How We Handle Your Data
Plain English. No legalese. Built for procurement teams in regulated sectors who need to know exactly what touches their data before they sign.
Six principles we work to
Minimum necessary
We only collect the data we genuinely need to scope, deliver and invoice the work.
Encrypted in transit
All website traffic is HTTPS. Operational tools use TLS and at-rest encryption.
Least-privilege access
Only the people working on your engagement can see your data. No shared logins.
Grounded AI, no training
Where AI is used, we use Retrieval Augmented Generation against verified data. Your data is not used to train third-party models.
UK first
We default to UK or EU-hosted services. Where US providers are used, transfers are covered by the UK IDTA or DPF.
DPA on request
A Data Processing Agreement (DPA) is available for any client engagement. Just ask.
Sub-processor list
We engage the following sub-processors to deliver our website, tools and client work, including CreditHire-Assist. Their processing is governed by data processing terms no less protective than those we owe our customers. The list is reviewed regularly and updated on material change.
| Provider | Purpose | Region | Transfer safeguard |
|---|---|---|---|
| Supabase Inc. (via Lovable Cloud) | Managed PostgreSQL, authentication, file storage; hosted on AWS | EU (eu-west-2, Ireland) | UK / EU adequacy |
| Lovable GmbH | Application hosting and AI gateway layer | EU | UK / EU adequacy |
| Google LLC (Gemini, via Lovable AI Gateway) | AI inference under zero-retention enterprise terms | EU routing via Lovable; transfers under UK IDTA / SCCs | UK IDTA / SCCs |
| Cloudflare, Inc. | CDN, TLS termination, traffic proxying | Global edge, EU-preferred | UK IDTA / SCCs |
| Resend, Inc. | Transactional email | EU / US | DPA / SCCs |
IDTA = UK International Data Transfer Addendum. DPF = EU-US Data Privacy Framework (UK Extension). SCCs = Standard Contractual Clauses.
Lovable's published Data Processing Agreement, including its published sub-processor list, is available at trust.lovable.dev and is incorporated by reference. The hosting region for our project is EU (Europe, Ireland), evidenced at platform level. Transfers outside the EU at the AI inference layer are safeguarded through Standard Contractual Clauses at the Lovable-to-Google contractual layer, with the formal IDTA / UK Addendum to the EU SCCs and Transfer Impact Assessment documentation available via Lovable's Trust Center on B2B compliance request.
Security posture
- Transport: HTTPS / TLS for all website and tool traffic.
- Authentication: Multi-factor authentication on all business-critical accounts.
- Access control: Least-privilege; client data accessible only to assigned engagement staff.
- Storage: UK or EU data centres by default. At-rest encryption on all primary stores.
- Retention: Engagement data deleted on request, or 6 years after engagement close (HMRC).
- Incident response: Notifiable data incidents reported to affected clients without undue delay and to the ICO within 72 hours where required.
Compliance and registrations
- Data controller: Optimus Consulting (North West) Limited
- Companies House: 13718490
- ICO registration: ZB883931
- Jurisdiction: England and Wales
Need a DPA, security questionnaire or sub-processor notice?
We keep template Data Processing Agreements ready to share with regulated clients. Send us your standard questionnaire and we will turn it round quickly.
Email chris@optimus-consulting.co.uk