Template notice: This document is a working draft. Review with qualified legal counsel and a security professional before going live.
Our commitment
Seasonable handles sensitive operational data for campsites and their staff: availability, housing assignments, and pay records. We take that responsibility seriously. This page describes the technical and organisational measures we apply to protect your data. We review and update these measures as the platform grows.
Infrastructure and hosting
The Seasonable platform is hosted on cloud infrastructure within the European Economic Area (EEA). We use reputable, professionally managed hosting providers that maintain their own security certifications (including ISO 27001 or equivalent). Physical access to the underlying data centres is controlled by our hosting providers under industry-standard security policies.
Production environments are logically separated from development and staging environments. No real customer data is used in non-production systems.
Encryption in transit
All data transmitted between your browser and the Seasonable platform is encrypted using TLS 1.2 or higher. We enforce HTTPS on all endpoints. HTTP connections are automatically redirected to HTTPS. We aim for an A rating on standard TLS evaluation tools and periodically review our cipher suite configuration.
HTTP Strict Transport Security (HSTS) is enabled to prevent downgrade attacks.
Encryption at rest
Databases and file storage containing customer data are encrypted at rest using AES-256 or equivalent. Encryption keys are managed separately from the encrypted data. Backups are also encrypted before storage.
Authentication and access control
Access to the Seasonable application is protected by authenticated sessions. Passwords are never stored in plain text: they are hashed using a modern, salted algorithm (bcrypt or equivalent). We strongly recommend that Operators enable two-factor authentication (2FA) when it becomes available.
Internal access to production systems follows the principle of least privilege: team members access only the data and systems necessary for their role. Access rights are reviewed regularly and revoked promptly when no longer needed.
Administrative access to infrastructure is protected by SSH key authentication. Password-based SSH login is disabled.
Data backups
Automated backups of the production database are taken daily. Backups are retained for a minimum of 14 days and are stored encrypted in a geographically separate location. Restoration procedures are tested periodically to verify backup integrity.
Vulnerability management
We monitor our software dependencies for known vulnerabilities and apply security patches on a regular cadence. Critical patches are applied as soon as possible after release. Our codebase undergoes code review before deployment. We aim to conduct a security review prior to any major release.
Incident response
In the event of a security incident affecting personal data, we follow an incident-response procedure that includes:
- Detection and containment: Identify the scope and isolate affected systems.
- Assessment: Determine which data was affected and the likely impact.
- Notification: Where required by GDPR, notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours, and notify affected individuals without undue delay.
- Remediation: Fix the root cause and deploy preventive measures.
- Post-incident review: Document learnings and update procedures.
If you believe you have been affected by a security incident involving your Seasonable account, contact us immediately at hello@seasonable.nl.
Responsible disclosure
We welcome responsible disclosure of security vulnerabilities. If you have found a potential security issue in the Seasonable platform or website, please report it to us before making it public so we have the opportunity to investigate and fix it.
Report a vulnerability: Email hello@seasonable.nl with the subject line "Security disclosure: Seasonable". Include a clear description of the issue, steps to reproduce it, and the potential impact. We will acknowledge receipt within 5 business days and aim to resolve confirmed issues within 30 days.
Please do not access, modify, or delete data that does not belong to you. We will not pursue legal action against researchers who act in good faith and follow this policy.
What we ask of you
Security is a shared responsibility. As a Seasonable Operator, you can protect your account by:
- Using a strong, unique password for your Seasonable account.
- Not sharing your login credentials with others.
- Logging out after using shared computers or devices.
- Reporting suspicious activity on your account promptly.
- Keeping the email address on your account current so we can reach you in an emergency.
Questions
For any security questions not covered here, contact:
Seasonable
hello@seasonable.nl