We treat client data, project assets, submitted materials, and business information as client-controlled information unless a written agreement states otherwise. Where we build, host, maintain, or integrate digital systems on your behalf, we handle that data only to deliver the agreed services, support the solution, secure the environment, and maintain operational continuity.
We aim to collect and retain only the data reasonably necessary for project delivery, support, communication, billing, security monitoring, and compliance obligations. We encourage clients not to provide unnecessary sensitive information unless it is essential to the solution and explicitly agreed as part of the project scope.
Depending on the solution, client data may be processed through infrastructure, cloud hosting, analytics, communication, backup, or AI providers selected to support delivery. We use reputable service providers and limit access to what is operationally required. Where third-party platforms are part of the agreed solution, their own terms, infrastructure practices, and regional storage policies may also apply.
We retain project and support data for as long as reasonably necessary to deliver the engagement, maintain hosted systems, preserve backups, resolve disputes, meet accounting obligations, and comply with applicable legal or contractual requirements. At the end of an engagement, deletion, transfer, export, or continued retention terms should be governed by the applicable service agreement or a written handover plan.
We apply reasonable administrative, technical, and operational safeguards designed to protect data against unauthorised access, loss, misuse, or disclosure. These safeguards may include role-based access controls, credential management practices, encrypted transmission, logging, backups, and environment separation where appropriate. No system can be guaranteed to be completely immune from risk, but we take security responsibilities seriously and design with practical risk reduction in mind.
If we become aware of a confirmed incident that materially affects client data under our control, we will act promptly to investigate, contain, and communicate the issue through the appropriate client contact, subject to the information available at the time and any legal or contractual constraints. Timelines for notice and remediation may vary depending on the nature of the incident, hosting arrangement, and client agreement.
Clients remain responsible for the legality, accuracy, and integrity of the information they provide to us, including whether they have the right to submit that information for processing. Where a project involves regulated, confidential, or sensitive information, the client should disclose that context early so the correct handling, access, storage, and contractual controls can be agreed before implementation begins.
Because modern digital delivery may involve global cloud infrastructure, backups, content delivery networks, analytics tools, and managed service providers, some project data may be processed or stored outside the client's home jurisdiction. Where cross-border processing is relevant, we aim to use commercially reasonable providers and configurations appropriate to the service, but regional residency guarantees should only be treated as binding where expressly agreed in writing.
Questions about how project data is handled, retained, secured, transferred, or returned should be raised through the designated project or support contact so they can be reviewed against the actual delivery arrangement. This page provides the general operating standard; project-specific data governance details should always be read together with the signed proposal, maintenance plan, handover agreement, or hosting terms applicable to the engagement.