How we keep the request small
- Metadata first. Content only when metadata cannot answer the question.
- Aggregate wherever possible. Totals and distributions rather than records.
- Role counts instead of names.
- Cost bands instead of individual compensation.
- Client-managed, read-only, time-limited access where your tooling supports it.
- Limited samples rather than complete message archives.
- More is requested only when we can explain why it is necessary.
Your responsibility
You are responsible for confirming that you have the authority to provide the information used in the assessment, and that its collection and disclosure comply with applicable law, contractual obligations and your internal policies. Our minimisation requirements do not replace your own privacy and security obligations.
Confidentiality
We will enter into a reasonable confidentiality agreement before client operational data is transferred. We can review and, where appropriate, work under a client-provided NDA.
Your data remains your data. We do not publish, quote or reference a client, its data or an engagement in marketing without explicit written permission.
Engagement-specific deliverables are provided under the engagement agreement. We retain ownership of our pre-existing methods, frameworks, templates and general know-how, without retaining or incorporating your confidential information.
Transfer and storage
Our order of preference:
- A workspace you provide, with read-only, time-limited access. This is the preferred route, because your data stays in your environment and access ends when the engagement does.
- Our secure file portal, once that account is active. Until then we will agree a suitable secure method with you before anything is transferred.
- Not by ordinary email attachment. We do not accept bulk operational exports that way.
Temporary working copies and temporary local databases are treated as client files: the same controls and the same deletion schedule apply to them.
Device security
The device used for client work has full-disk encryption (FileVault), automatic screen locking, current macOS security updates, and multi-factor authentication on the business accounts that support it. Unencrypted removable media is not used for client data.
Because our first preference is to work inside a client-provided workspace, the volume of client data held locally is kept as small as the engagement allows.
Who can access your data
Victoria Mumford is the only person authorised to access client operational data. We do not provide client data to employees, contractors or offshore personnel. If additional personnel are ever required for an engagement, you will be informed and your written approval obtained before access is granted.
Artificial intelligence
Client operational data is not submitted to general-purpose generative AI systems by default. Identifiable ticket content, customer names, email addresses, employee personal information and confidential client records are not entered into ChatGPT, Claude or similar services as part of the standard assessment process.
If a proposed analysis would require a third-party AI service, we will first disclose the provider, the information involved, the purpose, the relevant data-use terms and the proposed safeguards. The information will not be submitted without your written authorisation.
AI tools may be used for general administration, templates, research and methodology development, where no client confidential or personal information is included.
Service providers
These are the providers currently in use. We will update this page before adding any other provider that touches client data.
| Provider |
What it handles |
Purpose |
Processing location |
| Netlify |
Website hosting and technical request logs |
Serving and securing this website |
Primarily United States |
| Namecheap Private Email |
Contact information, contracts and ordinary correspondence |
Business email |
May occur outside Canada |
| Formspree |
Website enquiry submissions only |
Enquiry form handling and delivery |
United States |
Formspree does not receive client operational exports. It handles only what is typed into the enquiry form on this site.
Retention and deletion
| What |
How long |
| Unsuccessful enquiries |
Deleted from active business systems within 90 days of the last substantive contact |
| Client operational data, temporary databases, identifiable working files |
Deleted within 30 days after final delivery, unless the engagement agreement or applicable law requires otherwise |
| Access to your systems and shared folders |
Removed when no longer required, and no later than the end of that same 30-day period |
| Final deliverables containing your confidential information |
Retained for 12 months to support reasonable follow-up, unless earlier deletion or another period is agreed |
| Routine engagement correspondence |
Retained for up to 12 months after closing, unless it forms part of a contract, accounting record, dispute or legal matter |
| Contracts, invoices and required accounting or tax records |
Generally six years from the end of the tax year they relate to, or longer where legally required |
| Security-incident records involving personal information |
Retained for at least 24 months |
| Hosting and security logs |
Per the provider's operational retention schedule |
We do not retain ticket exports merely because financial records must be kept.
Written confirmation of deletion is available on request. We do not currently provide independently audited certificates of destruction.
If something goes wrong
If we determine that a security incident affected your data, we will notify you without undue delay and, where reasonably possible, within 48 hours. The notice will include the information available at the time, the containment steps taken, and any actions reasonably required from you. We will cooperate with your investigation and comply with applicable reporting and notification obligations.
Questions
If your security or legal team needs something this page does not answer, ask before the engagement rather than during it. Email info@mumfordadvisory.com or request a fit conversation and say it is a security question. You will get a direct answer, including "we do not do that yet" where that is the truth.