Legal

Privacy Policy

Plain-language summary of what we collect, why, and how it is protected.

Information we collect

  • Contact details you submit through forms, audits, quote requests and consultation bookings — name, email, phone, company, website.
  • Business context you provide: industry, goals, challenges, requested services, budget and timeline.
  • Attribution data such as referral source and UTM parameters attached to your visit.
  • Account and portal data if you are an active client, including project files, messages, contracts and payment records.

How we use it

  • To respond to enquiries, prepare quotes and proposals, and deliver contracted work.
  • To generate audit results, scoring and system recommendations.
  • To operate your client portal, including project status, files, invoices and support.
  • To improve our services and understand which channels bring qualified enquiries.

What we never do

  • We do not sell your information.
  • We do not share client data between clients — access is enforced at the database level with row-level security.
  • We do not use your project content to train third-party models.

Storage and security

  • Data is stored in a managed PostgreSQL database with encryption in transit and at rest.
  • Access is role-based; internal staff access is scoped and audit-logged.
  • Uploaded files are stored in private buckets and served only through short-lived signed links.

Payments

  • Card and bank details are handled entirely by Stripe. We never receive or store full payment credentials.

Your rights

  • You can request a copy of the information we hold about you, ask for corrections, or ask us to delete it where we are not required to retain it.
  • Marketing emails include an unsubscribe link, and you can opt out at any time.

Contact

  • For any privacy question or request, use the contact page and we will respond within five business days.