Security & data handling
How we handle your systems and data
We only connect to the specific tools and data your automation needs — never broad, unnecessary access. Wherever the platform supports it, we use secure, revocable connections rather than shared passwords, and everything we build runs inside systems you already own and control. You can review what’s connected, and remove our access, at any time. For client-sensitive workflows — particularly in finance — we build with data minimisation in mind from the start, and we’re always happy to talk through exactly what a specific workflow will and won’t touch before we build it.
Our approach to access and data
Data minimisation
We only request access to the specific systems and data fields a workflow needs — never blanket account access.
Secure, revocable access
Wherever a platform supports it, we use scoped credentials and OAuth-based connections instead of shared logins or stored passwords.
You stay in control
You retain ownership and admin control of your own accounts and systems at all times, and can revoke our access whenever you choose.
Full visibility
Workflow logs and execution history stay visible and reviewable inside the platforms you already use — nothing is hidden from you.
Nothing undisclosed
Any third-party tool used in a build is disclosed to you as part of the system documentation, with no undisclosed subprocessors.
Your data stays yours
All client data, workflows and documentation remain your property, retained only within the platforms you already own — we don’t build separate, undisclosed data stores.
Built with your region in mind
United Kingdom
Where genuinely relevant to a specific workflow — such as how client documents are handled — we may reference GDPR and UK GDPR by name. Compliance is always a shared responsibility between our build and your own data-handling practices, so we won’t claim blanket compliance status.
United States
We focus on general data-privacy best practice and, where relevant, the sector-specific frameworks your own compliance function identifies. We don’t claim expertise in US financial regulation itself.
Canada
We build with PIPEDA-aware practice in mind, in general terms, without claiming a formal compliance certification we don’t hold.
Have a specific question about a workflow?
We’re always happy to talk through exactly what a specific workflow will and won’t touch — before we build anything.

Blog