Working together
We design so that systems hold the least data that will do the job. The cheapest way to protect personal data is not to collect it, and the second cheapest is not to copy it into a second system.
What we commit to
Data minimisation is a design decision made early.
Every field on a form and every column in an integration should have someone who acts on it; fields collected because they might be useful create obligation without value, and they measurably reduce form completions as well.
We keep personal data out of systems that do not need it. Analytics implementations are configured to avoid capturing personal information in URLs and event properties, and integrations pass identifiers rather than copying records wherever the receiving system does not need the detail.
For AI work this matters more, not less. Sending business documents to a hosted model is a data transfer, and it should be a decision rather than a side effect. We state which data leaves your systems, where it goes, and what the provider's retention terms are, so the decision is made with the facts.
What we do not do is offer legal advice on your obligations. Requirements differ by jurisdiction, sector and the nature of the data, and they should be confirmed by your own advisers. Our part is to build so that the surface those obligations apply to is as small as it can reasonably be.

We design so that systems hold the least data that will do the job. The cheapest way to protect personal data is not to collect it, and the second cheapest is not to copy it into a second system.
Everything above is how we say we work. Thirty minutes on a real problem is the fastest way to find out whether it is also how we behave — and it costs you nothing to check.