How we protect your data
Four commitments we hold to on every engagement.
Data handling, in practice
Before any data changes hands, we agree the scope, the legal basis, the retention period and the security controls in writing. Data is transferred over encrypted channels and held only in controlled environments for the agreed purpose.
Access and confidentiality
Access is restricted to the specific team members delivering your engagement, under confidentiality obligations. We do not use one client's data to benefit another, and we do not publish client-identifying results.
Retention and deletion
Data is retained only for as long as the engagement requires or as agreed with you, and is securely deleted or returned at the end of the retention period. We are glad to align retention with your own data-protection obligations.
Working within your framework
Our clients operate under a range of regulatory and data-protection regimes across Europe and the Middle East. We work within your governance requirements and are happy to complete your security and vendor due-diligence processes.
For how we handle personal data on this website, see our Privacy Policy.