Privacy & Security
This page explains how we handle your data, credentials, and API keys when we build AI systems, automation, n8n workflows, and bespoke web applications. We aim to be transparent, practical, and secure-by-default.
Last updated: 28 August 2026
What we collect
We collect the minimum information required to deliver your project and support it safely.
- Contact details you submit via our forms
- Project requirements and technical notes
- System metadata needed for troubleshooting (where agreed)
What we do not do
We do not sell your data or use it to train public models.
- No selling or renting client data
- No publishing credentials or secrets
- No using your content for marketing without permission
Where data is processed
Data may be processed in systems you control (preferred) or secure environments we manage, depending on the engagement.
- Client tenants (Microsoft 365, Google, etc.)
- Client automation platforms (n8n, Make, etc.)
- Our controlled environments for development & testing (where agreed)
API keys & credentials
Many projects require third-party credentials (Microsoft Graph, Google APIs, Brevo, Stripe, OpenAI, webhooks, database credentials, etc.). We treat secrets as high-risk assets and aim to reduce exposure and lifetime.
Data security measures
Security is applied in layers — access, encryption, monitoring, and operational processes.
Automation, AI & third-party services
Some solutions involve third-party platforms (e.g., n8n, Microsoft 365, Google Workspace, Brevo, hosting providers, analytics). Each provider may process data under their own terms. We will help you choose sensible configurations and minimise data exposure.
AI systems (LLMs / agents)
If an AI feature is used, we aim to control what data is sent and when.
- Prefer sending only the fields required for the task
- Support redaction/anonymisation workflows
- Keep prompts and outputs within client-controlled storage where possible
Webhooks & integrations
Webhooks can expose endpoints if misconfigured. We secure them by default.
- Signed requests / shared secrets where supported
- IP allowlisting (when appropriate)
- Rate limiting and input validation
Your responsibilities
Security is shared. The safest solutions combine our implementation with your internal policies and controls.
Provide secure access
Use named accounts where possible, with MFA enabled and scoped permissions.
Rotate credentials
Rotate API keys and secrets periodically, and immediately if a device/account is compromised.
Review permissions
Approve scopes for apps/integrations and remove access when no longer required.
Contact & requests
If you have questions about privacy, security, or data handling for your project, contact us and we’ll respond with clear answers. If you want a formal DPA or additional controls (e.g., IP allowlists, dedicated environments, retention policies), we can scope that.
Email: [email protected]