Discuss a project

Privacy & security

Data flows, access and approvals are defined before automation.

Security is not a single product feature. It results from architecture suited to the use case, limited permissions, reviewable outputs and clear operational responsibility.

Minimise data

Only information required by the defined workflow is processed. Test and production data are separated where practicable.

Limit access

Interfaces and accounts receive only the rights required for their task. Write access and automated actions are assessed separately.

Make results reviewable

Source references, logging, test cases and human approval are used where errors can have commercial, legal or editorial consequences.

Choose providers to fit

Models, hosting and data storage are selected according to sensitivity, integration needs, quality and cost. There is no blanket promise that every solution uses the same infrastructure.

Prepare operations

Before production use, responsibilities, failure paths, change processes and necessary controls are defined. Automation without an operational model is avoided.

Contracts and documentation

Scope, confidentiality, data processing terms and technical measures are agreed for each project where required by its specific data flow.

Important

The public website and client projects must be considered separately.

The privacy notice describes the services actually used on hits7.com. Each client project receives separate documentation of its concrete data flow before work begins. Requirements for hosting region, retention, roles, logging and model providers are explicitly defined there.

Read the website privacy notice

Clear requirements before the first data transfer

The initial discussion can classify data types, existing systems and required safeguards. Confidential or special-category personal data should not be entered in the public request form.

Discuss requirements