Written Information Security Plan (WISP)
Effective Date: April 28, 2025
Business Name: DaVille Unlimited, LLC DBA Equilibrium Consultants
Contact Person: Katherine Scardaville, CEO
Email: info@equilibriumconsultantsnj.com
1. Purpose
We are committed to protecting our clients’ sensitive information. This Written Information Security Plan (WISP) outlines how we safeguard personal and financial data according to IRS Publication 5708, Publication 4557, and the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule.
2. Information We Collect
- Names, addresses, email addresses, phone numbers
- Social Security Numbers and Employer Identification Numbers
- Bank account and routing information
- Tax returns and supporting financial documents
3. How We Protect Information
Physical Security:
- All client paper records are stored in locked cabinets.
- Office doors are locked after business hours.
- Only authorized personnel have access to client files.
Electronic Security:
- All computers are password-protected and have updated antivirus, firewall, and encryption software.
- Two-factor authentication (2FA) is used to access client data.
- Backups are performed daily and stored securely.
- We use secure portals or encrypted emails for transmitting sensitive information.
Access Control:
- Only employees who need access to sensitive information have it.
- Former employees’ access is revoked immediately upon termination.
Training:
- Staff receives annual training on data security and phishing awareness.
4. Response to Data Breaches
- We will investigate immediately to determine the extent of the breach.
- We will notify affected clients and the IRS as required.
- We will document the breach and the corrective actions taken.
- We will review and update our security policies to prevent future incidents.
5. Service Providers and Third Parties
- Verify they have proper security measures in place.
- Require signed confidentiality agreements.
6. Plan Review and Updates
This WISP is reviewed annually or whenever there are significant changes to our operations or applicable regulations. We update policies and train staff accordingly.
7. Client Responsibilities
- Use our secure methods client portal (powered by Accounta.com) when sending sensitive information.
- Notify us immediately if they suspect any data breach related to their information.
Questions?
Please contact Katherine Scardaville at info@equilibriumconsultantsnj.com.