How we handle content
Practices, not badges. We do not claim SOC 2, ISO, HIPAA, or "GDPR certified."
Controller and processor
On assessment and contact forms we are the controller: name, work email, company, role, and project notes.
During a migration we are the processor of customer CMS content: entries, assets, URLs, metadata, and personal data inside that content. Processed only to perform the engagement.
Training policy
Customer content is not used to train models. That is a policy, not a certification or audit.
How paid work is collected
After a signed SOW, invoice and/or Stripe. There is no checkout on this site. See Privacy for Vercel, Resend, and PostHog on the marketing site.