Our Approach to Data Governance
Data is one of our clients’ most valuable assets as well as an important topic for their customers. Responsible data handling is foundational to how we deliver AI strategy, implementation and advisory services. Here’s a high-level overview of how we work with client data.
This document provides a high-level overview of our data governance practices and does not create contractual obligations. Binding data protection commitments are set forth in applicable agreements, including any Data Processing Addendum.
Client Data Ownership and Control
We access, process and analyze client data solely to deliver the agreed upon services. We do not use client data for our own purposes, resale or product development. Clients retain full ownership and control of their data at all times, period.
Client data is never used to train artificial intelligence or machine learning models unless explicitly authorized in writing by the client.
Data Protection and Privacy Regulations
We are committed to handling client data in a manner consistent with applicable data protection and privacy laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and relevant U.S. state privacy laws, where applicable.
In most engagements, we act as a data processor or service provider, processing personal data solely on the instructions of our clients, who remain the data controllers. We work collaboratively with them to support their privacy and governance obligations related to AI initiatives.
Purpose-Limited Data Use
Whenever possible, we use anonymized, aggregated or synthetic data for AI exploration and testing. When that’s not possible or economically viable, we follow an industry-standard approach to reduce use of real client data called principle of purpose limitation:
- Data is accessed only when necessary
- Use is limited to the scope of the engagement
- Access is restricted to authorized personnel on a need-to-know basis
Security and Access Controls
We maintain administrative, technical and organizational safeguards designed to protect client data from unauthorized access, disclosure or loss. Our security practices are guided by industry-standard principles, including:
- Least-privilege access
- Logical segregation of client data
- Encryption in transit and at rest where appropriate
- Secure development and operational practices
Use of AI Models and Third Parties
In the course of delivering AI services, we may use third-party platforms, services or model providers. When we do:
- Client data is handled in accordance with agreed contractual terms
- Sub-processors are required to meet data protection and confidentiality standards
- We remain accountable for how client data is handled within the scope of our services
Data Retention and Deletion
We retain client data only for as long as necessary to deliver services or meet legal obligations. Upon completion of an engagement, client data is returned or securely deleted in accordance with contractual agreements.
Supporting Client Compliance
We partner with clients to support their data protection and regulatory obligations, such as privacy and security requirements relevant to AI. Where applicable, we assist with documentation, governance frameworks and responsible AI practices aligned to client risk profiles and industry standards.
Contractual Commitments
Our specific data protection obligations are clearly defined in every contractual agreement which may include a Data Processing Addendum.
There may be other unique considerations addressed in your engagement contract, but this overview should give you a general sense of our approach. We encourage you to reach out if you’d like more information about our data governance policies. This information was provide for guidance only and does not create a contractual commitment.