of its information, systems, client data, employee data and business operations. This policy outlines the security measures, responsibilities and standards we apply to protect information and support our obligations under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR).
Please read this Information Security Policy carefully and in conjunction with our Privacy Policy and Terms and Conditions.
1. Who We Are
Bluestone Design Group Ltd (trading as Bluestone98) is a company registered in England and Wales under company number 03995844. Our registered office is at 5 Victoria Avenue, Harrogate, North Yorkshire, HG1 1EQ. You can contact us at hello@bluestone98.com.
2. Purpose of This Policy
The purpose of this Information Security Policy is to:
- Protect Bluestone98, client, employee and supplier information from unauthorised access, loss, misuse, alteration or disclosure
- Maintain reliable access to systems and data required to deliver our services
- Support compliance with legal, regulatory and contractual obligations
- Promote a security aware culture across the business
- Ensure security risks are identified, assessed and managed appropriately
- Provide clear expectations for anyone who accesses Bluestone98 information or systems
3. Scope
This policy applies to:
- All Bluestone98 information, whether digital, printed, verbal or stored in cloud systems
- Client data, project files, website data, analytics data, marketing data, employee data and supplier data
- Devices used for Bluestone98 work, including laptops, desktops, mobile phones, tablets and removable media
- Systems used by Bluestone98, including email, cloud storage, design tools, development environments, hosting platforms, CRM systems, analytics platforms, finance systems and communication tools
- All employees, directors, contractors, freelancers, suppliers and third parties who access Bluestone98 information or systems
4. Information Security Objectives
Bluestone98 aims to:
- Protect confidential, personal, client and business information
- Prevent accidental or unauthorised disclosure of information
- Ensure systems remain available for business operations
- Maintain accurate and reliable information
- Respond quickly and appropriately to security incidents
- Keep security controls proportionate to the nature, scale and risk of our work
- Continually improve our information security practices
5. Roles and Responsibilities
Bluestone98 senior management is responsible for approving this policy, providing appropriate resources for information security and ensuring that security risks are considered in business decisions.
Bluestone98 will appoint an appropriate person or role to oversee information security. This person or role is responsible for:
- Maintaining this policy
- Coordinating security reviews
- Overseeing information security risks
- Managing security incidents
- Ensuring appropriate staff guidance and training is in place
- Reviewing supplier and third party security risks where appropriate
Everyone who works with Bluestone98 must:
- Follow this policy
- Protect Bluestone98 and client information
- Use strong authentication
- Report suspected security incidents immediately
- Keep devices secure
- Complete any required security or data protection training
- Only access information needed for their role
6. Information Classification
Bluestone98 information should be handled according to its sensitivity.
Public information includes information intended for public release, such as published website content, marketing materials, public case studies and social media content.
Internal information includes information intended for use within Bluestone98, such as internal processes, templates, planning documents and non sensitive operational information.
Confidential information includes information that could harm Bluestone98, clients, employees or suppliers if disclosed. This may include client project files, commercial proposals, contracts, credentials, unpublished campaign assets, employee data, financial information and supplier records.
Restricted information includes highly sensitive information requiring the strongest protection. This may include passwords, API keys, security configurations, incident records, legal documents, sensitive personal data, payment related data and privileged access details.
7. Access Control
Access to Bluestone98 systems must be granted on a need to know basis.
Bluestone98 will:
- Provide access only where required for a person’s role
- Use unique user accounts wherever possible
- Avoid shared accounts unless there is a documented business need
- Remove or change access promptly when someone leaves or changes role
- Review user access regularly
- Restrict administrator access to authorised personnel only
- Apply stronger controls for privileged accounts
- Use multi factor authentication where available, especially for email, cloud storage, financial systems, hosting, domain management, code repositories and administrator accounts
8. Passwords and Authentication
All users must:
- Use strong, unique passwords
- Never reuse Bluestone98 passwords on personal services
- Store passwords only in an approved password manager
- Never share passwords by email, chat or unsecured documents
- Enable multi factor authentication where available
- Report suspected password compromise immediately
Default passwords must be changed before any system, device, website, plugin, cloud service or hosting account is used.
9. Device Security
Devices used for Bluestone98 work must be protected against unauthorised access, loss and malware.
Users must:
- Keep devices locked when unattended
- Use a password, PIN or biometric lock
- Keep operating systems and applications up to date
- Use approved security software where required
- Avoid storing confidential information locally unless necessary
- Report lost or stolen devices immediately
- Avoid using unsupported or outdated devices for Bluestone98 work
Bluestone98 should use device encryption where available, especially for laptops, mobile devices and removable media containing personal, client or confidential data.
10. Secure Configuration
Bluestone98 systems, devices, websites, plugins and cloud services must be configured securely.
This includes:
- Removing unused accounts
- Disabling unnecessary services
- Changing default passwords
- Applying least privilege access
- Using secure settings for cloud storage and sharing
- Limiting administrator permissions
- Keeping website plugins, themes and dependencies up to date
- Reviewing security settings after major updates or platform changes
11. Malware Protection
Bluestone98 will take reasonable steps to prevent, detect and respond to malware.
This includes:
- Using reputable malware protection where appropriate
- Keeping systems updated
- Blocking or avoiding suspicious downloads
- Treating unexpected attachments and links with caution
- Avoiding unapproved software
- Reporting suspicious activity immediately
12. Security Updates and Patching
Bluestone98 systems must be kept up to date.
Security updates should be applied promptly to:
- Operating systems
- Browsers
- Productivity tools
- Design and development software
- Website platforms
- Plugins, themes and libraries
- Servers and hosting environments
- Cloud services where manual updates are required
Unsupported software, plugins or systems should not be used unless there is a documented exception and appropriate controls are in place.
13. Network and Cloud Security
Bluestone98 will use appropriate controls to protect networks, cloud systems and hosted environments.
This includes:
- Using firewalls and secure network configurations
- Protecting administrator interfaces
- Restricting access to hosting control panels, domain accounts and cloud administration portals
- Using HTTPS for websites and online services where appropriate
- Monitoring suspicious activity where available
- Applying secure backup and recovery controls
- Separating client environments where appropriate
14. Email and Communications Security
Email and messaging systems must be used responsibly.
Users must:
- Check recipients before sending confidential information
- Avoid sending passwords, API keys or credentials by email or chat
- Use secure sharing methods for sensitive files
- Be alert to phishing, spoofing and impersonation attempts
- Report suspicious emails or messages
- Avoid clicking unexpected links or opening suspicious attachments
Where confidential or restricted information must be shared externally, appropriate protection should be used, such as access controlled links, password protected files or encrypted transfer methods.
15. Data Handling and Storage
Bluestone98 will collect, use, store and protect information in line with its Privacy Policy and applicable data protection laws.
Personal data should only be:
- Collected for clear business purposes
- Accessed by authorised people
- Stored in approved systems
- Shared only where necessary
- Retained only for as long as needed
- Deleted securely when no longer required
16. Client Information
Client information must be treated as confidential unless it has been approved for public use.
Staff must:
- Use client information only for authorised work
- Keep client files in approved systems
- Avoid downloading client data unnecessarily
- Avoid discussing client confidential information in public places
- Check permissions before sharing client work externally
- Respect client contracts, NDAs and confidentiality requirements
- Securely delete or archive client information when no longer required
Any public case study, testimonial, campaign result, screenshot or project example must be approved before publication.
17. Supplier and Third Party Security
Bluestone98 uses third party tools and service providers to deliver services, support business operations and manage website performance, analytics, marketing and security.
Before using a supplier that will access Bluestone98, client or personal data, Bluestone98 should consider:
- What information the supplier will access
- Where the information will be stored
- Whether the supplier has appropriate security controls
- Whether a data processing agreement is needed
- Whether access can be limited
- How data can be exported or deleted
- What happens if the supplier has a security incident
18. Backups and Business Continuity
Bluestone98 must maintain appropriate backups for critical business information and systems.
Backups should:
- Cover key business and client information
- Be protected from unauthorised access
- Be tested periodically where practical
- Be available for recovery after accidental deletion, system failure, ransomware or other incidents
- Be retained only for an appropriate period
Critical systems should have documented recovery steps where practical.
19. Remote and Hybrid Working
When working remotely, users must:
- Use secure internet connections
- Avoid public WiFi for confidential work unless using appropriate protection
- Keep screens private when working in shared locations
- Store devices securely
- Avoid leaving printed materials unattended
- Use approved systems for file storage and communication
- Report loss, theft or compromise of devices immediately
20. Removable Media and Printing
Removable media should only be used where necessary.
Users must:
- Avoid storing confidential or restricted information on USB drives or external disks unless approved
- Encrypt removable media where confidential or restricted information is stored
- Keep printed confidential information secure
- Dispose of printed confidential information securely
- Avoid printing client or personal data unless required
21. Software, Tools and Artificial Intelligence
Users must only use software, online tools and AI services that are appropriate for Bluestone98 work.
Before uploading client, personal, confidential or restricted information to any external tool, users must consider:
- Whether the tool has been approved
- Whether client permission is required
- Whether the information includes personal data
- Whether the supplier may use the data for training or other purposes
- Whether a safer alternative is available
- Whether the output needs human review
Confidential client information, credentials, source code, private strategy documents and sensitive personal data must not be entered into unapproved AI tools.
22. Development and Website Security
Where Bluestone98 designs, develops, hosts or maintains websites or digital services, appropriate security controls must be applied.
This includes:
- Secure coding practices
- Keeping platforms, plugins, themes and dependencies updated
- Protecting admin accounts with strong authentication
- Using HTTPS where appropriate
- Restricting administrator access
- Reviewing form security, spam protection and bot protection
- Avoiding hard coded credentials
- Protecting API keys and environment variables
- Testing changes before deployment where practical
- Maintaining backups before significant website changes
- Removing unused plugins, themes, accounts and test files
23. Incident Reporting and Response
A security incident is any actual or suspected event that could affect the confidentiality, integrity or availability of Bluestone98 information or systems.
Examples include:
- Lost or stolen devices
- Phishing or suspicious emails
- Malware or ransomware
- Unauthorised account access
- Accidental data disclosure
- Emails containing confidential information sent to the wrong recipient
- Website compromise
- Leaked credentials
- Supplier security incidents
- Unexplained system behaviour
All users must report suspected incidents immediately to Bluestone98 senior management or the person responsible for information security.
Bluestone98 will:
- Assess the incident
- Contain the issue where possible
- Preserve relevant evidence
- Notify affected clients, suppliers or individuals where required
- Consider whether the incident is a personal data breach
- Meet any legal or contractual reporting obligations
- Review lessons learned after the incident
If a personal data breach occurs, Bluestone98 will assess whether notification to the Information Commissioner’s Office or affected individuals is required under UK GDPR.
24. Training and Awareness
Bluestone98 will provide appropriate information security and data protection guidance to staff, contractors and freelancers.
Training should cover:
- Passwords and multi factor authentication
- Phishing and social engineering
- Client confidentiality
- Data protection basics
- Secure file sharing
- Remote working
- Incident reporting
- Use of AI and online tools
- Handling personal data
25. Monitoring and Audit
Bluestone98 may monitor its systems, accounts, websites, devices and networks to protect security, investigate incidents, maintain service reliability and meet legal or contractual obligations.
Monitoring must be proportionate, lawful and respectful of privacy.
Security controls should be reviewed periodically, including:
- User access
- Administrator permissions
- Supplier access
- Backup arrangements
- Security update status
- Website and hosting security
- Incident records
- Policy compliance
26. Exceptions
Any exception to this policy must be approved by Bluestone98 senior management or the person responsible for information security.
Exceptions should be:
- Documented
- Risk assessed
- Time limited where possible
- Reviewed regularly
- Supported by appropriate controls where needed
27. Breach of Policy
Failure to follow this policy may result in removal of system access, disciplinary action, termination of contract or legal action, depending on the seriousness of the breach.
28. Policy Review
This policy will be reviewed at least annually or sooner if:
- Bluestone98 introduces significant new systems or services
- There is a significant security incident
- There is a major legal or regulatory change
- Client requirements change
- A risk assessment identifies the need for changes
29. Contact Us
If you have any questions or concerns about this Information Security Policy, contact us at: hello@bluestone98.com
We’d love to hear from you
If you’d like to talk about your next dream project, please email us at hello@bluestone98.com or speak to us on 0330 633 1998