Information Privacy & Protection Standards

Policy Statement

BroadPoint Group is the company operating name and the entity is Redcley LLC. Throughout this document, references to "BroadPoint Group," "BroadPoint," "we," or "our" refer to Redcley LLC and its employees, contractors, consultants, and authorized representatives. BroadPoint Group is committed to protecting the confidentiality, integrity, and availability of information entrusted to us by our clients, partners, employees, candidates, and business stakeholders. These Information Privacy and Protection Standards establish the requirements for the collection, access, use, storage, transmission, retention, and disposal of sensitive information. The purpose of this policy is to safeguard information assets, reduce risk, comply with contractual and legal obligations, and maintain the trust our clients and partners place in BroadPoint Group. These standards apply to all employees, contractors, consultants, and third parties acting on behalf of BroadPoint Group.

Why Information Protection Matters

In the normal course of business, BroadPoint Group receives, creates, accesses, and manages confidential information belonging to clients, partners, candidates, and employees. This information may include business strategies, financial data, technical documentation, source code, product plans, personal information, recruiting data, and other sensitive materials. Such information may be transmitted or stored electronically, physically, or verbally. Protecting this information is a fundamental business responsibility and a requirement of our professional services practice. BroadPoint Group personnel are expected to adhere to these standards and any additional client-specific security, privacy, confidentiality, or compliance requirements communicated during an engagement.

Core Information Protection Principles

BroadPoint Group follows these principles when handling information:

  1. Access information only when required to perform authorized business activities.

  2. Collect only information necessary to perform contracted services.

  3. Maintain information in a secure manner appropriate to its sensitivity.

  4. Protect information from unauthorized access, disclosure, modification, or destruction.

  5. Share information only with authorized individuals who have a legitimate business need.

  6. Return, remove, or securely dispose of information when no longer required.

  7. Immediately report suspected security or privacy incidents.

Information Classification

  • Public

    Information approved for public release.

  • Internal Use Only

    Business information intended solely for BroadPoint Group personnel.

  • Confidential

    Client, partner, employee, financial, recruiting, operational, and proprietary business information.

  • Restricted

    Highly sensitive information requiring enhanced protections, including regulated data, source code, credentials, security information, and confidential client materials.

Project Lifecycle Controls

1. Assemble

  • Collect only information reasonably necessary to fulfill business requirements.

  • Obtain information through approved communication channels.

  • Store information only on approved systems and devices.

  • Avoid collecting or retaining unnecessary information.

  • Maintain physical and electronic safeguards during data collection and transfer.

2. Utilize

  • Use information solely for authorized business purposes.

  • Limit access to personnel with a legitimate business need.

  • Access confidential information only in approved work environments.

  • Follow all client-specific confidentiality, security, and privacy requirements.

  • Do not disclose confidential information to unauthorized individuals.

3. Store & Protect

  • Maintain appropriate administrative, technical, and physical safeguards.

  • Utilize encrypted devices and approved cloud storage platforms.

  • Protect systems through strong authentication practices and multi-factor authentication where available.

  • Secure laptops, mobile devices, removable media, and paper records.

  • Lock screens when unattended and prevent unauthorized viewing of confidential information.

  • Do not share passwords, credentials, or system access.

4. Return, Retain & Dispose

  • Return client information when contractually required or upon request.

  • Retain information only for legitimate business, legal, or contractual purposes.

  • Securely delete electronic information when no longer required.

  • Shred or securely destroy physical records containing confidential information.

  • Remove access to information upon completion of an engagement or termination of a business need.

Remote Work Requirements

Personnel working remotely must:

  • Use company-approved or authorized devices whenever practical.

  • Connect through secure networks and communication methods.

  • Avoid storing confidential information on public or shared devices.

  • Protect confidential information from unauthorized viewing or access in public locations.

  • Secure devices when unattended.

Artificial Intelligence & External Systems

Client, partner, candidate, employee, or other confidential information may not be entered into publicly available AI tools, consumer AI platforms, or external systems unless expressly authorized by BroadPoint Group management and permitted by applicable client requirements.

Third-Party Providers

BroadPoint Group may utilize third-party technology and service providers to support business operations. Such providers should maintain appropriate confidentiality, privacy, and security safeguards consistent with the nature of the information being processed.

Incident Reporting

Any suspected or actual loss, theft, unauthorized disclosure, cybersecurity event, phishing incident, malware infection, or compromise involving company, client, partner, candidate, or employee information must be reported immediately to BroadPoint Group management.

Compliance

Failure to comply with these standards may result in disciplinary action, termination of access privileges, termination of contract or employment, and other measures deemed appropriate by BroadPoint Group.

Appendix A: Minimum Security Controls

BroadPoint Group personnel are expected to adhere to the following minimum security controls:

  • Multi-factor authentication enabled where available.

  • Use of encrypted computers and mobile devices for company business.

  • Storage of company and client information only in approved systems.

  • No unauthorized sharing of credentials or accounts.

  • No use of unapproved AI platforms for confidential information.

  • Prompt application of security updates and patches where applicable.

  • Immediate reporting of suspected security or privacy incidents.

  • Secure disposal of confidential information when no longer required.