Data Security & Confidentiality Statement
How Binary Findings delivers secure, flexible and effective consultancy remotely.
Last updated: 26 August 2026
1. Our Commitment
Binary Findings understands that clients netrust us with information that may be commecially sensitive, confidential or personal. Protecting that information is fundamental to how we work. We use proportionate technical and organisational safeguards to preserve the confidentiality, integrity and availability of the information entrusted to us. Our approach is guided by the UK General Data Protection Regulation, the Data Protection Act 2018 and recognised principles of good information governance. This statement provides a public summary of our approach. More detailed arrangements may be documented within individual contracts, statements of work, data-processing agreements or confidentiality agreements.
2. Our Security Principles
We apply the following principles througout our work:
- Collect and use only information reasonably required for the agreed purpose
- Establish clear responsibilities and permitted uses before receiving client data
- Restrict access to authorised individuals with a legitimate business need
- Use secure systems and appropriate safeguards when storing, accessing or transferring information
- Maintain the accuracy, reliability and traceability of data where this forms part of the agreed service
- Retain information only for as long as it is required
- Dispose of information securely when its retention is no longer necessary
- Report and respond appropriately to suspected security or confidentiality incidents
- Review security arrangements as technology, risks and legal requirements change
3. Information We May Handle
Depending on the engagement, Binary Findings may handle:
- Business and operational information
- Contact and stakeholder information
- Research, survey or evaluation data
- Performance, quality and service-delivery data
- Financial or commercial information
- Pseudonymised or anonymised datasets
- Personal or special-category information where this is necessary, lawful and expressly agreed
4. Secure Systems & Devices
Binary Findings uses managed business systems and security controls appropriate to the nature of its work. These include:
5. Access & Confidentiality
Access to client information is limited to those who require it to delivery agreed work. Binary Findings is led and operated by its Principal Consultant. If a subcontractor or specialist supplier is required, this will be managed in accordance with the relevant contract. Appropriate confidentiality, data-protection and security requirements will be established before access is granted. Client information will not be disclosed to another party unless:
6. Data Sharing & Transfers
Information is shared only where necessary and through an appropriate method. The method used will take account of the nature, volume and sensitivity of the information. Where a third-party platform or service provider is used, Binary Findings considers its purpose, security arrangements, contractual protections and data location where relevant. Personal information will not be transferred internationally unless an appropriate lawful mechanism and suitable safeguards are in place.
7. Use of Artificial Intelligence
Binary Findings may use artificial intelligence tools to support appropriate low-risk activities, such as developing ideas, improving general wording or assisting with non-confidential technical work. Client-confidential, identifiable or special-category information will not be entered into public generative AI services. Any proposed use of AI involving client information or a material part of a client deliverable will be assessed for privacy, confidentiality, accuracy and contractual implications. AI-generated or AI-assisted material remains subject to human review. Binary Findings retains responsibility for verifying work before it is relied upon or supplied to a client.
8. Data Retention & Secure Disposal
Information is retained only for as long as it is needed for the agreed service, applicable legal or regulatory responsibilities, legitimate business records or the establishment and defence of legal rights. Retention requirements may be agreed with the client at the start of an engagement. When information is no longer required, it will be securely deleted, anonymised or returned as appropriate. Deletion from active systems may not immediately remove information from protected backup or recovery systems. Any remaining copies will be isolated from ordinary use and removed through the relevant system’s normal retention cycle.
9. Security Incidents
Binary Findings maintains procedures for identifying, assessing, containing and responding to suspected information-security incidents. Where an incident affects client information, Binary Findings will:
10. Client Responsibilities
Effective security is a shared responsibilit. Clients are expected to:
11. Review & Continuous Improvement
Binary Findings reviews this statement and its supporting practices periodically and following significant changes to its services, systems, risks or legal responsibilities. Changes may be made to reflect improvements in our controls, new technology, updated guidance or changes in the law. The latest version will be published on this website.
12. Questions or Concerns
Questions about the security or confidentiality of information handled by Binary Findings can be sent to: Email: enquiries@binaryfindings.co.uk Website: www.binaryfindings.co.uk Privacy enquiries, information-rights requests and data-protection complaints are handled in accordance with our Privacy Policy and complaints arrangements