Appalachian Insights and Analytics, LLC

Data Security Policy

Protecting research data, client information, and organizational assets

Effective: July 1, 2026  |  Annual Review: July 1, 2027

1. Purpose and Scope

This Data Security Policy establishes the standards and practices Appalachian Insights and Analytics, LLC ('AIA') uses to protect the confidentiality, integrity, and availability of data in our care. This policy applies to all AIA personnel, contractors, and systems that handle organizational, client, research participant, or federal data.

2. Data Classification

Level 1 — Public

Information approved for public release (website content, published reports, marketing materials). No special handling required.

Level 2 — Internal

Business information not intended for public release (financial records, contracts, operational documents). Store securely; do not share externally without authorization.

Level 3 — Confidential

Client data, proprietary research findings, personally identifiable information (PII). Restricted access; encrypted storage and transmission required.

Level 4 — Restricted / Sensitive

Federal agency data, human subjects research data, protected health information (PHI), and data subject to federal data use agreements. Highest protection standards apply, governed by applicable federal regulations including FISMA and HIPAA where applicable.

3. Data Storage and Access Controls

4. Data Transmission

5. Research Data Protections

6. Incident Response

In the event of a suspected data breach or security incident, AIA will:

7. Training and Compliance