All client data is stored exclusively within Microsoft 365 Business Standard, protected by ISO 27001, ISO 27018, SOC 2, GDPR compliance, and UK/EU data residency.
Laptops are fully encrypted using BitLocker, and all access is protected by multi‑factor authentication.
No client data is stored on personal devices or external systems. All dashboards, reports, and documents are delivered through a secure SharePoint client portal with named‑user access only.
-
Your data is protected by a combination of:
Microsoft’s enterprise‑grade cloud security
UK GDPR compliance
Strong device security
Clear governance and deletion processes
A secure SharePoint client portal
Controlled Power BI access
Multi‑factor authentication (MFA)
Encryption at rest and in transit
All client data stays inside Microsoft 365 Business Standard, which is certified to ISO 27001, ISO 27018, SOC 2, and fully compliant with UK GDPR.
-
All client data is stored exclusively within:
SharePoint Online
OneDrive for Business
Power BI Service
Exchange Online (via password protected email communication)
No data is stored on personal cloud services, USB drives, or unmanaged devices.
All storage locations are encrypted, access‑controlled, and protected by MFA.
-
Key certifications include:
ISO 27001 — Information Security Management
ISO 27018 — Protection of Personal Data in the Cloud
SOC 1 / SOC 2 — Security, Availability, Confidentiality
GDPR compliance
UK Data Protection Act compliance
EU Model Clauses
Encryption at rest and in transit
Zero Trust architecture
These certifications are publicly available and widely trusted across charities, councils, NHS Trusts, and education organisations.tem description
-
BitLocker full‑disk encryption (AES‑256)
Multi‑factor authentication
Automatic security updates
Strong password policy
Separate business and personal identities
No client data stored locally outside OneDrive Business
-
Each client receives a private SharePoint site with:
Granular permissions
Named‑user access only
MFA enforced
UK/EU data residency
Audit logs
Version history
Secure upload area
No anonymous access
No cross‑client visibility description
-
Dashboards are hosted securely using:
Power BI Service (not “Publish to Web”)
Workspace permissions (Viewer role for clients)
Row‑Level Security (RLS) where needed
MFA enforced
UK/EU data residency
Encrypted data at rest and in transit
No dashboards are ever made public.
-
Access is granted on a named‑user basis only.
Roles:
Site Owner — You
Members — Named client staff (edit access)
Visitors — Wider client team (read‑only)
Principles:
Least privilege
No shared accounts
MFA required
No anonymous links
No external sharing unless approved
-
We process data only for:
Reporting
Dashboard development
Governance reviews
Accessibility/EDI audits
Operational improvement
We do not process special category data unless explicitly agreed.
All processing is covered by ourData Processing Agreement.
-
Unless otherwise agreed:
Project files: retained for 12–24 months
Raw data: deleted after project completion
Governance documents: retained for up to 24 months
Accessibility/EDI survey data: retained for 12 months
Clients may request deletion at any time
Deletion is carried out across:
SharePoint
OneDrive Business
Power BI Service
Exchange Online
-
If a personal data breach occurs, we will:
Notify the client without undue delay
Provide details of the breach
Describe mitigation steps
Support the client in fulfilling any ICO obligations
Document the incident and actions taken
This aligns with UK GDPR requirements.
-
This website collects personal information to power our site analytics, including:
Information about your browser, network, and device
Web pages you visited prior to coming to this website
Your IP address
This information may also include details about your use of this website, including:
Clicks
Internal links
Pages visited
Scrolling
Searches
Timestamps
We provide this information to Squarespace, our website analytics provider, to learn about site traffic and activity.