Purpose
Clients may provide business information, account access, customer data, documents, content, or other confidential material so that we can perform requested services. This policy describes our general handling approach.
Need-to-Know Access
Access should be limited to personnel and service providers who reasonably need the information to perform assigned work or support the business relationship.
Confidentiality Expectations
Team members and contractors may be subject to confidentiality obligations appropriate to their role. Additional NDAs or data-processing terms may be used for projects with heightened confidentiality requirements.
Client Credentials
Passwords and authentication information should be shared through approved secure methods. Clients should avoid sending sensitive credentials through ordinary email or unsecured forms. Where feasible, create role-based or temporary accounts instead of sharing primary administrator credentials.
Data Minimization
Clients should provide only the information reasonably necessary for the task. Highly sensitive data should not be supplied unless the project specifically requires it and safeguards have been agreed.
Third-Party Tools
Service delivery may require cloud storage, email platforms, project-management systems, AI tools, hosting providers, design platforms, analytics, or other software vendors. Their terms and privacy practices also apply.
Incident Response
If we become aware of a material security incident involving client data under our control, we will take reasonable steps to investigate, contain, and notify affected parties where required by applicable law or contract.
Custom Data Processing Agreements
Clients with regulatory or enterprise requirements may request a separate DPA for review. Acceptance depends on the requested obligations, service scope, and technical capabilities.