Home / Trust centre / How we protect your data
You are about to give us a view of your systems.
An engagement means handing a consultant access to the places your personal data lives. That is a real risk to take on, and the least we can do is publish exactly what we do with that access.
The principle
We hold ourselves to the controls we ask clients to adopt. Every rule below is one we would write into your own data protection policy, so it would be difficult to defend not following it ourselves.
All of it is contractual. These commitments go into the engagement letter, which means you can enforce them rather than simply trust them.
Before we start
- Confidentiality first. We sign a confidentiality agreement before any system access, and before you send us anything.
- A named team. You are told who will work on the engagement. Nobody else gets access, and we do not rotate people in without telling you.
- No subcontracting by default. If a specialist is genuinely needed we name them, explain why, and wait for your written agreement. We do not pass your material to anyone you have not approved.
How we take access
- Named accounts, never shared logins. Each person on our side gets their own account on your systems, so your audit log shows who did what. We will decline a shared password.
- Read only wherever it is possible. Discovery almost never needs write access. Where a task genuinely needs it, we ask for it for that task and nothing wider.
- Time boxed. Access is requested for a stated period and we ask you to revoke it at the end of the step. We also remind you to, because clients forget and that is exactly the gap we are hired to find.
- Multi factor authentication on our side, always. Every account we hold on your systems has it enabled.
- We log what we looked at and that log goes into your evidence pack, so you can reconcile our activity against your own records.
What we take away
This is the part most consultancies get wrong. The usual pattern is a request for a full export so the analysis can happen offline, which doubles the number of places your data exists.
- We do not ask for data dumps. Discovery works from configuration, structure and counts: which fields exist, how many records, who has access, what the retention setting is. It does not need the records themselves.
- Screenshots are redacted at capture. Where we need visual evidence of a setting, personal data in the frame is obscured before the image is saved.
- Where a sample is unavoidable, for instance to show that a form writes to a field, we take the smallest possible sample, we agree it with you in advance, and it is destroyed at the end of that step rather than at close out.
Where the work happens
- Encrypted, managed devices only. Full disk encryption, automatic locking, current operating system and patches.
- No personal accounts or personal devices. Client material never moves into a personal email account, a personal drive or a personal phone. That includes WhatsApp, which we use for scheduling and never for documents.
- One agreed channel for exchange. We set up a single secure location for documents at the start, and we use it. Sensitive files do not travel as email attachments.
- Access on our side is restricted to the named team, not to the whole firm.
What we keep, and for how long
| Material | Held until | Then |
|---|---|---|
| Samples and system exports | End of the step that needed them | Destroyed, confirmed in writing |
| Screenshots and configuration evidence | Close out | Handed to you, our copies destroyed |
| Interview notes and working papers | Close out | Handed to you, our copies destroyed |
| Final deliverables | 3 years after close out, or another period you choose | Destroyed on the agreed date |
| Engagement letter and invoices | As Indian tax and company law requires | Retained, access restricted |
At close out you receive a written confirmation of what was destroyed and when. If you would rather we kept nothing at all beyond the contractual minimum, we will specifically ensure the same we achieved within the limits of legal requirements of retention.
If something goes wrong on our side
We will tell you. Not after we have fixed it, not after we have established how bad it is, but as soon as we have reason to believe your material may have been exposed.
- You hear from us within 24 hours of us becoming aware, with what we know at that point, even if that is very little.
- We give you a named contact and a written update at least daily until it is closed.
- We give you everything you need for your own notification obligations, because they are yours to meet and the clock is running on you as well as on us.
- You get a written account afterwards covering what happened, what we changed, and what it means for the engagement.
Confidentiality
We do not name clients publicly without written consent. No logo on our site, no case study, no mention in a proposal to someone else, not even a sector reference if it would identify you. If we ask to use you as a reference, you are free to say no and it changes nothing about the engagement.
You can check
You are entitled to ask us, in writing, how we are holding your material, which of our people have access, and what has been destroyed. We will answer within ten working days. If your own compliance process requires a supplier assessment questionnaire, send it and we will complete it honestly, including the questions where the answer is no.
What we ask of you
Some of this only works if both sides do it.
- Give access through your own administrative console rather than by sharing a password.
- Revoke our access at the end of the engagement, and tell us you have. We will ask.
- Do not email us customer records, identity documents or passwords. Use the agreed channel, and if in doubt ask us first.
- Tell us if someone on your side leaves mid engagement, so we can adjust who we are talking to.