How We Handle Your Data
Plain English. No legalese. Built for procurement teams in regulated sectors who need to know exactly what touches their data before they sign.
Six principles we work to
Minimum necessary
We only collect the data we genuinely need to scope, deliver and invoice the work.
Encrypted in transit
All website traffic is HTTPS. Operational tools use TLS and at-rest encryption.
Least-privilege access
Only the people working on your engagement can see your data. No shared logins.
Grounded AI, no training
Where AI is used, we use Retrieval Augmented Generation against verified data. Your data is not used to train third-party models.
UK first
We default to UK or EU-hosted services. Where US providers are used, transfers are covered by the UK IDTA or DPF.
DPA on request
A Data Processing Agreement (DPA) is available for any client engagement. Just ask.
Sub-processor list
We engage the following sub-processors to deliver our website, our consulting work and our own software products, Optimus Outreach and the AI Visibility Portal. Their processing is governed by data processing terms no less protective than those we owe our customers. The list is reviewed regularly and updated on material change.
| Provider | Purpose | Region | Transfer safeguard |
|---|---|---|---|
| Supabase Inc. (via Lovable Cloud) | Managed PostgreSQL, authentication, file storage; hosted on AWS | AWS, European Union (Ireland for this website; Stockholm for Optimus Outreach) | UK / EU adequacy |
| Lovable GmbH | Application hosting and AI gateway layer | EU | UK / EU adequacy |
| Google LLC (Gemini, via Lovable AI Gateway) | AI inference under zero-retention enterprise terms, including drafting outreach emails in Optimus Outreach | EU routing via Lovable; transfers under UK IDTA / SCCs | UK IDTA / SCCs |
| Cloudflare, Inc. | CDN, TLS termination, traffic proxying | Global edge, EU-preferred | UK IDTA / SCCs |
| Resend, Inc. | Transactional email | EU / US | DPA / SCCs |
| Used by Optimus Outreach only: | |||
| Perplexity AI, Inc. | Business research and fit scoring for Optimus Outreach. Receives business name, town, website, sector; no person data | United States | EU SCCs and UK Addendum (Perplexity DPA). No training on customer content |
| ReverseContact (VISUM SAS) | Finds named decision makers from public professional profiles. Receives business name and search term | France, EU-hosted | UK adequacy for the EU. DPA published |
| Gojiberry (Superfruits SAS) | Finds and verifies a business email address for a named person. Receives the person's name, job title, profile link and business name | France, EU-hosted | UK adequacy for the EU. Onward transfers under SCCs |
| Google Places (Google Ireland Ltd) | Business discovery. Receives search terms, no person data | EU | UK adequacy for the EU; Google DPF UK Extension |
IDTA = UK International Data Transfer Addendum. DPF = EU-US Data Privacy Framework (UK Extension). SCCs = Standard Contractual Clauses.
Lovable's published Data Processing Agreement, including its published sub-processor list, is available at trust.lovable.dev and is incorporated by reference. The hosting region for our project is EU (Europe, Ireland), evidenced at platform level. Transfers outside the EU at the AI inference layer are safeguarded through Standard Contractual Clauses at the Lovable-to-Google contractual layer, with the formal IDTA / UK Addendum to the EU SCCs and Transfer Impact Assessment documentation available via Lovable's Trust Center on B2B compliance request.
Security posture
- Transport: HTTPS / TLS for all website and tool traffic.
- Authentication: Multi-factor authentication on all business-critical accounts.
- Access control: Least-privilege; client data accessible only to assigned engagement staff.
- Storage: UK or EU data centres by default. At-rest encryption on all primary stores.
- Retention: Engagement data deleted on request, or 6 years after engagement close (HMRC). Optimus Outreach prospect records: deleted after 12 months with no engagement. See the Outreach privacy notice.
- Incident response: Notifiable data incidents reported to affected clients without undue delay and to the ICO within 72 hours where required.
Compliance and registrations
- Cyber Essentials: Certified 28 September 2026, whole organisation scope (recertification due 28 September 2027). Verify the certificate
- Data controller: Optimus Consulting (North West) Limited
- Companies House: 13718490
- ICO registration: ZB883931
- Registered office: 7-9 Macon Court, Crewe CW1 6EA
- Jurisdiction: England and Wales
Need a DPA, security questionnaire or sub-processor notice?
We keep template Data Processing Agreements ready to share with regulated clients. Send us your standard questionnaire and we will turn it round quickly.
Email chris@optimus-consulting.co.uk