Mumford Advisory

How we handle your data

An assessment cannot be completed on anecdote alone, so we ask for operational evidence. Support data can contain information about a client's customers and team. This page explains what we request, why we request it, how it is protected and when it is deleted.

This page supplements our privacy policy and the confidentiality and data-handling terms agreed for each engagement.

What we request

The standard request is ticket metadata, not ticket conversations. We ask for message content only where metadata genuinely cannot answer the question, and we agree the scope with you first.

Information Why it is needed How it is minimised
Ticket metadata covering up to 12 months Measures volume, demand drivers, handling time, reassignment, repeat contacts and reopen activity Message bodies, customer names and email addresses are not requested by default
Limited conversation samples, only where necessary Provides context that cannot be established from metadata alone Scope and purpose agreed with you in advance; content reduced or de-identified where reasonably possible
Support-tool list, licence counts and annual costs Identifies overlapping capability, inactive seats and unnecessary spend Normally contains little or no personal information
Documentation, macros and knowledge-base material Evaluates coverage, currency, discoverability and undocumented knowledge Personal information removed where unnecessary
Team roles, staffing levels and loaded cost bands Converts operational waste into financial impact Cost bands and role counts preferred over individual salaries and named rosters
Leadership and team interviews Explains the context behind the operational data Participation and scope agreed with you

Please do not provide passwords, authentication tokens, payment-card information, government identification numbers, health information or other highly sensitive information. Where these appear incidentally in operational records, they should be removed before transfer wherever reasonably possible.

How we keep the request small

  • Metadata first. Content only when metadata cannot answer the question.
  • Aggregate wherever possible. Totals and distributions rather than records.
  • Role counts instead of names.
  • Cost bands instead of individual compensation.
  • Client-managed, read-only, time-limited access where your tooling supports it.
  • Limited samples rather than complete message archives.
  • More is requested only when we can explain why it is necessary.

Your responsibility

You are responsible for confirming that you have the authority to provide the information used in the assessment, and that its collection and disclosure comply with applicable law, contractual obligations and your internal policies. Our minimisation requirements do not replace your own privacy and security obligations.

Confidentiality

We will enter into a reasonable confidentiality agreement before client operational data is transferred. We can review and, where appropriate, work under a client-provided NDA.

Your data remains your data. We do not publish, quote or reference a client, its data or an engagement in marketing without explicit written permission.

Engagement-specific deliverables are provided under the engagement agreement. We retain ownership of our pre-existing methods, frameworks, templates and general know-how, without retaining or incorporating your confidential information.

Transfer and storage

Our order of preference:

  1. A workspace you provide, with read-only, time-limited access. This is the preferred route, because your data stays in your environment and access ends when the engagement does.
  2. Our secure file portal, once that account is active. Until then we will agree a suitable secure method with you before anything is transferred.
  3. Not by ordinary email attachment. We do not accept bulk operational exports that way.

Temporary working copies and temporary local databases are treated as client files: the same controls and the same deletion schedule apply to them.

Device security

The device used for client work has full-disk encryption (FileVault), automatic screen locking, current macOS security updates, and multi-factor authentication on the business accounts that support it. Unencrypted removable media is not used for client data.

Because our first preference is to work inside a client-provided workspace, the volume of client data held locally is kept as small as the engagement allows.

Who can access your data

Victoria Mumford is the only person authorised to access client operational data. We do not provide client data to employees, contractors or offshore personnel. If additional personnel are ever required for an engagement, you will be informed and your written approval obtained before access is granted.

Artificial intelligence

Client operational data is not submitted to general-purpose generative AI systems by default. Identifiable ticket content, customer names, email addresses, employee personal information and confidential client records are not entered into ChatGPT, Claude or similar services as part of the standard assessment process.

If a proposed analysis would require a third-party AI service, we will first disclose the provider, the information involved, the purpose, the relevant data-use terms and the proposed safeguards. The information will not be submitted without your written authorisation.

AI tools may be used for general administration, templates, research and methodology development, where no client confidential or personal information is included.

Service providers

These are the providers currently in use. We will update this page before adding any other provider that touches client data.

Provider What it handles Purpose Processing location
Netlify Website hosting and technical request logs Serving and securing this website Primarily United States
Namecheap Private Email Contact information, contracts and ordinary correspondence Business email May occur outside Canada
Formspree Website enquiry submissions only Enquiry form handling and delivery United States

Formspree does not receive client operational exports. It handles only what is typed into the enquiry form on this site.

Retention and deletion

What How long
Unsuccessful enquiries Deleted from active business systems within 90 days of the last substantive contact
Client operational data, temporary databases, identifiable working files Deleted within 30 days after final delivery, unless the engagement agreement or applicable law requires otherwise
Access to your systems and shared folders Removed when no longer required, and no later than the end of that same 30-day period
Final deliverables containing your confidential information Retained for 12 months to support reasonable follow-up, unless earlier deletion or another period is agreed
Routine engagement correspondence Retained for up to 12 months after closing, unless it forms part of a contract, accounting record, dispute or legal matter
Contracts, invoices and required accounting or tax records Generally six years from the end of the tax year they relate to, or longer where legally required
Security-incident records involving personal information Retained for at least 24 months
Hosting and security logs Per the provider's operational retention schedule

We do not retain ticket exports merely because financial records must be kept.

Written confirmation of deletion is available on request. We do not currently provide independently audited certificates of destruction.

If something goes wrong

If we determine that a security incident affected your data, we will notify you without undue delay and, where reasonably possible, within 48 hours. The notice will include the information available at the time, the containment steps taken, and any actions reasonably required from you. We will cooperate with your investigation and comply with applicable reporting and notification obligations.

Questions

If your security or legal team needs something this page does not answer, ask before the engagement rather than during it. Email info@mumfordadvisory.com or request a fit conversation and say it is a security question. You will get a direct answer, including "we do not do that yet" where that is the truth.

The cost is already being carried. The only question is whether it has been counted.

Request a fit conversation →