How we handle your data

Short, because the rules are simple. Ask if anything here doesn't cover your situation.

Before we see anything

We sign your NDA, or provide ours, where required. With or without one, we work to your security and privacy policies from the first conversation. If you have a supplier onboarding process, we complete it.

Where the work happens

All development runs inside your own Microsoft tenant, on licences you already own. We do not copy your data to our systems, and nothing is hosted on a consultant's server or laptop.

Access

You grant access, scoped to the engagement and to the workspaces the work needs. We hold it only for as long as the engagement runs. At handover it is removed and you're told what was used.

Security by design

Row-level security, classification and lineage are designed into the model from the start, not added at the end. Every change is under version control, so there is an audit trail of what was built and when.

Personal information

We work to the Australian Privacy Principles for handling personal information. The founder is an Australian citizen based in Canberra.

Marketing

Client work is never used in our marketing without written permission. Case studies are anonymised unless you agree otherwise.

Compliance and registration requirements

Some clients need a supplier to hold a particular registration, accreditation or security posture before work can start. We assess these case by case and register where it's required for the engagement. Tell us what your procurement or compliance team needs and we'll confirm what we can meet, and how quickly, before you commit.

Book a fit call