Legal

Privacy Policy

A small firm with a simple answer. We collect what you send us, we keep it to ourselves, and we delete it when you ask.

Last updated: August 25, 2026

What we collect

Only what you choose to send us. This site has no account system, no sign up, no login and no forms that store what you type. If you email [email protected] or call, we have your message, your address or number, and whatever you told us. That is the whole of it.

Our hosting provider keeps ordinary server logs, such as the requested page and a timestamp, for security and reliability. We do not use those logs to build a profile of you.

Cookies and tracking

This site uses no advertising cookies and no tracking cookies. There are no advertising pixels, no cross site trackers and no third party analytics that follow you elsewhere on the web. Nothing on this page is trying to work out who you are.

Email

Our email runs on Google Workspace. Messages you send us are stored there under our account, subject to Google's security and privacy terms, and are read by the firm. We keep correspondence for as long as it is useful for the relationship, and we delete it on request.

Client materials

Documents, records, recordings and system access shared with us during an engagement are treated as confidential. We use them only to do the work you hired us for.

Client materials are not used to train public AI models. Where an engagement involves AI tooling, we configure it so your material stays inside your systems and your accounts wherever possible, and we tell you plainly which tools touch your data before anything is connected. Every workflow we build is designed for human review before it acts on anything that matters.

Who else sees your data

We do not sell your data, and we do not share it with third parties for marketing. We share information only with service providers who make the firm run, such as our email and hosting providers, and only to the extent they need it, or where the law requires disclosure. If an engagement requires bringing in another practitioner, we tell you first and they are bound by the same confidentiality terms.

Deleting your data

Email [email protected] and ask. Tell us what you want removed, and we will delete it and confirm when it is done. You can also ask for a copy of what we hold, or ask us to correct it. We do not charge for any of this.

Some records, such as invoices, we are required to keep for tax and accounting purposes. We will say so if that applies.

GDPR readiness

The firm is based in the United States and works mostly with US organizations, so in the ordinary case the GDPR does not apply to what we do. We built our practices to meet its spirit anyway: collect the minimum, say what it is for, keep it no longer than needed, and delete it when asked. Where an engagement does involve personal data of people in the EU or the UK, we will sign a data processing addendum setting out the terms, and we will agree in writing where the data lives and who may access it before the work starts. We hold no security or privacy certification, and we do not claim one.

Changes

If our practices change, this page changes with them, and the date at the top tells you when.

Questions

Email [email protected] and a person will answer.