Hamblett-Coding

Privacy & Security

This page explains how we handle your data, credentials, and API keys when we build AI systems, automation, n8n workflows, and bespoke web applications. We aim to be transparent, practical, and secure-by-default.

Last updated: 28 August 2026

Security-first Least privilege Client-owned access
At a glance
API keys
Never shared publicly; stored only as needed
Credentials
Prefer client-managed vaults & access controls
Data retention
Minimum required; client-defined
Access
Role-based; logged where possible

What we collect

We collect the minimum information required to deliver your project and support it safely.

  • Contact details you submit via our forms
  • Project requirements and technical notes
  • System metadata needed for troubleshooting (where agreed)

What we do not do

We do not sell your data or use it to train public models.

  • No selling or renting client data
  • No publishing credentials or secrets
  • No using your content for marketing without permission

Where data is processed

Data may be processed in systems you control (preferred) or secure environments we manage, depending on the engagement.

  • Client tenants (Microsoft 365, Google, etc.)
  • Client automation platforms (n8n, Make, etc.)
  • Our controlled environments for development & testing (where agreed)

API keys & credentials

Many projects require third-party credentials (Microsoft Graph, Google APIs, Brevo, Stripe, OpenAI, webhooks, database credentials, etc.). We treat secrets as high-risk assets and aim to reduce exposure and lifetime.

✅ Prefer client-managed credential stores (e.g., platform vaults, secrets managers, environment variables)
✅ Least-privilege scopes and time-limited keys where supported
✅ Separation of development/test vs production credentials
✅ Rotation support and emergency revocation guidance
Typical credential handling
Client creates key Stored in vault / env Used by workflow Audited/rotated
Where possible, you keep ownership. We only access what we need, for as long as needed.

Data security measures

Security is applied in layers — access, encryption, monitoring, and operational processes.

01
Access control
Role-based access, least privilege, and separation of duties where practical. We avoid shared credentials and prefer named access.
02
Encryption
HTTPS/TLS for data in transit. For data at rest, we rely on platform encryption and can implement additional encryption where required.
03
Logging & audit
Where supported, we enable logs and audit trails for key actions (automation runs, webhooks, admin actions) to aid incident response.
04
Data minimisation
We collect and store the smallest amount of data needed. Sensitive fields can be redacted, tokenised, or excluded.
05
Retention & deletion
Retention is defined by the engagement. On request, we will delete project data we control, subject to legal/contractual requirements.
06
Incident response
If we suspect a security incident impacting your project, we act quickly: contain, assess impact, notify, and remediate.

Automation, AI & third-party services

Some solutions involve third-party platforms (e.g., n8n, Microsoft 365, Google Workspace, Brevo, hosting providers, analytics). Each provider may process data under their own terms. We will help you choose sensible configurations and minimise data exposure.

AI systems (LLMs / agents)

If an AI feature is used, we aim to control what data is sent and when.

  • Prefer sending only the fields required for the task
  • Support redaction/anonymisation workflows
  • Keep prompts and outputs within client-controlled storage where possible

Webhooks & integrations

Webhooks can expose endpoints if misconfigured. We secure them by default.

  • Signed requests / shared secrets where supported
  • IP allowlisting (when appropriate)
  • Rate limiting and input validation

Your responsibilities

Security is shared. The safest solutions combine our implementation with your internal policies and controls.

Provide secure access

Use named accounts where possible, with MFA enabled and scoped permissions.

Rotate credentials

Rotate API keys and secrets periodically, and immediately if a device/account is compromised.

Review permissions

Approve scopes for apps/integrations and remove access when no longer required.

Contact & requests

If you have questions about privacy, security, or data handling for your project, contact us and we’ll respond with clear answers. If you want a formal DPA or additional controls (e.g., IP allowlists, dedicated environments, retention policies), we can scope that.

Email: [email protected]