Working with us
How we handle your client data
Automating a process usually means touching a spreadsheet full of real people. This is what happens to it, written before you ask, because you should not have to.
If you are looking for what this website collects, that is on the privacy page. This page is about the data you hand us when we work together, which is a different question with a different answer.
The short version
Four things that decide most of the risk
- We ask for made-up data first. Automation needs the shape of your data, not the contents.
- The work runs in your environment. Your accounts, your storage, your keys. Your records mostly never arrive here at all.
- Every supplier that could see it is named, below, before it is used.
- You get a data processing agreement without having to chase us for one.
Why we ask for fake data
A column called customer_email full of a@example.com
builds and tests exactly the same automation as one full of real addresses. The
logic does not know the difference. So the default request is structure and a handful of invented rows, and for most projects, that is where it ends.
Synthetic data is often better for building than the real thing, because the awkward cases can be written deliberately rather than waited for: the empty field, the name with an apostrophe, the date in the wrong format, the duplicate that should not exist.
We move down that list one step at a time, only when the step above genuinely will not work, and we tell you why.
Where the work happens
Builds run on your own accounts and infrastructure. That is our standard position for reasons that have nothing to do with data protection: you own what you paid for, and there is nothing to migrate if you stop working with us. But it happens to be the strongest privacy control available: data that never leaves your environment is not exposed by ours.
It also keeps the supplier list below short. When an automation calls a service under your own key, that service is your supplier, not ours. It never enters our contract chain.
AI services, specifically
We sell AI automation, so this deserves saying plainly rather than leaving you to wonder.
Our rules for anything involving a language model
- Never a consumer AI subscription. A personal ChatGPT or Claude account has no data processing agreement behind it. Your customer records do not go near one.
- Business tiers only, with a data processing agreement, zero data retention, and no training on anything submitted.
- Named and authorised before use, never explained afterwards.
- Under your account and key wherever the platform allows, so the vendor answers to you directly.
- Redacted or synthetic input even when a DPA is in place. The best control is still not sending the data.
Who else could see it
These are the suppliers involved in running the practice itself. Anything specific to your project is named in your agreement before it is used, and you get notice and a right to object before we add anything.
The typefaces on this site are served from our own domain rather than a font CDN, so loading a page does not disclose your IP address to a third party.
Roles, in the legal sense
When you engage us and we handle data about your customers or staff, you are the controller and we are the processor. You decide what happens to that data; we act on your instructions. GDPR Article 28 requires a written agreement between us, and we will send you one rather than wait to be asked.
It covers what the regulation requires: processing only on your instructions, confidentiality, security measures, sub-processor rules, help with data subject requests, breach notification, and deletion or return of everything at the end, confirmed in writing.
We are a United States company. Where you are in the EEA or the UK, the agreement includes the European Commission's standard contractual clauses, with the UK addendum where that applies.
What we will not take
Some data raises the bar past what is proportionate for work of this size. We will say no, or ask for specific terms first, rather than accept it and hope:
- Health, biometric, genetic or other special category data (GDPR Article 9)
- Criminal offence data, and children's data
- US healthcare data, without a signed HIPAA business associate agreement: a GDPR agreement does not cover it and the two are not interchangeable
- Payment card details, which belong with a processor already built for them
If something goes wrong
If we become aware of a breach affecting your data, we tell you without undue delay and within 24 hours, before we have the full picture, not after. Your own 72-hour deadline to notify a regulator starts when you find out, so waiting until the investigation is tidy would be spending your time, not ours.
Want the paperwork before you talk to us? Ask and we will send the data processing agreement and our technical and organisational measures document. No call required, and no obligation to have one.
Get in touch