Security Policy

Last Updated: 8 February 2025

Pekulav is committed to protecting the security of our platform, systems, and the data entrusted to us by our users. This Security Policy describes the technical and organisational measures we employ to safeguard information and maintain the integrity, availability, and confidentiality of our services available at mekarou.com.

By using our platform, you acknowledge that you have read and understood this policy. We encourage you to review it periodically, as we update it to reflect improvements to our security practices.


1. Scope

This policy applies to all systems, infrastructure, applications, and data managed by Pekulav in connection with the delivery of our online masterclass platform. It covers:


2. Information We Protect

Our security controls are designed to protect the following categories of information:


3. Security Measures

3.1 Data Encryption

All data transmitted between your browser and our servers is encrypted using Transport Layer Security (TLS). We enforce HTTPS across all pages and services. Sensitive data stored within our systems is encrypted at rest using industry-standard encryption algorithms. Passwords are never stored in plain text and are processed using strong one-way hashing functions.

3.2 Access Controls

Access to production systems and user data is restricted to authorised personnel only. We apply the principle of least privilege, ensuring that each team member has access only to the resources necessary for their specific role. Administrative access requires multi-factor authentication and is subject to regular review.

3.3 Network Security

Our infrastructure is protected by firewalls, intrusion detection systems, and network segmentation. We monitor network traffic for anomalous activity and apply rate limiting and filtering to mitigate abuse and denial-of-service attempts.

3.4 Application Security

We follow secure software development practices throughout our development lifecycle, including:

3.5 Authentication and Session Management

User accounts are protected through secure authentication mechanisms. Sessions are managed using time-limited tokens that are invalidated upon logout. We support and encourage the use of strong, unique passwords and may offer multi-factor authentication options to further protect user accounts.

3.6 Infrastructure and Hosting

Our platform is hosted on reputable cloud infrastructure providers that maintain their own comprehensive security certifications and compliance programmes. Physical access to data centres is controlled and monitored by our hosting providers. We configure our cloud environments in accordance with security best practices, including isolated environments, automated backups, and access logging.

3.7 Data Backups

We perform regular automated backups of critical data. Backups are stored securely and tested periodically to ensure they can be restored reliably. Retention periods for backups are defined in accordance with our operational and data management requirements.


4. Third-Party Service Providers

We work with carefully selected third-party vendors to deliver certain aspects of our service, including payment processing, email delivery, and analytics. We evaluate the security posture of these providers before engagement and require that they maintain appropriate security standards. Data shared with third parties is limited to what is strictly necessary for the purpose of the service they provide.

We do not sell user data to third parties and do not permit third-party providers to use your data for purposes beyond those we have authorised.


5. Security Monitoring and Incident Response

5.1 Monitoring

We maintain continuous monitoring of our systems and infrastructure. Logs are collected, stored securely, and reviewed to detect unauthorised access, unusual behaviour, or potential security events. Automated alerts are configured to notify our team of conditions that may indicate a security incident.

5.2 Incident Response

We maintain an incident response process to handle security events in a timely and structured manner. In the event of a confirmed security incident that affects user data, we will:

Notifications will be sent to the email address associated with your account. We encourage users to keep their contact information up to date.


6. User Responsibilities

Security is a shared responsibility. We ask that all users of our platform take reasonable steps to protect their own accounts and data:


7. Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities. If you believe you have discovered a security issue affecting our platform, we ask that you contact us directly before making any information public. Please provide sufficient detail to allow us to reproduce and investigate the issue.

To report a vulnerability, please contact us at:

Email: support@mekarou.com
Phone: +353 1 810 3439

We commit to acknowledging your report promptly, investigating it in good faith, and keeping you informed of our progress. We ask that you do not access, modify, or delete any data beyond what is necessary to demonstrate the vulnerability, and that you refrain from disrupting our services during your research.


8. Organisational Security Practices

Internally, Pekulav maintains security through the following organisational measures:


9. Retention and Deletion

We retain data only for as long as necessary to fulfil the purposes for which it was collected, to comply with applicable obligations, or to resolve disputes. When data is no longer required, it is securely deleted or anonymised. Users may request the deletion of their account and associated personal data by contacting our support team.


10. Updates to This Policy

We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this page and, where appropriate, notify users through the platform or by email.

Continued use of the platform following the publication of an updated policy constitutes your acceptance of the revised terms. If you do not agree with any changes, you should discontinue use of the platform and contact us to request deletion of your account.


11. Contact Us

If you have any questions, concerns, or requests relating to this Security Policy or our security practices, please contact us using the details below:

Pekulav
Tievebane, Co. Donegal, F93 TW54, Ireland
Email: support@mekarou.com
Phone: +353 1 810 3439
Website: mekarou.com