Security, NDAs and how we handle your data
Handing account access and customer data to a supplier in another jurisdiction is the part that makes legal and IT teams nervous, and reasonably so. This is our posture, written down, so you can send it to them instead of relaying it.
Contracts
Signed before discovery, not before kickoff. You should not have to describe your business to evaluate whether to work with us.
We act as processor, you remain controller. Standard Contractual Clauses are available where transfer to India needs them for UK or EU data.
Every deliverable β code, copy, creative, campaign structure, documentation β is yours on payment. We retain no licence and no portfolio right you have not agreed to.
For white-label work, a standing covenant on any client you introduce, for the term plus 24 months. Your client list is not a prospect list.
Access and systems
We ask for the narrowest access that lets the work happen β delegated Google Ads access rather than account ownership, editor rather than admin, scoped rather than global.
We are comfortable working entirely inside your Slack, your project tool, your drive and your password manager. Client data does not move to systems you have not approved.
Every person has their own credential so access is attributable. Shared logins make an audit trail impossible.
When someone rolls off your account, access is revoked the same day and you get written confirmation of what was removed.
Practice
Enforced on every platform account, no exceptions and no opt-out.
No credentials in email, chat, spreadsheets or documents.
Disk encryption and screen lock enforced on every machine that touches client work.
Verification on everyone with production access, before access is granted.
What we are not going to overstate
We are not currently ISO 27001 or SOC 2 certified. Plenty of suppliers imply certification they do not hold, and you will find out at procurement rather than at pitch β so we would rather tell you now.
What we do have is the practice above, a willingness to complete your security questionnaire in full, and an openness to any control your policy requires. If formal certification is a hard procurement gate for you, tell us early and we will be straight about whether we can meet your timeline.
Common questions
Will you sign our NDA and DPA rather than yours?
Yes. We are happy to work from your paper. If your template has a clause we cannot meet we will say which one and why, rather than signing and hoping.
Is transferring data to India GDPR-compliant?
It requires an appropriate transfer mechanism. We execute Standard Contractual Clauses alongside the DPA, and where you would rather data never left your jurisdiction we work inside your systems instead of copying data to ours.
Who owns the work?
You do, in full, on payment β including source files, code repositories and campaign structures. Nothing is held back as leverage.