privacy data use · Privacy Policy
Balance policy finding
“ Keeping your data secure is important to us. We take the following steps to protect your personal data in line with good practice and GDPR requirements: Step 1: Encrypt everything. All data is encrypted both in transit (TLS) and at rest. Third-party integration credentials are stored using Fernet/AES-128 symmetric encryption. Secrets and API keys are managed through a SOC 2 certified secrets manager. Step 2: Control access. Multi-factor authentication (MFA) is enforced on all infrastructure and administrative accounts. We use role-based access controls with the principle of least privilege, so only employees who need access to your data to do their job have it. Step 3: Isolate your data. Each customer’s data is logically separated. Our customers cannot access each other’s data. User identity is managed through Firebase Authentication. Step 4: Minimise what we keep. AI processing logs are automatically deleted on a rolling basis. When a customer’s contract ends, all their data is deleted within 90 days (except where we are legally required to retain financial records). Step 5: Monitor and improve. We regularly assess our security measures and update them as needed. We have a documented data breach response procedure with clear escalation steps.”
- Document
- Privacy Policy
- Captured
- 2026-07-19
- Location
- Privacy Policy › “Your Rights”
- Snapshot SHA-256
- 5c0f1b94f895bc2cbecaef3ddff0ce93d48ae37030758b90f8856f604fb0d378
Informational only, not legal advice. Terms change; verify the source and capture date.