PRINCIPLES
The principles we work to
We collect what a purpose requires and no more, we use it for that purpose, we keep it accurate, we delete it when it has served its use, and we can account for each of those decisions. These are the Regulation's own principles, and we treat them as operating rules rather than as a preamble.
ROLES
Controller or processor
For our own website, our enquiries and our business contacts, we are the controller. Inside a client engagement the client is the controller and we act on instruction as a processor, under a written data processing agreement signed before any personal data is handled.
TOOLS AND MATERIAL
Before a tool touches anything
No client material enters a tool the client has not approved. Engagement setup includes a written agreement on which classes of material may touch which services, and what stays inside the client's perimeter. We log what actually touched the material and hand that log over on request.
Where a provider offers a business configuration that excludes customer data from model training, we use it, and we show the settings rather than assert them.
OUR OWN AI USE
Our own AI use
We use AI in our own delivery, and we say so in proposals rather than let you discover it. A person reviews every draft before it reaches you, the judgment in our advice is human, and the log of what touched your material covers our internal use too.
SECURITY
Security measures
Access is limited to those who need it, accounts are protected by multi factor authentication, devices are encrypted, and material is stored in managed services rather than on loose drives. We hold our own material to the standard we ask of a client's.
We make no claim to a certification we do not hold. If your assessment needs evidence beyond this page, ask and we will answer specifically.
SUBPROCESSORS
Providers we rely on
We use a small number of providers for email, hosting, internal systems and document storage, each under written terms. Which ones apply to an engagement, and where they process, is declared for that engagement rather than buried in a general list.
Processing stays within the European Union and the European Economic Area wherever it can. Where it cannot, we rely on the safeguards EU law requires, and we say so before the engagement starts.
IF SOMETHING GOES WRONG
Breach handling
If personal data is exposed, lost, or reached by someone who should not have reached it, we contain it first and then tell the people who need to know. Where we act as processor, the client is told without undue delay so that their own notification clock can run.
Where we are the controller, we assess the risk and notify the supervisory authority and the individuals affected where the Regulation requires it. We do not wait for a complete picture before making the first call.
PEOPLE
The people doing the work
Everyone working on an engagement is bound by confidentiality and works to this policy. Independent specialists join per project, under the same undertakings, and are given only the access their part of the work requires.
REVIEW
Review
We review this policy when the way we work changes, and at least once a year.
Last updated 25 July 2026.