Delmara Baltic Living
Security & Compliance
Last updated: 11 September 2026
1. Security Governance & Commitments
Delmara Baltic Living (operated by Infinity Consciousness Europe SIA) is committed to rigorous standards in information security and data privacy. Our technical and organizational measures align directly with ISO/IEC 27001 (Information Security Management Systems), SOC 2 Type II Trust Services Criteria (Security, Availability, Confidentiality, and Privacy), and the European Union General Data Protection Regulation (GDPR - Regulation (EU) 2016/679).
Security and privacy controls are built into every level of our engineering lifecycle under our Security by Design framework.
2. ISO/IEC 27001 Technical & Organizational Controls (TOMs)
- Cryptography (A.8.24): All data in transit is encrypted using modern TLS 1.3 cipher suites. HTTP Strict Transport Security (HSTS) is enforced with a 2-year max-age and preloading flag. Data at rest is encrypted via AES-256 across database instances and cloud object stores.
- Network and Browser Security (A.8.20 / A.13): Comprehensive browser defenses include Content-Security-Policy (CSP), X-Frame-Options: DENY (anti-clickjacking), X-Content-Type-Options: nosniff, and strict Permissions-Policy.
- Access Control (A.8.2 / A.9): Principle of Least Privilege. Database queries enforce PostgreSQL Row Level Security (RLS) guaranteeing tenant isolation. Administrative CMS access is protected with token-based role authentication (RBAC).
- Abuse & Denial-of-Service Defense (A.8.7): Dynamic sliding-window rate limiting on critical endpoints (checkout payment initiation, guest registration, support messaging) mitigates brute force and resource exhaustion vectors.
- Logging and Monitoring (A.8.15 / A.12.4): Structured security event logging captures operational telemetry while applying cryptographic IP anonymization and zero-credential redaction.
3. SOC 2 Type II Trust Services Criteria
- Security (CC6): Perimeter defense via CDN edge firewalls, container isolation, and automated secrets handling via encrypted environment key stores.
- Availability (CC7): Global multi-region edge delivery (Vercel Edge Network and Cloudflare Global CDN) ensuring resilience against localized outages.
- Processing Integrity (CC8): Deterministic server-side recalculation and validation of basket items, destination VAT, and exchange rates prior to payment authorization.
- Confidentiality: Strict segregation of customer personal details and restriction of operational access to designated security personnel.
- Privacy: Transparent notification of data processing purposes, storage limits, and cross-border transfer protections.
4. GDPR Compliance & Data Subject Rights
Data Controller: Infinity Consciousness Europe SIA, Vēja iela 4-2, Ādaži, 2164, Latvia. Inquiries: hello@delmaraliving.com. Supervisory Authority: Data State Inspectorate of Latvia (Datu valsts inspekcija, dvi.gov.lv).
- Right of Access & Data Portability (GDPR Art. 15 & 20): Authenticated customers can download a full, machine-readable JSON archive of all personal data (profile, addresses, orders, baskets) directly from Account → Profile & addresses.
- Right to Erasure / 'Right to be Forgotten' (GDPR Art. 17): Self-service account deletion permanently purges customer profiles and saved addresses. Statutory financial records are anonymized to fulfill statutory EU/Latvian tax obligations under Art. 17(3)(b).
- Consent Management (GDPR Art. 6 & 7): Zero non-essential tracking occurs prior to explicit consent. Preferences can be updated or revoked anytime via our interactive consent manager.
5. Sub-Processor Directory & Safeguards
All third-party infrastructure and service providers are vetted for regulatory compliance, holding valid Data Processing Agreements (DPAs) incorporating EU Standard Contractual Clauses (SCCs):
- Supabase Inc. (Database & Auth): ISO 27001 & SOC 2 certified, EU Frankfurt data center.
- Stripe Payments Europe Ltd. (Payment processing): PCI-DSS Level 1 certified payment service provider, Ireland/EU.
- Vercel Inc. (Hosting & Edge Computing): ISO 27001 & SOC 2 Type II certified global infrastructure.
- Cloudflare Inc. (CDN & Media Storage R2): ISO 27001 & SOC 2 Type II certified edge network.
- Brevo / Sendinblue SAS (Transactional Email): ISO 27001 certified, servers located within the European Union.
6. Vulnerability Disclosure Policy (RFC 9116)
We value the contribution of independent security researchers. Our security policy is published in accordance with RFC 9116 at /.well-known/security.txt.
Please report suspected security issues to security@delmaraliving.com or hello@delmaraliving.com. We acknowledge receipt within 24 business hours and coordinate remediation with high priority.