Home / Trust centre
We ask clients to document how they handle data. Here is ours.
A data protection practice that cannot show its own position has no business assessing yours. Everything we publish about our own handling of information sits on this page.
What we publish
Privacy notice
What we collect when you contact us, why we hold it, how long we keep it and how to get it removed.
Grievance redressal
How to complain about anything we do with personal data, who answers, within what time, and where to escalate.
How we protect your data
What we do with access to your systems during an engagement. The controls we hold ourselves to while we assess yours.
Our commitments
Response times, completion criteria, independence and confidentiality, written down so you can hold us to them.
Terms of use
The terms on which this website is published, and what it is and is not.
Responsible disclosure
How to report a security problem with this website, and what we commit to in return.
Engagement terms
How client engagements are set up: scope, fees, revisions, document ownership and independence.
What we do not claim.
We are a new practice. We hold no ISO certification, we have not been through an external security audit, and we are not going to display badges we have not earned. Several firms in this market do, and a buyer cannot easily tell the difference between a certificate and a logo on a page.
What we offer instead is specific and checkable. We publish our commitments with times attached, we publish exactly what we do with access to your systems, and we publish completion criteria for every document we produce. You can hold us to all three, and you can ask for any of it in writing before you engage us.
If your procurement process requires a certified supplier, say so on the first call. We will tell you honestly whether we clear your bar, and if we do not, we would rather say so than waste a month of your time.