Ownership and data
What is yours, where your data is processed, what the AI usage policy commits us to, and how performance is judged.
Ownership, data and AI
The accounts, repositories and data we work in are yours from the first day, under your name, and the work itself becomes yours as it is paid for. That is not generosity — it is the only arrangement that makes the relationship honest, because it means we have to keep earning it.
Ownership
| Asset | Where it lives |
|---|---|
| Code repositories | Your GitHub, GitLab or Azure DevOps organisation, from the first commit. We are collaborators, not owners. |
| Domains and DNS | Your registrar account. We will happily manage it; we will not hold it. |
| Ad accounts | Your Google Ads, Meta, LinkedIn and TikTok accounts, with us as a linked agency. |
| Analytics | Your GA4 property and your tag manager container. |
| Data | Your systems. We process it under a written agreement and delete our copies at the end. |
| Prompts and agent configurations | Your repository, versioned alongside the code. |
| Evaluation sets | Yours. This is the artefact that lets anyone maintain the agent later. |
This table is about custody: these accounts and repositories are in your name from the start, so there is never a handover to negotiate. Intellectual property in the work we create for you passes to you on payment in full, as set out in the terms and in your signed agreement.
Data handling
Every engagement has a data handling note covering what personal data is involved, where it is processed, who can see it and how long it is kept. It is written against UK GDPR and, where the work touches the UAE, the UAE Personal Data Protection Law.
In-region hosting is available for work with data residency requirements: Azure UAE, and AWS in the UAE and Bahrain. A common pattern is a split — retrieval and personal data stay in region, and a frontier model handles reasoning over already-redacted content.
Subprocessors are listed, not implied. If we add one, you are told before it starts processing anything of yours.
AI usage policy
Every contract that involves AI names four things:
Agents start by drafting for a person. Autonomy expands only as evaluation scores earn it, and it can be withdrawn the same way. Read the full AI usage policy.
Security and assurance
| Item | Status |
|---|---|
| HTTPS, HSTS and security headers | Standard on everything we build and part of the go-live checklist. |
| Dependency scanning | Automated on every repository we maintain, with a patch cadence agreed per project. |
| Form spam protection | On every public form, without a CAPTCHA that punishes screen-reader users. |
| Access control | Least privilege by default. Access is reviewed when a pod changes. |
| Cyber Essentials (UK) | Being pursued in year one. |
| ISO 27001 | Roadmap under consideration — not yet committed. |
| Platform partnerships | Shopify, HubSpot and Webflow partner programmes, plus Anthropic and OpenAI partner programmes, applied for in year one. |
Accountability
01
Written into the brief and signed off in the portal before design starts. If we cannot agree a metric, that is a signal worth listening to.
02
Held against those metrics, not against activity. If the number has not moved, that is the conversation.
03
Both ways. Long enough to hand over properly, short enough that we cannot coast.
Next step
Send them. We would rather answer a security questionnaire early than discover a blocker in week six.