Cybersecurity, Confidentiality and Responsible Digital Strategy

Loving Social Media takes the protection of client information seriously. Our approach covers how we receive, use, store and share information while delivering marketing and digital services.

Access to client information

We restrict access to client information to authorised people who need it to deliver the agreed work. Where subcontractors are involved, we require appropriate confidentiality commitments.

We use individual accounts where available, strong passwords and multi-factor authentication on supported services. Passwords must not be included in ordinary emails, chat messages or project documents.

Confidential projects

Before starting a confidential project, we review the client’s requirements and any confidentiality agreement. We agree the permitted tools, people and sharing arrangements.

Confidential information must not be published, used in another client’s work or included in our portfolio without permission. Confidential project links must use access restrictions appropriate to the information involved. An unlisted or difficult-to-guess link is not a substitute for access control.

AI and external services

We may use AI and other digital services to support research, drafting, design and analysis.

Before providing confidential client information to an external service, we check whether the client’s agreement permits that use. Where permission is required, we obtain it first.

We assess the service’s account protections, training settings, retention arrangements and access controls. We use business accounts and settings appropriate to the project’s requirements.

We do not enter passwords, access tokens or identifiable patient information into general-purpose AI tools. AI-assisted outputs are reviewed by a person before delivery or publication.

Devices and file storage

Devices used for client work must have current security updates, screen locks and appropriate protection against unauthorised access. Confidential files must be stored in approved locations with suitable permissions and encryption.

Saving a file on a desktop does not, by itself, establish that it is secure or that no cloud copies exist.

Retention and deletion

We agree how long project information needs to be retained, taking account of client instructions, contractual requirements and necessary business records.

When information is no longer needed, we remove working copies from locations under our control, subject to applicable retention requirements. External providers and backups may have separate deletion schedules. We do not promise immediate permanent deletion

  • Responsibility: “Garry Kousoulou is responsible for overseeing this policy.”
  • Dates: The actual adoption date and next review date. Don’t backdate it.
  • Reporting: “Report suspected security incidents to info@lovingsocialmedia.com.”
  • Privacy Notice: Link to the page explaining how you handle personal information.
  • Client requirements: “Where a client agreement requires stricter controls, those requirements take precedence.”

Reassuring me we do on a monthly basis with all the team

  • Secure sign-ins: unique passwords, passkeys where supported, and two-factor authentication.
  • Controlled access: individual accounts, limited permissions and prompt removal when someone leaves.
  • Protected computers: encryption, updates, malware protection and automatic screen locking.
  • Controlled sharing: restricted client folders and a review of connected apps.
  • Clear AI rules: confidential information only goes into tools approved for that client and purpose.
  • Recovery and incident handling: tested backups, retention rules and a named person responsible for security.

A personal commitment from our founder

I’m Garry Kousoulou FBDO, founder and managing director of Loving Social Media, a dispensing optician and marketing strategist. My career spans optical practice, business ownership and digital marketing, where trust and professional responsibility matter every day.

We take the confidentiality of your information seriously and are committed to taking reasonable, practical steps to protect it. No organisation can promise complete protection against every cyber threat. Our responsibility is to keep improving our safeguards, honour our confidentiality commitments and respond promptly and openly if an incident occurs.

We recommend strong, unique passwords stored in a password manager, with two-factor authentication or passkeys wherever available. We also recommend reviewing account access every three months and removing anyone who no longer needs it. Passwords should be changed promptly if they may have been exposed.

If your organisation has particular security or confidentiality requirements, please contact info@lovingsocialmedia.com so we can agree them before work begins.

Garry Kousoulou, FBDO
Founder and Managing Director, Loving Social Media