Certification
Information Security & Privacy (GDPR / NIS2)
As an IT wholesaler, we attach great importance to protecting customer data, ensuring the continuity of our services, and complying with privacy legislation (GDPR). Within our B2B customers' supply chain, we take our role in information security extremely seriously.
- Cybersecurity & Information Security Statement For our B2B customers and business partners, we have clearly outlined the key aspects of our technical and organizational security measures, continuity assurance, and risk policy. (Available upon request for business relations; please contact your account manager)
Our Approach to Data and Security Management
We apply a risk-driven security strategy to protect company and customer data. To keep our internal expertise at the highest level, our specialists hold various recognized industry certifications (including CompTIA A+, Network+, Security+, Pentest+, and CySA+).
- Data Protection Policy & Transparency: We process and store personal data exclusively in accordance with the requirements of the GDPR and our privacy statement. Customers retain their statutory rights at all times.
- Access Management & Identity Control: Our IT environment is secured according to the principle of least privilege, controlled access rights, and strict user authentication.
- Continuity & Data Recovery: We guarantee the continuity of our services with a structured backup strategy, periodic recovery testing, and measures to prevent data loss.
- Secure Ordering Portal: Transactions and the processing of payment and order data on our ordering portal take place via a certified PCI DSS Level 1 infrastructure.
- Supply Chain Security & NIS2: Although, as a small-scale enterprise, we are not directly subject to supervision under the Cybersecurity Act (NIS2), we use the principles of NIS2 and general cybersecurity standards as a reference framework for our supply chain responsibility.
Policy Statement Regarding Ransomware & Ransoms
At Service Parts International B.V., we adhere to a firm principle regarding cyber incidents: we do not pay ransoms.
Paying a ransom provides no guarantee of data recovery and supports illegal activities. Instead, we continuously invest in preventive, detective, and corrective security measures — including robust backup and recovery procedures. Should an incident occur, we prioritize transparency, ethical data recovery, and close cooperation with law enforcement and security experts.