Access
We ask for access only to the data and systems needed for your project. Access is read-only by default. If we need to build reports, models, or automations in your environment, we agree in writing on where we can create or change content. We don't change or delete your source records.
Passwords and system access
We ask for named accounts rather than shared logins and use the least access needed for the work. Credentials are kept in an encrypted password vault, not in email or messages. We review access during the engagement and remove credentials when the project or ongoing service ends.
Storage
When we need copies of your files, we keep them in encrypted cloud storage in a separate folder for your business. Where practical, we work in your own systems instead of copying data out.
Delivery
We deliver confidential files through a secure client portal. Reports and other work built in your environment stay there; we use the portal for handoff documents.
Retention and deletion
We delete raw data extracts when they're no longer needed, no later than the end of the project or service. Our standard retention periods are one year for working files and notes and three years for final deliverables. If you'd like everything deleted sooner, tell us any time before the project or service ends. We'll delete it at close and confirm in writing.