Information Security Policy Statement
Information and information systems are valuable assets to Bee Lite Limited, and their confidentiality, integrity, and availability are critical to our business.
Information and information systems are valuable assets to Bee Lite Limited, hereafter referred to as Bee Lite, and their confidentiality, integrity, and availability are critical to our business. The goal of information security is to protect information and information processing assets from a wide range of threats and effectively lower business risks.
Bee Lite is committed to maintaining the highest standards of information security by implementing and continually improving an ISO/IEC 27001-compliant Information Security Management System, or ISMS. Our approach ensures that:
- Confidentiality: Sensitive business and customer information is accessed only by authorised personnel.
- Integrity: Information remains accurate, complete, and protected from unauthorised modifications.
- Availability: Information and systems are available when required by authorised users.
Scope and purpose
This statement applies to the people, processes, systems, suppliers and information assets used to deliver Bee Lite services. It sets out the principles that guide how we protect information throughout its lifecycle, from collection and creation through to storage, transfer, use, retention and disposal.
The policy supports a consistent approach to information security across day-to-day operations, client delivery, hosting support and internal administration. It also helps ensure that security decisions are proportionate to risk, clearly owned and aligned with business objectives.
Commitment to Information Security
To demonstrate our commitment to information security, Bee Lite:
- Ensures Compliance: We adhere to applicable legal, regulatory, and contractual requirements, including ISO/IEC 27001, data protection laws, and industry regulations.
- Establishes Robust Controls: We implement technical, administrative, and physical security controls to mitigate risks and protect information assets.
- Conducts Continuous Risk Management: We regularly identify, assess, and mitigate risks that could impact the security of our information assets.
- Promotes a Security Culture: We train employees, contractors, and third-party partners to understand and comply with security policies, ensuring security awareness at all levels.
- Implements Incident Management: We have established an Incident Response Plan to quickly detect, respond to, and recover from security incidents.
- Ensures Business Continuity: Our ISMS integrates with business continuity and disaster recovery plans to maintain operations during disruptions.
- Performs Regular Audits & Reviews: We conduct internal and external audits, management reviews, and security assessments to ensure the continuous improvement of our ISMS.
- Enforces Third-Party Security Management: We ensure that suppliers, vendors, and partners comply with our security requirements to safeguard shared information.
This policy is approved by Bee Lite's executive management and is communicated to all employees, contractors, and stakeholders. It will be reviewed annually or whenever significant changes occur to maintain its effectiveness.
Governance and responsibility
Responsibility for information security is shared across the organisation. Management provides direction, resources and oversight, while employees, contractors and relevant third parties are expected to follow approved policies, report security concerns and protect information entrusted to them.
Security requirements are considered when introducing new systems, changing existing services, onboarding suppliers or handling client information. Where risks are identified, appropriate controls and ownership are agreed so that actions can be tracked and reviewed.
Review and continual improvement
Bee Lite reviews the effectiveness of its ISMS through risk assessments, monitoring, audits, incident learnings and management review. Findings are used to improve policies, controls, training and operational procedures.
This continual improvement approach helps ensure that security remains relevant as technology, threats, legal obligations and client expectations change.
Approval
Information Security Manager
Bee Lite Limited
12/02/2025

