How we handle content

Practices, not badges. We do not claim SOC 2, ISO, HIPAA, or "GDPR certified."

Controller and processor

On assessment and contact forms we are the controller: name, work email, company, role, and project notes.

During a migration we are the processor of customer CMS content: entries, assets, URLs, metadata, and personal data inside that content. Processed only to perform the engagement.

Training policy

Customer content is not used to train models. That is a policy, not a certification or audit.

How paid work is collected

After a signed SOW, invoice and/or Stripe. There is no checkout on this site. See Privacy for Vercel, Resend, and PostHog on the marketing site.