Data Privacy & Security
Protecting client data is treated as a core part of every engagement, not an afterthought.
-
All client data and working files are kept on an encrypted hard drive, separate from other business and personal files.
This drive connects to the internet through my laptop during active engagement work, but data is never backed up to the cloud.
Certain third-party business tools (e.g., email and file sharing platforms, BI/analytics software, project management software) may be used during an engagement to deliver the work. These tools are selected with data handling in mind, and I'm happy to discuss which tools a given engagement will involve.
-
Data is used only for the purposes agreed to in the signed SOW.
A confidentiality/non-disclosure agreement (NDA) is offered as standard practice for every engagement.
-
All project artifacts (working copies of client data, internal documents, and assessment files) are cleaned and/or destroyed within 30 days of project completion.
Written acknowledgment of destruction is provided once complete.
Client-owned deliverables (reports, dashboards, documentation) remain the client's property and are not subject to this destruction policy.
Any case studies written based on the engagement will be discussed with the client first and will be fully anonymized.
Data to Decisions Consulting carries professional liability (errors & omissions) insurance as well as cyber insurance. Coverage details are available upon request.