Your Data Is Your Business. Protecting It Is Our Responsibility.
How Y5MEDIA handles the systems, credentials and business information clients entrust to us under our managed IT, security and technology services – and what you can hold us to.
Confidential by default, accessed only as authorized.
At Y5MEDIA, we treat your business data with the utmost confidentiality and care. We do not sell client data, exploit confidential business information for personal benefit, or access client systems beyond the authorized scope of our engagement. Our approach is built around data minimization, restricted access, secure handling, transparency, and accountability.
We aim to prevent unauthorized data access, leakage, misuse, loss, and disclosure through appropriate technical and organizational safeguards. We establish clear responsibilities, document authorized access, and follow agreed procedures for data handling, retention, and deletion.
Your information is entrusted to us for a defined business purpose. We respect that responsibility.
Client information, not website visitors.
This commitment applies to information we access or handle while delivering services to a client: their systems, accounts, credentials, files, mailboxes, backups and the business or personal data inside them.
Information about people who visit this website or contact us is covered by our Privacy Policy. The binding terms for any client are the ones in their signed agreements; this page summarizes the standards those agreements are built on.
The standards we work to.
“Your trust matters. We are committed to protecting your privacy, respecting your confidentiality, and handling your business information responsibly.”
What authorized personnel must never do.
These rules bind every employee, contractor and other person we authorize to work on a client environment. Each signs a confidentiality agreement before access is granted.
- Browse client information without a legitimate work requirement
- Copy, export, download or transfer client data without authorization
- Share client files, credentials or confidential information with unauthorized parties
- Use client information for personal purposes
- Sell or commercially exploit client data
- Use client data to train AI models, unless explicitly authorized through a separate, informed agreement with appropriate safeguards
- Install unapproved software or monitoring tools in client environments
- Create unauthorized accounts, backdoors or hidden access mechanisms
- Retain client credentials after authorization ends, unless retention is specifically required and agreed
- Delete, alter or disclose client information outside the approved scope
If the policy is breached: the person’s access is revoked immediately, the matter is investigated and recorded, the affected client is informed under the agreed incident procedure, contractual remedies are applied, and any report the law requires is made.
Every access has an owner, a reason and a record.
Written authorization first
We confirm who at the client has authority to grant access and record the systems, people and activities that are permitted before work begins.
Named accounts
We ask for individual accounts for our staff instead of shared logins, with roles limited to what the work requires.
Multifactor authentication
Enabled for administrative access wherever the platform supports it.
Careful credential handling
Passwords are not requested unnecessarily. Where one must be shared, it goes through an approved secure method, never plain email, chat or a web form.
Recorded changes
Significant changes and administrative actions are documented, and out-of-scope work needs your approval first.
Review and removal
Access is reviewed periodically and revoked when a person leaves the engagement or the contract ends.
We tell you who else is involved.
Some services depend on third-party providers such as hosting companies, cloud platforms, email providers and monitoring tools. Where a provider will handle your information, it is identified to you and recorded, and we look at its access, hosting location and contractual terms before relying on it.
Confidential client information is not entered into unapproved AI or analytics services. Client data is not used to train AI models unless you have agreed to that separately and in writing.
We keep what the work needs, for as long as it needs.
We collect and hold only the information a service legitimately requires. When an engagement ends, administrative access is revoked or handed over, your information is returned in an agreed format, and our copies are securely deleted.
Two exceptions are recorded and explained to you: records the law requires us to keep, and data sitting in backups until the backup cycle expires. A completion record is provided on request.
Seen something that worries you? Tell us straight away.
If you suspect unauthorized access, a data leak, a compromised account or misuse of information connected with a Y5MEDIA service, contact us using the details below. Clients with a signed SLA should also use the escalation contacts named in their agreement.
- Email: support@y5media.com with the subject line “Security incident”
- Phone / WhatsApp: +91 7902024242
- Please include: what you noticed, when, the system or account involved, and how we can reach you. Do not send passwords or copies of sensitive data.
What happens next: we record the report, assess its severity, contain the issue where we are authorized to, preserve relevant evidence, and inform the designated client contact under the agreed procedure. We then assess legal and contractual notification obligations, cooperate with the client and relevant authorities where required, and document the remediation and lessons learned.
What is a promise, and what is verified per engagement.
We keep the two apart on purpose. A policy tells you how we intend to behave. A control is something that can be checked.
Our standing commitments
Confidentiality, no sale or misuse of client data, access only as authorized, confidentiality agreements for personnel, incident reporting to the client, and return or deletion of data at the end of an engagement. These apply to every client and are written into our agreements.
Controls confirmed for your environment
Named accounts, multifactor authentication, encryption, logging, monitoring, backup testing and access reviews depend on the platforms you use and the plan you choose. During onboarding we agree which apply to you and record the status of each, so nothing is assumed.
We do not claim that any system is completely secure, and we hold no ISO, SOC 2 or similar certification. We commit to specific safeguards, contractual obligations and responsible incident handling.
Put in writing before work starts.
Depending on the service, an engagement is governed by a Master Services Agreement, a Statement of Work, a Service Level Agreement, a mutual Non-Disclosure Agreement and, where we process personal data on your behalf, a Data Processing Agreement.
These are provided to clients and prospective clients as controlled copies and are tailored to each engagement. To request them, ask for a confidential consultation.
A named person to write to.
For questions, requests or complaints about how we handle personal data, contact our Grievance Officer, Raymond Ronald Cardoza, at support@y5media.com (subject “Grievance” or “Personal data request”) or on +91 7902024242, Monday to Saturday, 9:30 AM to 6:30 PM IST.
Full details, including your rights under India’s Digital Personal Data Protection Act, 2023, are in our Privacy Policy. See also our Terms & Conditions.
Changes to this commitment.
- Version 1.0 – 9 October 2026: first published with the launch of Premium Managed IT, Cybersecurity and Data Privacy Services.
We review this page at least once a year and whenever our services or the applicable law change materially. The current version is always the one shown here.
Want to see how this applies to your business?
Ask for a confidential consultation. We will walk you through the agreements, the access model and the controls that would apply to your environment.
