Last Updated: October 2, 2026
1. Purpose
This Data Processing & Confidentiality Policy explains how 1st North Star Consulting (“1st North Star,” “we,” “us,” or “our”) handles personal data, confidential business information, client-provided information, project files, credentials, and other sensitive materials in connection with our services.
This Policy applies to:
- Clients
- Prospective clients
- Agency partners
- Business partners
- Contractors
- Virtual assistants
- Authorized team members
- Other individuals whose information may be processed through our services
This Policy should be read together with our:
- Privacy Policy
- Terms of Service
- Client Service Agreement
- AI Use & Content Responsibility Policy
- Acceptable Use Policy
- Any applicable Statement of Work
- Any applicable Data Processing Agreement
- Any applicable Nondisclosure Agreement
Where a separate signed agreement contains more specific data-processing or confidentiality terms, that agreement will generally control for the applicable project.
2. Our Role in Processing Information
Depending on the service being provided, 1st North Star Consulting may act in different capacities.
For example, we may process information:
- For our own business administration
- To communicate with clients
- To manage payments and billing
- To provide support
- To perform digital services
- On behalf of a client
- Through authorized team members
- Through approved third-party systems
In certain client engagements, the client may determine why and how personal information is processed, while 1st North Star processes that information only as necessary to perform the agreed service.
In those situations, the client may act as the relevant data controller, business, organization, or similar responsible party, while 1st North Star may act as a processor, service provider, contractor, or similar role depending on applicable law.
3. Types of Information We May Process
Depending on the project, we may process:
- Names
- Email addresses
- Telephone numbers
- Business contact information
- Customer records
- CRM records
- Subscriber lists
- Lead lists
- Employee information
- Website content
- Marketing data
- Analytics information
- Social media information
- Product information
- E-commerce information
- Documents
- Spreadsheets
- Images
- Videos
- Audio
- Internal business files
- Website credentials
- Platform credentials
- Project instructions
- Business procedures
- Reports
- Research materials
- Other information reasonably required to complete the project
4. Confidential Information
Confidential information may include any non-public information disclosed in connection with a project.
Examples may include:
- Business plans
- Internal procedures
- Pricing
- Customer lists
- Leads
- Sales information
- Financial information
- Marketing strategies
- Internal documents
- Proprietary content
- Product development information
- Passwords
- Login credentials
- Non-public website information
- Source files
- Business processes
- Trade secrets
- Client communications
- Unpublished content
- Internal reports
- Technical configurations
Information does not have to be marked “Confidential” to be treated as confidential when its nature reasonably indicates that it should not be publicly disclosed.
5. Our Confidentiality Commitment
We seek to use reasonable organizational and technical measures to protect client confidential information.
Confidential information should generally be:
- Used only for legitimate project purposes
- Shared only with authorized personnel
- Accessed only when reasonably necessary
- Stored using appropriate systems
- Protected against unauthorized disclosure
Authorized personnel may include team members, VAs, contractors, or specialists who require access to perform assigned work.
6. Managed Fulfillment and Team Access
1st North Star operates using a managed fulfillment model.
A client contracts with 1st North Star Consulting, while work may be assigned internally to appropriate personnel.
This may include:
- Virtual assistants
- Administrative personnel
- Designers
- Writers
- Editors
- Developers
- Video specialists
- Marketing personnel
- Researchers
- Project coordinators
- Quality reviewers
- Specialized contractors
Not every team member receives access to every client project.
Limit access based on the responsibilities assigned to the individual.
7. Need-to-Know Access
Where practical, we follow a need-to-know approach.
This means team members should receive only the information reasonably necessary to perform their assigned task.
For example:
A graphic designer may not need access to a client’s CRM.
A writer may not need website-administrator credentials.
A video editor may not need access to billing information.
A VA performing data entry may only need the specific spreadsheet required for the task.
This helps reduce unnecessary exposure of client information.
8. Contractor and Team Confidentiality
Where appropriate, authorized personnel may be subject to contractual obligations involving:
- Confidentiality
- Data handling
- Security
- Non-disclosure
- Client information
- Acceptable use
- Intellectual property
- Internal procedures
We may also provide operational guidance on properly handling client information.
9. Client Instructions
When processing information primarily on behalf of a client, we may act according to the client’s documented instructions.
These instructions may be contained in:
- Project brief
- Statement of Work
- Client Service Agreement
- Data Processing Agreement
- Support request
- Other documented communication
We may request clarification where instructions are incomplete or create potential legal, security, or operational concerns.
10. Client Responsibility for Data
Clients are responsible for ensuring that they have appropriate legal authority to provide data to us.
This is especially important when clients provide:
- Customer databases
- Subscriber lists
- Employee information
- Prospect lists
- CRM information
- Personal information
- Marketing data
- Third-party records
Clients should ensure that their collection, processing, and disclosure of such information is lawful and appropriate.
11. Data Minimization
Clients should avoid sending information that is not reasonably necessary for the project.
Where possible, we encourage clients to:
- Remove unnecessary personal data
- Redact sensitive information
- Limit access permissions
- Use test accounts
- Use temporary credentials
- Provide only relevant records
This reduces unnecessary security and privacy risk.
12. Highly Sensitive Information
Clients should not provide highly sensitive information unless it is specifically required for an agreed project and appropriate protections are in place.
Examples may include:
- Full financial account details
- Complete credit-card information
- Government identification numbers
- Passport numbers
- Medical records
- Authentication codes
- Private encryption keys
- Biometric information
- Highly sensitive employment records
If a project requires sensitive data, additional contractual or security arrangements may be necessary.
13. Credentials and Passwords
When clients need account access, they should use secure access practices whenever possible.
Recommended approaches include:
- Creating a separate project account
- Providing limited user permissions
- Using temporary credentials
- Using password-management tools
- Revoking access after completion
- Enabling multi-factor authentication where appropriate
Clients should avoid sharing primary administrative passwords where a limited-access account can be created.
14. Credential Storage
Where credentials must be retained temporarily, clients should use reasonable care to restrict access.
Credentials should not be unnecessarily copied, distributed, or retained longer than required.
Clients are encouraged to change or revoke passwords after project completion.
15. Personal Data Processing
When we process personal information on behalf of a client, we may process it only as reasonably necessary to:
- Perform the service
- Complete project instructions
- Provide support
- Troubleshoot issues
- Maintain security
- Meet legal obligations
We do not acquire independent ownership of client personal data merely because we process it.
16. Data Processing Agreements
Certain clients may require a formal Data Processing Agreement, or DPA.
A DPA may be appropriate when:
- Personal data is processed regularly
- The client operates in a regulated jurisdiction
- EU or UK personal data is involved
- The client requires specific processor obligations
- Sensitive business data is involved
- Contractual privacy requirements apply
The DPA may address:
- Processing instructions
- Security
- Subprocessors
- Data transfers
- Retention
- Deletion
- Data subject requests
- Incident notification
- Audit obligations
17. Third-Party Service Providers
We may use third-party platforms to perform services.
These may include providers of:
- Hosting
- Cloud storage
- File sharing
- Project management
- CRM
- Automation
- Communication
- Accounting
- Payment processing
- Artificial intelligence
- Graphic design
- Video production
- Website tools
- Analytics
- Backup
- Security
These providers may process information according to their own terms, privacy policies, and security practices.
18. Subprocessors and Service Providers
Where 1st North Star acts as a processor on behalf of a client, certain third-party providers or contractors may function as subprocessors.
Examples may include:
- Cloud providers
- Hosting providers
- Software platforms
- Contractors
- Specialized production vendors
- AI providers
Where required by contract or law, additional subprocessor terms may apply.
19. Artificial Intelligence and Data Processing
We may use AI-assisted tools where appropriate for certain projects.
Possible uses include:
- Drafting
- Editing
- Summarization
- Research assistance
- Coding
- Graphic generation
- Video production
- Transcription
- Data organization
- Automation
Clients should notify us before project commencement if specific information must not be processed using third-party AI systems.
20. Confidential Information and AI
Do not automatically submit confidential or sensitive information to external AI systems.
Where a project contains sensitive information, we may:
- Exclude the information from AI workflows
- Redact identifying information
- Use a different production process
- Ask the client for approval
- Use an approved AI environment
If a client’s AI restrictions significantly change the project requirements, additional fees or revised project terms may apply.
21. International Data Processing
1st North Star Consulting operates from the Philippines and serves international clients.
As a result, information may be processed in:
- The Philippines
- The client’s country
- Countries where our service providers operate
- Cloud infrastructure located internationally
Clients acknowledge that cross-border processing may occur where necessary to perform the service.
22. International Data Transfers
Where applicable, international transfers may be supported by:
- Contractual safeguards
- Service-provider agreements
- Data Processing Agreements
- Standard contractual mechanisms
- Other legally recognized measures
The specific mechanism may vary according to jurisdiction and project requirements.
23. Security Measures
We may use reasonable technical and organizational measures appropriate to the nature of the service.
These may include:
- Password protection
- Access controls
- Secure hosting
- Encryption where available
- Multi-factor authentication
- Role-based permissions
- Security updates
- Backup procedures
- Anti-malware tools
- Secure file sharing
- Restricted administrative access
- Internal confidentiality procedures
No security method can guarantee complete protection.
24. Client Security Responsibilities
Clients also have responsibilities for protecting their systems.
Clients should:
- Use strong passwords
- Enable multi-factor authentication where appropriate
- Limit administrator accounts
- Maintain backups
- Install security updates
- Remove former-user access
- Monitor unusual activity
- Revoke temporary credentials after project completion
25. File Sharing
Project files may be exchanged using:
- Cloud storage
- Shared drives
- Secure transfer systems
- Project-management platforms
- Client portals
The appropriate method may depend on the sensitivity and size of the information.
26. Project Files and Working Copies
During production, copies of files may exist in:
- Local work environments
- Cloud storage
- Temporary folders
- Collaboration platforms
- Backup systems
Reasonable efforts may be made to reduce unnecessary copies after the project is completed.
27. Data Retention
Information may be retained for as long as reasonably necessary to:
- Perform services
- Provide support
- Maintain client records
- Maintain financial records
- Resolve disputes
- Defend legal claims
- Comply with legal requirements
- Maintain backups
- Support legitimate business operations
Retention periods may differ depending on the type of information.
28. Project Completion and Data Deletion
After a project is completed, client information may remain temporarily in:
- Project systems
- Cloud storage
- Backups
- Administrative records
Clients may request deletion of eligible information.
Some information may need to be retained for:
- Legal obligations
- Tax records
- Accounting
- Fraud prevention
- Contract enforcement
- Security
- Backup integrity
29. Backup Copies
Deleted information may remain temporarily in backup systems until those backups are overwritten or rotated.
Backup data is generally not actively used unless restoration is required.
30. Client Requests for Return or Deletion
Where reasonably applicable, clients may request:
- Return of project data
- Deletion of client data
- Removal of system access
- Destruction of credentials
Requests may be subject to:
- Legal retention requirements
- Contractual obligations
- Backup limitations
- Technical feasibility
31. Data Subject Requests
If 1st North Star receives a privacy request relating to personal data processed primarily on behalf of a client, we may refer the request to the client.
Where reasonably required, we may assist the client with:
- Access requests
- Correction requests
- Deletion requests
- Restriction requests
- Data portability requests
Additional work may be billed where permitted by the applicable agreement.
32. Confidentiality After Project Completion
Confidentiality obligations may continue after project completion or termination where appropriate.
Ending a project does not automatically authorize disclosure of confidential information.
33. Exceptions to Confidentiality
Information may not be considered confidential where it:
- Was already publicly available
- Becomes public without breach
- Was lawfully known before disclosure
- Is independently developed
- Is lawfully received from another source
- Is released with authorization
34. Required Disclosure
We may disclose confidential or personal information where required by:
- Law
- Regulation
- Court order
- Government request
- Legal process
Where legally permitted, we may attempt to notify the affected client before disclosure.
35. Security Incidents
A security incident may include:
- Unauthorized access
- Accidental disclosure
- Loss of project data
- Credential compromise
- Malware infection
- Unauthorized data transfer
If we become aware of a significant incident affecting client information, we may investigate and take reasonable remedial steps.
36. Incident Notification
Where required by applicable law or contract, affected clients may be notified of a qualifying data incident.
Notification may include information reasonably available regarding:
- Nature of the incident
- Information affected
- Corrective measures
- Recommended client actions
The timing and content of notification may depend on applicable legal or contractual requirements.
37. Client Notification Duties
Clients should promptly notify us if they become aware of:
- Compromised credentials
- Unauthorized access
- Security incidents affecting shared systems
- Improper disclosure of project information
- Lost devices containing project data
Prompt notification can help reduce potential impact.
38. No Absolute Security Guarantee
While we seek to use reasonable safeguards, no:
- Website
- Server
- Cloud platform
- Email system
- AI tool
- Computer
- Network
can be guaranteed completely secure.
Clients acknowledge the inherent risks of electronic data transmission and storage.
39. Confidentiality of Client Business Information
Client business information should not be intentionally used for unrelated commercial purposes.
For example, we should not use one client’s confidential marketing plan to benefit another client.
General skills, experience, know-how, and non-confidential techniques gained through normal business operations may continue to be used.
40. Trade Secrets
Clients should clearly identify particularly sensitive trade-secret information.
Where appropriate, additional restrictions may be established through:
- NDA
- Restricted access
- Limited personnel assignment
- Specific storage requirements
- Separate contractual terms
41. White-Label and Agency Clients
White-label projects may require enhanced confidentiality.
These may include:
- Non-disclosure of the agency relationship
- Restrictions on portfolio use
- Client non-solicitation
- Restricted communication with end clients
- Confidential branding
- Restricted project disclosure
Document these requirements before work begins.
42. Portfolio and Case Study Restrictions
We will not intentionally publish confidential information in a portfolio or case study.
If client identity or project details are sensitive, we will obtain written permission before publication.
A client may request that a project remain confidential.
43. Employee and Contractor Data
Information relating to workers, applicants, VAs, contractors, or team members may also be treated as confidential where appropriate.
This may include:
- Contact information
- Identification information
- Compensation
- Performance information
- Work records
- Application information
- Internal communications
Limit access to authorized business purposes.
44. Talent Network Information
Applicants to the 1st North Star talent network may provide:
- Resume
- Portfolio
- Work history
- Skills
- Availability
- Contact information
- Compensation expectations
- References
- Work samples
This information may be used for:
- Applicant evaluation
- Talent matching
- Project assignment
- Future opportunities
- Internal records
Applicant information should not be publicly disclosed without authorization.
45. No Sale of Client Confidential Information
1st North Star does not operate a business model based on selling client confidential information or project data to data brokers.
46. Data Ownership
Unless otherwise stated:
- Clients retain ownership of their source data.
- 1st North Star does not claim ownership merely because it processes client data.
- Ownership of deliverables is governed by the applicable Client Service Agreement and intellectual property terms.
47. Data Portability
Where reasonably feasible, client-provided information may be returned in commonly available formats.
Complex migration, export, or conversion work may require a separate fee.
48. Data Accuracy
Clients are responsible for the accuracy of information they provide.
We are not required to independently verify every record unless verification is part of the purchased service.
49. Data Processing for Quality Control
Authorized personnel may review project materials for purposes such as:
- Quality assurance
- Error correction
- Training on internal procedures
- Troubleshooting
- Project management
Do not unnecessarily disclose confidential information during these processes.
50. Internal Training
When we use client work internally for training or quality improvement, we should make reasonable efforts to avoid unnecessary disclosure of confidential client information.
Do not reuse highly sensitive materials for training without appropriate authorization.
51. Internal Documentation
We may maintain internal records concerning:
- Project status
- Instructions
- Deliverables
- Revision history
- Quality issues
- Client communications
These records may be retained for legitimate business purposes.
52. Data Breach Liability
Any liability relating to a data incident will be governed by:
- Applicable law
- Applicable contracts
- Terms of Service
- Client Service Agreement
- Any applicable Data Processing Agreement
Nothing in this Policy is intended to eliminate rights or obligations that cannot lawfully be excluded.
53. Compliance With Client Security Policies
Enterprise or agency clients may request compliance with additional security or confidentiality procedures.
Disclose these requirements before project commencement.
If additional requirements materially increase operational costs, we may require a revised quotation or separate agreement.
54. Audits and Compliance Requests
Certain clients may request information about our data-handling practices.
Where required by contract or law, reasonable cooperation may be provided.
Extensive audits, questionnaires, custom documentation, or compliance work may require additional fees unless otherwise agreed.
55. Changes to This Policy
We may update this Policy to reflect:
- Changes in our services
- Technology changes
- Security practices
- New tools
- AI developments
- Legal or regulatory requirements
The most recent revision date will appear at the top of this page.
56. Contact
Questions about data processing, confidentiality, or client information may be directed to:
1st North Star Consulting
Website:
1stNorthStarConsulting.com
Business Location:
Philippines
Email:
[INSERT BUSINESS EMAIL]
For privacy or data-processing matters, use the subject:
Data Processing / Confidentiality Request
57. Requesting Additional Protections
Clients with particularly sensitive projects should contact us before transferring confidential materials.
Depending on the project, we may establish:
- Nondisclosure Agreement
- Data Processing Agreement
- Restricted AI workflow
- Restricted team access
- Secure file-sharing procedure
- Special credential-handling process
- Additional confidentiality provisions
Your Information Should Be Handled With Purpose
1st North Star Consulting’s managed-services model depends on trust.
Our goal is to give the right team members the information they need to do the work while avoiding unnecessary access, disclosure, or retention.
Share what is necessary. Protect what is sensitive. Manage access responsibly.