Draft — requires legal review and sign-off before publication. Not legal advice.
Security & Data Protection
Last updated 3 August 2026
Tenant isolation
Every organisation on the platform is fully isolated, with its own data, users, branding and configuration. Isolation is enforced at the data-access layer, not by interface filtering.
Access control
Access is governed by granular role-based permissions with a roles editor and invitation flow. Last-owner protection prevents an organisation from being locked out of its own workspace.
Encryption
Personally identifiable information in contact records is encrypted at rest. All traffic to the platform is served over TLS.
Audit logging
Every significant administrative action is recorded with the acting user and timestamp, supporting governance and compliance review.
Sub-processors and data location
The sub-processor list, hosting region and data residency position must be stated here before publication.
Vulnerability reporting
The disclosure address and response commitment must be stated here before publication.
Data Processing Agreement
A DPA is available on request. The standard DPA text, or a link to it, must be inserted here before publication.