Security Policy

Effective Date: 21/11/2025

1. Introduction

1.1. This Security Policy (hereinafter - the “Policy”) is an official document ofSKYNEX LTD, a company registered in England and Wales under company number16866353 (hereinafter - the “Company”, “we”, “us”, or “our”).

1.2. The purpose of this Policy is to establish the technical, organizational, and administrative measures used to protect the website https://elysiumskins.com (hereinafter - the “Service”), its systems, Users, transactions, and related data against internal and external threats.

1.3. This Policy applies to the Company’s operation of the Service, as well as to Users, employees, contractors, and other authorized persons who may interact with or access the Service, related systems, or related data.

1.4. The Company recognizes that security is a critical element of user trust and undertakes to maintain security standards aligned with applicable legal requirements, reasonable industry practices, and the operational needs of the Service.

2. Objectives

2.1. The objective of this Policy is to maintain an appropriate level of information, operational, and transaction security for the Service.

2.2. The Company’s key security objectives include:

  • preventing unauthorized access to accounts, personal data, and digital assets;
  • protecting the integrity and security of transactions and payment-related processes;
  • maintaining the availability and resilience of the Service;
  • detecting, preventing, and mitigating security incidents;
  • reducing the risk of fraud, abuse, and unauthorized activity;
  • supporting compliance with applicable laws and internal security procedures.

3. Security Principles

The Company follows the following core security principles:

  • Confidentiality - personal and sensitive information is accessible only to authorized persons where necessary.
  • Integrity - systems and data are protected against unauthorized or improper alteration.
  • Availability - the Service is maintained with a view to operational continuity and resilience.
  • Accountability - security-related actions and access rights are assigned, controlled, and reviewable.
  • Least privilege - access is granted only to the extent necessary for a legitimate operational purpose.
  • Continuous improvement - security controls are reviewed and updated over time in response to new risks and operational needs.

4. Technical Measures

4.1. Secure Transmission and Encryption

The Company uses reasonable technical measures to protect data transmitted through the Service, including:

  • secure HTTPS connections using current transport security standards where appropriate;
  • encryption of sensitive data in transit;
  • security controls designed to reduce the risk of interception or unauthorized access.

4.2. Infrastructure and Hosting

The Company uses hosting and infrastructure measures designed to support security, continuity, and resilience, including:

  • controlled hosting environments and service providers;
  • access restrictions for administrative systems and infrastructure;
  • backup and recovery measures intended to reduce the impact of technical incidents or data loss.

4.3. Network and System Security

The Company may use technical safeguards such as:

  • firewalls and system protection controls;
  • monitoring and alerting tools;
  • anti-abuse and anti-bot measures;
  • malware protection and vulnerability management measures;
  • access logging and security event monitoring.

4.4. Authentication and Access Control

The Company applies access control measures appropriate to the Service, including:

  • User authentication through supported login mechanisms, including Steam authentication where applicable;
  • administrative access controls and account restrictions;
  • multi-factor authentication or equivalent security measures for privileged access where appropriate;
  • periodic review of access rights for internal accounts.

4.5. Monitoring and Logging

The Company may maintain logs and monitoring systems to:

  • detect suspicious activity;
  • investigate incidents and abuse;
  • support fraud prevention and security analysis;
  • maintain operational visibility and troubleshooting capability.

Security logs and related records may be retained for as long as reasonably necessary for security, compliance, operational, or investigative purposes.

5. Organizational Measures

5.1. Access Management

The Company applies organizational access controls, including:

  • access on a need-to-know basis;
  • role-based access controls where appropriate;
  • periodic review and removal of unnecessary access rights.

5.2. Staff Awareness and Security Practices

The Company may provide appropriate internal guidance, procedures, and training relating to:

  • cybersecurity awareness;
  • secure handling of systems and data;
  • incident escalation and reporting;
  • fraud prevention and access control responsibilities.

5.3. Incident Response

The Company maintains internal procedures for responding to security-related issues. Such procedures may include:

  • identifying, recording, and assessing incidents;
  • containing and mitigating security risks;
  • investigating the nature and impact of an incident;
  • taking corrective actions where appropriate;
  • notifying affected parties or authorities where required by law.

5.4. Risk Review and Security Assessment

The Company may periodically review risks, systems, and controls in order to identify vulnerabilities, improve resilience, and support compliance and operational security.

6. User Responsibilities

6.1. Users are responsible for taking reasonable steps to protect their own accounts and devices. Users agree to:

  • keep their Steam account credentials and login details confidential;
  • use secure and unique credentials for related accounts where applicable;
  • refrain from sharing account access with third parties;
  • ensure their device and environment are reasonably secure;
  • notify the Company promptly in the event of suspected unauthorized access, suspicious activity, or security concerns related to their account.

6.2. Users acknowledge that failure to follow reasonable security practices may increase the risk of unauthorized access, account compromise, transaction issues, or loss of access.

7. Relationship with Other Policies

This Security Policy forms part of the Company’s overall compliance and operational framework and should be read together with the following documents:

  • Terms of Service - governing the general conditions of using the Service;
  • Privacy Policy - describing how personal data is collected, used, stored, and protected;
  • Cookie Policy - describing the use of cookies and similar technologies;
  • KYC and AML Policy - describing verification, compliance, and payout control measures;
  • Refund & Chargeback Policy - describing refund and dispute handling rules;
  • Prohibited Activities Policy - describing activities that are not permitted on the Service;
  • Risk Disclosure Policy - describing relevant risks connected with use of the Service.

In the event of a conflict between this Policy and another Company policy, the more specific policy shall apply to the relevant subject matter.

8. Limitation of Liability

The Company takes reasonable steps to maintain the security of the Service. However, Users acknowledge that:

  • no online service or technical system can be guaranteed to be completely secure;
  • the security of third-party accounts, including Steam accounts, depends in part on the User’s own actions and the third-party provider’s systems;
  • the Company is not responsible for failures, breaches, delays, or incidents caused by third-party services, platforms, payment providers, infrastructure providers, or events beyond the Company’s reasonable control, except as required by applicable law.

Nothing in this Policy limits any rights that Users may have under applicable consumer protection or data protection law.

9. Policy Updates

The Company may amend, update, or revise this Policy from time to time to reflect changes in:

  • technology;
  • security practices;
  • operational requirements;
  • legal or regulatory requirements.

Any updated version will be published on the Service with the effective date clearly stated. Continued use of the Service after publication of an updated version constitutes the User’s acknowledgment of the revised Policy.

10. Contact Information

SKYNEX LTD

Company number: 16866353

Registered address: 85 Great Portland Street, First Floor, London, England, W1W 7LT

Email: [email protected]

Website: https://elysiumskins.com

If you have any questions regarding this Security Policy or wish to report a security-related concern, you may contact the Company at [email protected]