Data Processing
Last updated September 21, 2026
When we build or run systems for a client, we handle personal data that belongs to that client. This page sets out how. It supplements, and does not replace, the data processing agreement signed for each engagement.
01Roles
For data in a client system, the client is the controller and we are the processor. We act on the client instructions recorded in the engagement agreement and nowhere else.
For data collected through our own website, we are the controller, and the privacy policy on this site applies.
02What we do with client data
We process it only to deliver the agreed work: building, migrating, testing, and operating the systems described in the agreement. We do not use client data for our own purposes, we do not use it to train AI models, and we do not disclose it except to the sub-processors named in the agreement.
03Security
Access is limited to the named people working on the engagement and is removed when it ends. Production credentials are held in a secrets manager rather than in code or documents. Connections use TLS. Databases are encrypted at rest by the hosting provider.
Where we need production data for testing, we work with anonymised copies. Where anonymisation is not possible, we agree the exception in writing first.
04Sub-processors
Hosting, database, email, and analytics providers are named in each engagement agreement before work starts. We tell clients before adding a new one, and a client may object.
05Incidents
If we become aware of a personal data breach affecting client data, we notify the client without undue delay and in any case within 48 hours, with what we know at the time rather than after an internal investigation completes.
06End of engagement
At the end of an engagement we return client data in a usable format and delete our copies, except where law requires retention. Repositories and hosting accounts are already in the client name, so nothing needs to be transferred.