Data Processing & Confidentiality Policy

How Client Information Is Handled During Service Delivery

Last updated: October 2, 2026

Last Updated: October 2, 2026

1. Purpose

This Data Processing & Confidentiality Policy explains how 1st North Star Consulting (“1st North Star,” “we,” “us,” or “our”) handles personal data, confidential business information, client-provided information, project files, credentials, and other sensitive materials in connection with our services.

This Policy applies to:

  • Clients
  • Prospective clients
  • Agency partners
  • Business partners
  • Contractors
  • Virtual assistants
  • Authorized team members
  • Other individuals whose information may be processed through our services

This Policy should be read together with our:

  • Privacy Policy
  • Terms of Service
  • Client Service Agreement
  • AI Use & Content Responsibility Policy
  • Acceptable Use Policy
  • Any applicable Statement of Work
  • Any applicable Data Processing Agreement
  • Any applicable Nondisclosure Agreement

Where a separate signed agreement contains more specific data-processing or confidentiality terms, that agreement will generally control for the applicable project.


2. Our Role in Processing Information

Depending on the service being provided, 1st North Star Consulting may act in different capacities.

For example, we may process information:

  • For our own business administration
  • To communicate with clients
  • To manage payments and billing
  • To provide support
  • To perform digital services
  • On behalf of a client
  • Through authorized team members
  • Through approved third-party systems

In certain client engagements, the client may determine why and how personal information is processed, while 1st North Star processes that information only as necessary to perform the agreed service.

In those situations, the client may act as the relevant data controller, business, organization, or similar responsible party, while 1st North Star may act as a processor, service provider, contractor, or similar role depending on applicable law.


3. Types of Information We May Process

Depending on the project, we may process:

  • Names
  • Email addresses
  • Telephone numbers
  • Business contact information
  • Customer records
  • CRM records
  • Subscriber lists
  • Lead lists
  • Employee information
  • Website content
  • Marketing data
  • Analytics information
  • Social media information
  • Product information
  • E-commerce information
  • Documents
  • Spreadsheets
  • Images
  • Videos
  • Audio
  • Internal business files
  • Website credentials
  • Platform credentials
  • Project instructions
  • Business procedures
  • Reports
  • Research materials
  • Other information reasonably required to complete the project

4. Confidential Information

Confidential information may include any non-public information disclosed in connection with a project.

Examples may include:

  • Business plans
  • Internal procedures
  • Pricing
  • Customer lists
  • Leads
  • Sales information
  • Financial information
  • Marketing strategies
  • Internal documents
  • Proprietary content
  • Product development information
  • Passwords
  • Login credentials
  • Non-public website information
  • Source files
  • Business processes
  • Trade secrets
  • Client communications
  • Unpublished content
  • Internal reports
  • Technical configurations

Information does not have to be marked “Confidential” to be treated as confidential when its nature reasonably indicates that it should not be publicly disclosed.


5. Our Confidentiality Commitment

We seek to use reasonable organizational and technical measures to protect client confidential information.

Confidential information should generally be:

  • Used only for legitimate project purposes
  • Shared only with authorized personnel
  • Accessed only when reasonably necessary
  • Stored using appropriate systems
  • Protected against unauthorized disclosure

Authorized personnel may include team members, VAs, contractors, or specialists who require access to perform assigned work.


6. Managed Fulfillment and Team Access

1st North Star operates using a managed fulfillment model.

A client contracts with 1st North Star Consulting, while work may be assigned internally to appropriate personnel.

This may include:

  • Virtual assistants
  • Administrative personnel
  • Designers
  • Writers
  • Editors
  • Developers
  • Video specialists
  • Marketing personnel
  • Researchers
  • Project coordinators
  • Quality reviewers
  • Specialized contractors

Not every team member receives access to every client project.

Limit access based on the responsibilities assigned to the individual.


7. Need-to-Know Access

Where practical, we follow a need-to-know approach.

This means team members should receive only the information reasonably necessary to perform their assigned task.

For example:

A graphic designer may not need access to a client’s CRM.

A writer may not need website-administrator credentials.

A video editor may not need access to billing information.

A VA performing data entry may only need the specific spreadsheet required for the task.

This helps reduce unnecessary exposure of client information.


8. Contractor and Team Confidentiality

Where appropriate, authorized personnel may be subject to contractual obligations involving:

  • Confidentiality
  • Data handling
  • Security
  • Non-disclosure
  • Client information
  • Acceptable use
  • Intellectual property
  • Internal procedures

We may also provide operational guidance on properly handling client information.


9. Client Instructions

When processing information primarily on behalf of a client, we may act according to the client’s documented instructions.

These instructions may be contained in:

  • Project brief
  • Statement of Work
  • Email
  • Client Service Agreement
  • Data Processing Agreement
  • Support request
  • Other documented communication

We may request clarification where instructions are incomplete or create potential legal, security, or operational concerns.


10. Client Responsibility for Data

Clients are responsible for ensuring that they have appropriate legal authority to provide data to us.

This is especially important when clients provide:

  • Customer databases
  • Subscriber lists
  • Employee information
  • Prospect lists
  • CRM information
  • Personal information
  • Marketing data
  • Third-party records

Clients should ensure that their collection, processing, and disclosure of such information is lawful and appropriate.


11. Data Minimization

Clients should avoid sending information that is not reasonably necessary for the project.

Where possible, we encourage clients to:

  • Remove unnecessary personal data
  • Redact sensitive information
  • Limit access permissions
  • Use test accounts
  • Use temporary credentials
  • Provide only relevant records

This reduces unnecessary security and privacy risk.


12. Highly Sensitive Information

Clients should not provide highly sensitive information unless it is specifically required for an agreed project and appropriate protections are in place.

Examples may include:

  • Full financial account details
  • Complete credit-card information
  • Government identification numbers
  • Passport numbers
  • Medical records
  • Authentication codes
  • Private encryption keys
  • Biometric information
  • Highly sensitive employment records

If a project requires sensitive data, additional contractual or security arrangements may be necessary.


13. Credentials and Passwords

When clients need account access, they should use secure access practices whenever possible.

Recommended approaches include:

  • Creating a separate project account
  • Providing limited user permissions
  • Using temporary credentials
  • Using password-management tools
  • Revoking access after completion
  • Enabling multi-factor authentication where appropriate

Clients should avoid sharing primary administrative passwords where a limited-access account can be created.


14. Credential Storage

Where credentials must be retained temporarily, clients should use reasonable care to restrict access.

Credentials should not be unnecessarily copied, distributed, or retained longer than required.

Clients are encouraged to change or revoke passwords after project completion.


15. Personal Data Processing

When we process personal information on behalf of a client, we may process it only as reasonably necessary to:

  • Perform the service
  • Complete project instructions
  • Provide support
  • Troubleshoot issues
  • Maintain security
  • Meet legal obligations

We do not acquire independent ownership of client personal data merely because we process it.


16. Data Processing Agreements

Certain clients may require a formal Data Processing Agreement, or DPA.

A DPA may be appropriate when:

  • Personal data is processed regularly
  • The client operates in a regulated jurisdiction
  • EU or UK personal data is involved
  • The client requires specific processor obligations
  • Sensitive business data is involved
  • Contractual privacy requirements apply

The DPA may address:

  • Processing instructions
  • Security
  • Subprocessors
  • Data transfers
  • Retention
  • Deletion
  • Data subject requests
  • Incident notification
  • Audit obligations

17. Third-Party Service Providers

We may use third-party platforms to perform services.

These may include providers of:

  • Hosting
  • Cloud storage
  • Email
  • File sharing
  • Project management
  • CRM
  • Automation
  • Communication
  • Accounting
  • Payment processing
  • Artificial intelligence
  • Graphic design
  • Video production
  • Website tools
  • Analytics
  • Backup
  • Security

These providers may process information according to their own terms, privacy policies, and security practices.


18. Subprocessors and Service Providers

Where 1st North Star acts as a processor on behalf of a client, certain third-party providers or contractors may function as subprocessors.

Examples may include:

  • Cloud providers
  • Hosting providers
  • Software platforms
  • Contractors
  • Specialized production vendors
  • AI providers

Where required by contract or law, additional subprocessor terms may apply.


19. Artificial Intelligence and Data Processing

We may use AI-assisted tools where appropriate for certain projects.

Possible uses include:

  • Drafting
  • Editing
  • Summarization
  • Research assistance
  • Coding
  • Graphic generation
  • Video production
  • Transcription
  • Data organization
  • Automation

Clients should notify us before project commencement if specific information must not be processed using third-party AI systems.


20. Confidential Information and AI

Do not automatically submit confidential or sensitive information to external AI systems.

Where a project contains sensitive information, we may:

  • Exclude the information from AI workflows
  • Redact identifying information
  • Use a different production process
  • Ask the client for approval
  • Use an approved AI environment

If a client’s AI restrictions significantly change the project requirements, additional fees or revised project terms may apply.


21. International Data Processing

1st North Star Consulting operates from the Philippines and serves international clients.

As a result, information may be processed in:

  • The Philippines
  • The client’s country
  • Countries where our service providers operate
  • Cloud infrastructure located internationally

Clients acknowledge that cross-border processing may occur where necessary to perform the service.


22. International Data Transfers

Where applicable, international transfers may be supported by:

  • Contractual safeguards
  • Service-provider agreements
  • Data Processing Agreements
  • Standard contractual mechanisms
  • Other legally recognized measures

The specific mechanism may vary according to jurisdiction and project requirements.


23. Security Measures

We may use reasonable technical and organizational measures appropriate to the nature of the service.

These may include:

  • Password protection
  • Access controls
  • Secure hosting
  • Encryption where available
  • Multi-factor authentication
  • Role-based permissions
  • Security updates
  • Backup procedures
  • Anti-malware tools
  • Secure file sharing
  • Restricted administrative access
  • Internal confidentiality procedures

No security method can guarantee complete protection.


24. Client Security Responsibilities

Clients also have responsibilities for protecting their systems.

Clients should:

  • Use strong passwords
  • Enable multi-factor authentication where appropriate
  • Limit administrator accounts
  • Maintain backups
  • Install security updates
  • Remove former-user access
  • Monitor unusual activity
  • Revoke temporary credentials after project completion

25. File Sharing

Project files may be exchanged using:

  • Email
  • Cloud storage
  • Shared drives
  • Secure transfer systems
  • Project-management platforms
  • Client portals

The appropriate method may depend on the sensitivity and size of the information.


26. Project Files and Working Copies

During production, copies of files may exist in:

  • Local work environments
  • Cloud storage
  • Email
  • Temporary folders
  • Collaboration platforms
  • Backup systems

Reasonable efforts may be made to reduce unnecessary copies after the project is completed.


27. Data Retention

Information may be retained for as long as reasonably necessary to:

  • Perform services
  • Provide support
  • Maintain client records
  • Maintain financial records
  • Resolve disputes
  • Defend legal claims
  • Comply with legal requirements
  • Maintain backups
  • Support legitimate business operations

Retention periods may differ depending on the type of information.


28. Project Completion and Data Deletion

After a project is completed, client information may remain temporarily in:

  • Project systems
  • Email
  • Cloud storage
  • Backups
  • Administrative records

Clients may request deletion of eligible information.

Some information may need to be retained for:

  • Legal obligations
  • Tax records
  • Accounting
  • Fraud prevention
  • Contract enforcement
  • Security
  • Backup integrity

29. Backup Copies

Deleted information may remain temporarily in backup systems until those backups are overwritten or rotated.

Backup data is generally not actively used unless restoration is required.


30. Client Requests for Return or Deletion

Where reasonably applicable, clients may request:

  • Return of project data
  • Deletion of client data
  • Removal of system access
  • Destruction of credentials

Requests may be subject to:

  • Legal retention requirements
  • Contractual obligations
  • Backup limitations
  • Technical feasibility

31. Data Subject Requests

If 1st North Star receives a privacy request relating to personal data processed primarily on behalf of a client, we may refer the request to the client.

Where reasonably required, we may assist the client with:

  • Access requests
  • Correction requests
  • Deletion requests
  • Restriction requests
  • Data portability requests

Additional work may be billed where permitted by the applicable agreement.


32. Confidentiality After Project Completion

Confidentiality obligations may continue after project completion or termination where appropriate.

Ending a project does not automatically authorize disclosure of confidential information.


33. Exceptions to Confidentiality

Information may not be considered confidential where it:

  • Was already publicly available
  • Becomes public without breach
  • Was lawfully known before disclosure
  • Is independently developed
  • Is lawfully received from another source
  • Is released with authorization

34. Required Disclosure

We may disclose confidential or personal information where required by:

  • Law
  • Regulation
  • Court order
  • Government request
  • Legal process

Where legally permitted, we may attempt to notify the affected client before disclosure.


35. Security Incidents

A security incident may include:

  • Unauthorized access
  • Accidental disclosure
  • Loss of project data
  • Credential compromise
  • Malware infection
  • Unauthorized data transfer

If we become aware of a significant incident affecting client information, we may investigate and take reasonable remedial steps.


36. Incident Notification

Where required by applicable law or contract, affected clients may be notified of a qualifying data incident.

Notification may include information reasonably available regarding:

  • Nature of the incident
  • Information affected
  • Corrective measures
  • Recommended client actions

The timing and content of notification may depend on applicable legal or contractual requirements.


37. Client Notification Duties

Clients should promptly notify us if they become aware of:

  • Compromised credentials
  • Unauthorized access
  • Security incidents affecting shared systems
  • Improper disclosure of project information
  • Lost devices containing project data

Prompt notification can help reduce potential impact.


38. No Absolute Security Guarantee

While we seek to use reasonable safeguards, no:

  • Website
  • Server
  • Cloud platform
  • Email system
  • AI tool
  • Computer
  • Network

can be guaranteed completely secure.

Clients acknowledge the inherent risks of electronic data transmission and storage.


39. Confidentiality of Client Business Information

Client business information should not be intentionally used for unrelated commercial purposes.

For example, we should not use one client’s confidential marketing plan to benefit another client.

General skills, experience, know-how, and non-confidential techniques gained through normal business operations may continue to be used.


40. Trade Secrets

Clients should clearly identify particularly sensitive trade-secret information.

Where appropriate, additional restrictions may be established through:

  • NDA
  • Restricted access
  • Limited personnel assignment
  • Specific storage requirements
  • Separate contractual terms

41. White-Label and Agency Clients

White-label projects may require enhanced confidentiality.

These may include:

  • Non-disclosure of the agency relationship
  • Restrictions on portfolio use
  • Client non-solicitation
  • Restricted communication with end clients
  • Confidential branding
  • Restricted project disclosure

Document these requirements before work begins.


42. Portfolio and Case Study Restrictions

We will not intentionally publish confidential information in a portfolio or case study.

If client identity or project details are sensitive, we will obtain written permission before publication.

A client may request that a project remain confidential.


43. Employee and Contractor Data

Information relating to workers, applicants, VAs, contractors, or team members may also be treated as confidential where appropriate.

This may include:

  • Contact information
  • Identification information
  • Compensation
  • Performance information
  • Work records
  • Application information
  • Internal communications

Limit access to authorized business purposes.


44. Talent Network Information

Applicants to the 1st North Star talent network may provide:

  • Resume
  • Portfolio
  • Work history
  • Skills
  • Availability
  • Contact information
  • Compensation expectations
  • References
  • Work samples

This information may be used for:

  • Applicant evaluation
  • Talent matching
  • Project assignment
  • Future opportunities
  • Internal records

Applicant information should not be publicly disclosed without authorization.


45. No Sale of Client Confidential Information

1st North Star does not operate a business model based on selling client confidential information or project data to data brokers.


46. Data Ownership

Unless otherwise stated:

  • Clients retain ownership of their source data.
  • 1st North Star does not claim ownership merely because it processes client data.
  • Ownership of deliverables is governed by the applicable Client Service Agreement and intellectual property terms.

47. Data Portability

Where reasonably feasible, client-provided information may be returned in commonly available formats.

Complex migration, export, or conversion work may require a separate fee.


48. Data Accuracy

Clients are responsible for the accuracy of information they provide.

We are not required to independently verify every record unless verification is part of the purchased service.


49. Data Processing for Quality Control

Authorized personnel may review project materials for purposes such as:

  • Quality assurance
  • Error correction
  • Training on internal procedures
  • Troubleshooting
  • Project management

Do not unnecessarily disclose confidential information during these processes.


50. Internal Training

When we use client work internally for training or quality improvement, we should make reasonable efforts to avoid unnecessary disclosure of confidential client information.

Do not reuse highly sensitive materials for training without appropriate authorization.


51. Internal Documentation

We may maintain internal records concerning:

  • Project status
  • Instructions
  • Deliverables
  • Revision history
  • Quality issues
  • Client communications

These records may be retained for legitimate business purposes.


52. Data Breach Liability

Any liability relating to a data incident will be governed by:

  • Applicable law
  • Applicable contracts
  • Terms of Service
  • Client Service Agreement
  • Any applicable Data Processing Agreement

Nothing in this Policy is intended to eliminate rights or obligations that cannot lawfully be excluded.


53. Compliance With Client Security Policies

Enterprise or agency clients may request compliance with additional security or confidentiality procedures.

Disclose these requirements before project commencement.

If additional requirements materially increase operational costs, we may require a revised quotation or separate agreement.


54. Audits and Compliance Requests

Certain clients may request information about our data-handling practices.

Where required by contract or law, reasonable cooperation may be provided.

Extensive audits, questionnaires, custom documentation, or compliance work may require additional fees unless otherwise agreed.


55. Changes to This Policy

We may update this Policy to reflect:

  • Changes in our services
  • Technology changes
  • Security practices
  • New tools
  • AI developments
  • Legal or regulatory requirements

The most recent revision date will appear at the top of this page.


56. Contact

Questions about data processing, confidentiality, or client information may be directed to:

1st North Star Consulting

Website:
1stNorthStarConsulting.com

Business Location:
Philippines

Email:
[INSERT BUSINESS EMAIL]

For privacy or data-processing matters, use the subject:

Data Processing / Confidentiality Request


57. Requesting Additional Protections

Clients with particularly sensitive projects should contact us before transferring confidential materials.

Depending on the project, we may establish:

  • Nondisclosure Agreement
  • Data Processing Agreement
  • Restricted AI workflow
  • Restricted team access
  • Secure file-sharing procedure
  • Special credential-handling process
  • Additional confidentiality provisions

Your Information Should Be Handled With Purpose

1st North Star Consulting’s managed-services model depends on trust.

Our goal is to give the right team members the information they need to do the work while avoiding unnecessary access, disclosure, or retention.

Share what is necessary. Protect what is sensitive. Manage access responsibly.

1stnorthstarconsulting@inbox360.email

This page is provided for general information. Questions about it? Contact us and we will be glad to clarify.