Hybrid Working Policy
Apollo Accreditation
1. How we work
We work across Malta and the United Kingdom, mostly remotely, with client work carried out wherever the person doing it happens to be. This policy exists because that model creates confidentiality and security obligations that an office model handles by default.
2. Client material
Client material includes draft curricula, assessment instruments, staff records and evidence prepared for submission. Some of it is commercially sensitive and some contains personal data.
Client material is stored only in approved organisational systems, never on personal accounts, personal devices without protection, or removable media.
3. Working away from a private space
Client material is not opened on public or shared networks without a VPN, is not displayed where it can be overlooked, and is not discussed where it can be overheard. Assessment instruments in particular are not to be visible in public.
4. Devices
Every device used for client work has full disk encryption, an automatic lock, a current operating system, and multi-factor authentication on every account that offers it.
Loss or theft of a device is reported the same day so access can be revoked.
5. Cross-border working
Working from Malta or the United Kingdom is routine. Where someone will work from outside those jurisdictions for a sustained period, it is agreed in advance so that the data transfer position and any tax or employment consequence is understood.
6. Availability
Hybrid working does not change what a client can expect. Deadlines in a scope are met regardless of where the work is done, and we are contactable during Central European Time working hours.
7. Wellbeing
Remote work blurs the line between working and not working. Time off is time off, and nobody is expected to answer outside working hours except where an agreed deadline requires it.
8. Review
Reviewed annually and after any security incident.