Privacy Principles
Personal information is collected for a stated purpose, used only for that purpose, and protected commensurate with its sensitivity.
- Purpose limitation
- Transparency about what is collected
- Proportionate protection by sensitivity
- Accountability for downstream use
Data Minimization
Systems are designed to collect the least information necessary. Fields that are not required are not requested.
- Least-data collection by design
- No unnecessary sensitive fields
- Aggregation preferred over identification
- Public forms explicitly warn against sensitive submissions
Retention
Information is retained only as long as needed for the stated purpose or as required by contract or law, then disposed of securely.
- Defined retention periods
- Secure disposal and media sanitization
- Backup retention aligned to policy
- Contractual retention honored
Encryption
Personal information is encrypted in transit and at rest, with access limited to those who need it for delivery.
- TLS in transit
- Encryption at rest
- Role-restricted access
- Access logging for sensitive records
Customer Ownership
Customer and agency data belongs to the customer. It is not sold, and it is not used for unrelated purposes.
- Customer retains ownership of their data
- No sale of customer or agency data
- No unrelated secondary use
- Return or deletion at end of engagement
Access Requests
Requests to access personal information are handled through the secure contact workflow with identity verification appropriate to the request.
- Requests received through the contact workflow
- Identity verification before disclosure
- Defined acknowledgement timeline
- Contractual and legal obligations respected
Deletion Requests
Deletion requests are honored where no overriding contractual, legal, or records-retention obligation applies.
- Deletion honored where permitted
- Explanation provided where retention is required
- Propagation to backups on the retention cycle
- Confirmation on completion