PQ-COM-11 · Rev. 2026-01
Information Security Policy
Minimum requirements for the handling of systems, access rights and data.
1. Access
- Personal accounts, no shared access credentials.
- Two-factor authentication for e-mail, accounting and remote access.
- Password manager instead of written-down passwords.
- Withdrawal of all access rights on the last working day.
2. Devices
- Encrypted hard drives and automatic screen lock.
- Up-to-date operating system and application updates.
- No processing of business data on private, unprotected devices.
3. Data
- Access only within the scope of the respective task.
- Daily backup of business-critical data and regular restore tests.
- Confidential documents to be sent only in encrypted form or via protected channels.
4. Incidents
Lost devices, suspicious e-mails and possible data leaks must be reported to Executive Management without delay. If an incident concerns personal data with a high risk, we examine whether to report it to the Federal Data Protection and Information Commissioner (FDPIC).
These policies describe the internal order of PHARMEQ AG. They create no third-party entitlements and do not replace any contractual agreement.