Our objective
Information is a fundamentally critical and valuable business asset for Doclan. We recognise that its security, accessibility and integrity are essential for our staff and customers to carry out their work successfully. Our objective is to ensure that all information and information systems of value to Doclan are adequately protected from threats that could disrupt or compromise them.
Security framework
Our policies provide a framework for the management and security of Doclan information assets against internal or external, deliberate or accidental threats. They cover all aspects of information security, including physical security, site access, data stored on computers, information transmitted across networks, printed or written material, and data stored on fixed or removable drives.
Our assets include any item or body of information, information storage system, information processing system, related intellectual property, and third-party assets under our control.
Supporting procedures protect against security threats and minimise the likelihood and impact of security incidents.
Scope
This policy statement applies to:
- Everyone with access to Doclan or customer systems.
- All information made available to Doclan through its operational activities.
- Principal information assets, including the physical locations from which Doclan operates.
Commitment and compliance
Doclan is committed to all aspects of its information security management system and aims to continually improve information-security performance based on the international standard ISO 27001:2022.
Doclan complies, and will continue to comply, with legal and regulatory requirements affecting its handling of data and information. Doclan acts as a data processor rather than a data controller and is registered with the ICO. Our systems process data transparently, including deletion, to help customers comply with current data-protection legislation.
Responsibilities and incidents
Doclan is responsible for implementing this policy and supporting procedures within each business area. Every employee is responsible for adhering to the policy, and disciplinary processes may apply if staff fail to meet these requirements.
All staff receive appropriate information-security training and guidance. Any actual or suspected breach, including unauthorised disclosure, must be reported to a direct report and/or a Doclan Director. All information-security breaches must be documented and investigated.
Contact
For information-security enquiries, email info(at)doclan.co.uk.
Doclan Director · November 2025
