Skip to main content
Navigation

SECURITY

Security and information handling

How we scope information handling for AI advisory, foundations, and development, and what to confirm before engagement.

Start with only the information needed

An initial consultation can begin with an overview of your business and challenges. You do not need to send customer or employee personal data, credentials, or confidential documents through the contact form. When specific information becomes necessary, we confirm how to share and handle it.

AI advisory focuses on keeping up with developments, discussing business decisions, and setting a direction for AI use. If the work moves into foundations or development, we define the data and systems involved for that engagement.

Define information-handling responsibilities

When you entrust personal information to us, we confirm the purpose, scope of instructions, authorized people, storage, and return or deletion at the end of the contract. We clarify your supervision of entrusted processing and our protective measures according to the actual work involved.

Information we collect for inquiries and our own contracts is handled under our privacy policy. Responsibility for all information is not transferred wholesale to the client.

Review what external AI services receive

When using an external AI service, we review the provider, information sent, retention and training-use terms and settings, and access permissions. Business-data transfers are designed within the scope agreed with you. We do not make a blanket guarantee that every AI service retains no data or never uses it for training.

Depending on the purpose, we consider sample or de-identified data for evaluation, limiting the fields sent, and human checks. We also design where AI output is reviewed and how errors are handled as part of the workflow.

Agree on operation and handover

Before development or rollout, we confirm account ownership, necessary permissions, credential-sharing methods, logs and backups, and maintenance responsibilities and scope. If subcontracted work requires access to your information, we explain the provider, scope, and handling in advance and obtain the necessary agreement.

Incident contacts, initial response responsibilities, and the scope of investigation and recovery are agreed individually. Where legal reporting or notification duties apply, we respond accordingly. Tell us before engagement if you require guarantees for availability, response times, or recovery times.

Information handled by this website

Contact submissions reach us through Resend and are handled in our Google Workspace business mailbox. Our existing free-guide operations separately include a registration database, Google Sheets synchronization, guide access, and unsubscribe handling.

We do not send names, email addresses, survey responses, access tokens, or LINE user IDs to Umami analytics. See the privacy policy for details, including cookies and external services.

Requirements for your internal review

This page is not evidence of certification or a completed security audit of an individual system. If your process requires ISMS or PrivacyMark certification, a SOC 2 report, a specific storage region, a non-disclosure agreement, or a security questionnaire, tell us in advance. We check the requirements and what we can provide before proposing an engagement.

Fees, scope, deliverables, acceptance, ownership of rights, and maintenance and operations are also addressed in the individual proposal and contract.