Data Security & AI Use

How we handle
your data and use AI.

Our practices for access, confidentiality, retention, and using AI with your permission.

How we handle your data

Access

We ask for access only to the data and systems needed for your project. Access is read-only by default. If we need to build reports, models, or automations in your environment, we agree in writing on where we can create or change content. We don't change or delete your source records.

Passwords and system access

We ask for named accounts rather than shared logins and use the least access needed for the work. Credentials are kept in an encrypted password vault, not in email or messages. We review access during the engagement and remove credentials when the project or ongoing service ends.

Storage

When we need copies of your files, we keep them in encrypted cloud storage in a separate folder for your business. Where practical, we work in your own systems instead of copying data out.

Delivery

We deliver confidential files through a secure client portal. Reports and other work built in your environment stay there; we use the portal for handoff documents.

Retention and deletion

We delete raw data extracts when they're no longer needed, no later than the end of the project or service. Our standard retention periods are one year for working files and notes and three years for final deliverables. If you'd like everything deleted sooner, tell us any time before the project or service ends. We'll delete it at close and confirm in writing.

How we use AI

We use AI for selected tasks, such as organizing notes, identifying possible data issues, and drafting documentation. A person reviews its output before we rely on it or share it with you.

Your choice

We'll explain how we propose to use your data with AI and get your written agreement first. You can decline; we can still do the work without putting your data into an AI tool.

Approved tools

We use only AI services approved for client work under business or API terms that prohibit the provider from using customer data to train its models. We limit what we provide to the information needed for the approved task and remove identifying details where practical.

Solutions built for you

If we build an AI solution for your business, we include documentation, a way for your team to review its output, and a handoff. It runs in your environment or accounts unless we agree otherwise in writing.

Confidentiality

We treat your data, documents, and conversations as confidential. We won't name you as a client without your permission. People working on your engagement must follow our data security policy and have access only to what their work requires.

If something goes wrong

If we discover a security incident that may affect your information, we'll act to contain it and notify you within 24 hours of discovery. We'll tell you what we know at that point, what may be affected, what we've done, and what you may need to do. We'll update you as we learn more.

Let’s talk about your business

Tell us what you’re working through and what you want to improve. We’ll help clarify what’s needed and discuss how GranVision can help.