Confidentiality & Data Protection Policy

Policy statement

CVA and Allied Assist Co commit to protecting client data, maintaining privacy, and acting with integrity. All confidential information must be handled responsibly, securely, and in compliance with legal and ethical standards.

Scope

Applies to all contractors, virtual assistants, staff, and administrators who handle or have access to confidential data for CVA or Allied Assist Co. Covers all information types (digital, paper, communication threads) and platforms such as Worklenz/Hubtasks, Slack, email, Hubstaff, OneDrive, JotForm, and similar approved tools. (ClickUp may appear in older source text; Worklenz is the live CVA task system.)

Compliance

Comply with relevant data privacy laws (GDPR, HIPAA, FERPA, local jurisdiction requirements) as applicable. All personnel must sign a confidentiality agreement during onboarding for both CVA and Allied Assist Co.Personally identifiable information (PII): Data that identifies an individual (name, address, phone, email, SSN, etc.).

Data protection: Processes, tools, and responsibilities to ensure information is stored, accessed, shared, and disposed of securely.

Confidentiality obligations

Treat sensitive client or business data as confidential.

Use data only for authorized and necessary business functions.

Do not share confidential information with outside parties without written consent.

Authorized platforms and secure tools

Use only approved tools and platforms for client-related work (e.g. Slack, Worklenz/Hubtasks, secure OneDrive storage, encrypted file sharing; handbook-listed resources may include Hubstaff, Canva, LastPass, and client systems such as Brightwheel, ProCare, Playground).

Do not store passwords or sensitive documents in unprotected personal notes, unencrypted email, or public/shared drives.Access controls and data handling

Access is least privilege — only those who need it get it.

Store documents in designated folders with correct permission levels.

Transfer or copy confidential data only under controlled conditions through secure channels.

Communication and information sharing

Use official communication channels for discussions involving sensitive information.

Do not use unapproved tools or personal messaging apps for client or PII-related info.

Any sharing of confidential info with clients must clearly outline what is shared and how it is protected.

Data breach and incident handling

Disciplinary measures

Non-compliance may lead to written warnings; suspension of access to client data or systems; and termination of contract or employment in severe or repeated cases. The handbook ties breaches to a Zero Tolerance Policy that can lead to instant termination.

Cultural tone

As a VA, maintaining ethical standards is paramount.

Document control

Review frequency: Annually

Approved by: Angie Bozsoki, Director of Operations

Effective date: [Insert Date] (source placeholder — do not invent a date)

Source: SweetProcess DOCX export (Drive pack). Migrated to Eniston category Allied. Do not treat as dual source of truth with SweetProcess.

Report any suspected breach, unauthorized access, or loss of confidential information immediately to Management.

Allied Assist Co & CVA will investigate, contain damage, notify affected parties as required, and implement corrective measures.

Remote-work devices must have up-to-date security patches, antivirus, and strong access controls.

Do not store company-related files on personal devices.

Definitions

Confidential information: Any non-public data belonging to clients or internal business matters, including childcare enrollment forms, billing, CACFP documentation, HR records, client communications.


Was this article helpful?