Skip to main content
Trust Center · Controlled document library

Data consulting trust documents for informed due diligence.

Review the availability of security, privacy, responsible AI, legal, continuity, conduct, and procurement materials used to support evaluation of our data consulting and Data & AI services.

Document access, applicability, and detail vary by review purpose, confidentiality requirements, engagement scope, and internal approval. No certification or compliance status should be inferred from this page.

Executive summary

A practical starting point for security, privacy, legal, and procurement review

This library is designed to help stakeholders understand what documentation may be available, who it is intended for, and how access is managed. It supports due diligence for data analytics, business intelligence, data engineering, AI and machine learning consulting, data governance, cloud data work, database services, reporting, automation, and managed data teams.

Documents provide context and evidence boundaries. They do not replace the engagement-specific review of services, systems, data categories, access, delivery locations, client responsibilities, subcontractors, contract terms, or technical configuration.

Availability guide

How document status is communicated

Status labels explain access conditions in plain language. Colour supports recognition, but every status is also written as text.

Publicly available

Approved for unrestricted access after the live URL and publication version are verified.

Available on request

Shared after we understand the review context and confirm the appropriate approved version.

Available under NDA

Contains information that may require confidentiality terms and a defined review purpose.

Planned / not yet published

A public document is being considered or prepared; current practices may instead be discussed directly.

Trust document library

Security, privacy, AI, legal, and operational documents

Use the filter to review document availability. Public actions remain disabled until an approved live URL is supplied in the page configuration.

12 documents shown
Available on request

Security Overview

A concise introduction to our security approach for data consulting, analytics, engineering, AI, reporting, automation, and managed service engagements.

Document type
Security summary
Intended audience
Security, technology, procurement
Version / date
Version/date pending approval
Publicly available

Privacy Notice

Explains how website and business-contact information is handled, subject to the approved notice and the activities described within it.

Document type
Privacy notice
Intended audience
Clients, prospects, website visitors
Version / date
Version/date pending approval
Available under NDA

Data Processing Addendum

Contractual data-processing terms that may be used when we process personal data on a client’s behalf, subject to engagement scope and legal review.

Document type
Contract addendum
Intended audience
Legal, privacy, procurement
Version / date
Version/date pending legal approval
Available on request

NDA Template

A proposed confidentiality template for evaluation or engagement discussions. Final terms remain subject to review and agreement by the relevant parties.

Document type
Legal template
Intended audience
Legal, procurement, business sponsors
Version / date
Version/date pending legal approval
Planned / not yet published

Responsible AI Policy

Describes our intended principles for responsible use of AI in consulting and delivery, including human oversight, appropriate use, and engagement-specific controls.

Document type
Policy
Intended audience
AI, data, legal, risk, executives
Version / date
Publication version not yet approved
Planned / not yet published

AI Governance Statement

A governance-level summary of how AI-related decisions, responsibilities, review points, limitations, and client requirements may be addressed.

Document type
Governance statement
Intended audience
Executives, AI governance, legal, risk
Version / date
Publication version not yet approved
Available on request

Business Continuity Summary

A high-level explanation of continuity planning considerations for service delivery, staffing, communication, dependencies, and recovery priorities where applicable.

Document type
Operational summary
Intended audience
Procurement, operations, risk, technology
Version / date
Version/date pending approval
Available under NDA

Incident Response Overview

An overview of roles, escalation considerations, communication expectations, and engagement-specific responsibilities for managing suspected incidents.

Document type
Security process overview
Intended audience
Security, technology, legal, procurement
Version / date
Version/date pending security approval
Available on request

Vendor Management Overview

A summary of how relevant third-party and subcontractor considerations may be evaluated for an engagement, subject to scope, access, and contractual arrangements.

Document type
Risk-management overview
Intended audience
Procurement, security, legal, operations
Version / date
Version/date pending approval
Publicly available

Code of Conduct

Sets expectations for professional behaviour, integrity, respectful collaboration, confidentiality, conflicts, and responsible representation.

Document type
Organisational policy
Intended audience
Clients, team members, partners
Version / date
Version/date pending approval
Planned / not yet published

Acceptable Use Policy

Defines appropriate and restricted use expectations for relevant services, systems, collaboration spaces, data, and AI-enabled capabilities.

Document type
Usage policy
Intended audience
Clients, users, technology, legal
Version / date
Publication version not yet approved
Planned / not yet published

Accessibility Statement

Describes our approach to accessible digital experiences, known limitations, feedback routes, and improvement priorities once formally reviewed.

Document type
Accessibility statement
Intended audience
Clients, users, procurement, accessibility teams
Version / date
Publication version not yet approved
Documentation request process

A controlled, context-aware request workflow

The process helps us provide the correct approved material without disclosing irrelevant or sensitive information.

Step 01

Tell us what you are reviewing

Identify the proposed service, stakeholder group, review objective, target decision date, and any required questionnaire or document list.

Step 02

We confirm document availability

We identify which approved materials are public, available on request, restricted under NDA, engagement-specific, or not yet published.

Step 03

Access conditions are agreed

Where appropriate, we confirm confidentiality, recipient, use restrictions, secure delivery method, and any dependencies on engagement scope.

Step 04

Relevant materials are provided

We share the approved documents or explain what can be addressed through a meeting, questionnaire response, contract, or scoped clarification.

Document governance

Versioning, review, and update expectations

Publication metadata should be evidence-based and maintained by an accountable document owner.

Minimum publication information

Before any document is presented as current, the page owner should verify:

  • Document owner and approving function.
  • Version identifier and effective or review date.
  • Approved audience and access classification.
  • Live public URL or controlled delivery route.
  • Whether a material change affects active clients or reviews.

Suggested update lifecycle

StagePurposeExpected evidence
DraftPrepare or revise content.Named owner and source materials.
ReviewValidate legal, privacy, security, technical, and brand accuracy.Recorded reviewer comments and approvals.
ApprovedAuthorise controlled or public use.Version, date, approver, and access classification.
PublishedMake the correct version available through the approved channel.Verified URL or delivery process.
SupersededPrevent outdated material from being used as current evidence.Archive record and replacement reference.
What this means for clients

Decision-useful information without overstating certainty

The library supports review while preserving the distinction between general practices and engagement-specific commitments.

Faster due diligence

A structured library helps procurement, security, legal, privacy, and technology teams identify relevant materials without relying on broad marketing claims.

Clearer evidence boundaries

Availability labels distinguish public evidence, controlled materials, confidential information, and documents that are not yet formally published.

Engagement-specific review

Documents support evaluation, but the applicable controls, responsibilities, platforms, data categories, and contract terms still depend on the actual engagement.

Important considerations

Scope, limitations, and shared responsibility

Trust documentation is one input into due diligence. It should be read with the proposed solution, contract, data flows, client environment, and operating responsibilities.

Applicability depends on scope

Not every document, practice, platform, or control applies to every service or delivery model.

Responsibilities are shared

Clients remain responsible for decisions, access approvals, lawful instructions, source data, environment controls, and use of deliverables within their organisation.

General information is not legal advice

Legal, regulatory, and contractual questions should be reviewed by appropriately qualified advisers and the relevant parties.

No unsupported assurance

This page does not claim certification, audit status, regulatory approval, guaranteed security, guaranteed continuity, or universal compliance.

Frequently asked questions

Trust document questions from buyers and review teams

These answers address common security, privacy, legal, procurement, technical, and governance questions.

What are data consulting trust documents?

They are controlled materials used to support security, privacy, legal, responsible AI, operational, and procurement review of a data consulting relationship. They may include public policies, contractual documents, process summaries, governance statements, and confidential supporting information.

Can I download every document directly from this page?

No. Documents are only linked when an approved public URL exists. Other materials may be available on request, restricted under NDA, engagement-specific, or not yet formally published. This page does not create placeholder or unapproved download links.

Why are some documents available only under NDA?

Certain materials may contain sensitive operational, security, process, or supplier information. Confidentiality conditions help limit distribution and ensure the material is used for a defined due-diligence purpose.

How do I request trust documentation?

Use the Trust Documentation contact route and include the service under review, your organisation, stakeholder role, requested materials, target decision date, and any questionnaire or procurement deadline.

Will the documents confirm that every control applies to my engagement?

Not necessarily. The applicable practices, responsibilities, tools, hosting arrangements, data access, subcontractors, and contractual commitments depend on the agreed scope and delivery model.

Is the Data Processing Addendum legal advice?

No. Any DPA is a proposed contractual document and should be reviewed by the relevant legal and privacy teams. This webpage provides general information and does not constitute legal advice.

Can procurement teams request a supplier questionnaire?

Yes. We can review a relevant questionnaire, although completion depends on scope, reasonable relevance, available verified evidence, confidentiality requirements, and the time needed for responsible internal review.

How are document versions managed?

Approved documents should have an owner, version identifier, effective or review date, approval record, and change history where appropriate. The live library should display only verified publication information.

What happens when a document is updated during procurement?

Where material changes affect an active review, the relevant contact may provide the newer approved version or explain the change. Contractual notification obligations, if any, are governed by the applicable agreement.

Can I request evidence about security or privacy practices not listed here?

Yes. Describe the requirement and why it is relevant to the proposed engagement. We will identify whether the matter can be addressed through an approved document, a scoped discussion, a questionnaire response, or contractual clarification.

Do these documents prove certification or regulatory compliance?

No certification, audit result, regulatory status, or compliance outcome should be inferred unless it is explicitly stated in an approved document and supported by current evidence. Applicability also depends on jurisdiction, service scope, and client requirements.

Who should review the documents?

Depending on the engagement, reviewers may include information-security, privacy, legal, procurement, technology, data governance, AI governance, finance, operations, and executive stakeholders.

Request Trust Documentation

Tell us which service is under review, the documents or questionnaire you need, your stakeholder role, and the target decision date. We will confirm what can be provided, any access conditions, and where engagement-specific clarification is required.

Contact the Trust Team