Our commitment
Data protection is core to what we do. We apply the same rigor to our own handling of data that we bring to client engagements, with security and minimization as defaults.
How we process data
We process personal data lawfully and for clearly defined purposes, limited to what is necessary. Where we act as a processor on behalf of clients, processing is governed by the relevant engagement agreement.
Security measures
We protect data with encryption in transit and at rest, access controls on a least-privilege basis, and post-quantum-aware practices consistent with the guidance we give clients.
Retention
We retain personal data only as long as needed for the purposes described or as required by law, after which it is deleted or anonymized.
Subprocessors
Where we rely on third-party service providers, we hold them to appropriate confidentiality and data-protection obligations.
Contact
Data-protection questions can be sent to hello@spooqy.io.