Confidentiality & Non-Disclosure
Confidentiality Is the Architectural Principle of Every Engagement
Our protocols are not marketing language. They are the operational and legal framework within which every engagement is conducted, from initial enquiry through to secure deletion of all client data on completion.
Mutual Non-Disclosure Agreement
We execute a mutual non-disclosure agreement before any personal information is exchanged. It is a bilateral agreement imposing obligations on both parties, not a standard terms document.
The NDA covers the scope of confidential information, permitted use, duration and remedies for breach. Clients may have it reviewed by their own legal advisors before execution.
It is available for digital signature and can typically be executed within 24 hours. There is no additional cost. It is available to all prospective clients regardless of whether they proceed with the review.
Digital Signature and Legal Validity
All engagement documents, including the NDA, are available for execution through a secure digital signature platform. Digital signatures have the same legal standing as handwritten signatures under the Electronic Communications Act 2000 (UK), the ESIGN Act and UETA (US) and the eIDAS Regulation (EU).
The signing process requires no software installation. A secure link is provided, the document can be reviewed in full, and execution takes a matter of minutes. A countersigned copy is retained by both parties upon completion.
Secure Data Handling & No AI Training
All client data is encrypted in transit (TLS 1.3) and at rest (AES-256). These are operational baselines, not aspirational standards.
Client data is never used for AI model training, pattern matching or any secondary purpose. It is processed solely within the scope of the engagement.
Access is restricted to personnel directly involved in the engagement. We maintain strict access controls, audit trails and separation of duties. Data is not stored on local devices or cloud services that do not meet our security requirements.
No Third-Party Disclosure
Client data is never sold, shared, licensed or disclosed to any third party. This is an absolute commitment, not subject to commercial qualification.
We do not aggregate client data for analytics, modelling or any secondary purpose. Data is used solely to conduct the engagement for which it was provided.
Where third-party providers are engaged (hosting, digital signatures), they are subject to contractual obligations requiring processing only in accordance with our instructions and under equivalent security standards. A list of processors is available on request.
Limited Internal Access
Access is limited to personnel directly responsible for conducting the review. Administrative and commercial staff have no access to client data at any stage.
All personnel with access are bound by confidentiality obligations that survive the termination of their involvement.
Secure Deletion on Completion
All client data is securely deleted within thirty (30) days of report delivery, including intake information, search records, intermediate findings and all associated metadata. Written confirmation is available on request.
The only exception is where retention is required by law, in which case the minimum required data is held for the minimum required period under the same security controls.
Jurisdictional Compliance
Our data handling complies with UK GDPR, EU GDPR and applicable US state privacy legislation.
Clients may exercise rights of access, rectification, erasure and portability at any time through the secure enquiry form. We respond within legally required timeframes.
Where data transfers cross jurisdictions, appropriate safeguards apply, including Standard Contractual Clauses where required.
Request a Non-Disclosure Agreement
To request NDA execution before sharing any personal information, submit an enquiry and indicate that you wish to proceed with NDA execution as the first step.
Request NDA