OUR COMMITMENT
The data we will not touch.
Most consultancies don't publish a page like this. That's precisely why we do. Exactly what we will and won't handle, how it's enforced technically rather than promised, and what happens when a project turns out to need something we've ruled out.
Three classes
RED
Never processed, stored, or transmitted by anything we build. Privileged legal material and matter files. Patient and clinical records. Student records and minors' personal data. Financial account and card data. Biometric data. National identification numbers. Data protected under a principal or supplier confidentiality agreement.
AMBER
Handled only where necessary, minimised, and covered by a data processing agreement. Names and business contact details. Appointment and scheduling data. Staff records. Billing administration.
GREEN
Normal handling. Your own procedures and templates. Public information. Operational metrics. Anonymised and aggregated data. Pre-engagement enquiries. Internal knowledge and documentation.
How it's enforced
- Contractually — the boundary is a written term of every engagement, binding on both sides.
- By design — workflows include a screening step that detects and diverts likely restricted data before it reaches any model.
- Architecturally — where possible, systems are built so restricted data structurally cannot reach a model call, rather than being discouraged from doing so.
- Through logging — boundary events are recorded. If restricted data appears, it's detected and reported to you.
- By placement — where sensitivity demands it, we deploy models inside your own infrastructure so data never leaves the building. That option is real now in a way it wasn't eighteen months ago.
- By refusal — if you ask us to work inside the boundary, we decline in writing and refer you elsewhere. This has no exceptions, including when it costs us the engagement.
If a project turns out to need restricted data
It happens. Halfway through mapping, a workflow turns out to depend on a field we've ruled out. When that occurs we stop, reclassify, and either redesign around it or remove it from scope. We do not proceed on the basis that it's only one field. The rule exists precisely for the moments when following it is inconvenient.
Malaysian context
Malaysia's Personal Data Protection Act was substantially amended through 2024 and 2025. Since June 2025, a Data Protection Officer is mandatory, breach notification is mandatory, and penalties reach RM1 million and three years' imprisonment.
Separately, Malaysia's National AI Office released a public consultation paper in July 2026 for the country's first horizontal AI statute, proposing a risk-based framework with Developer and Deployer roles. On the proposed definitions, a business that adapts or integrates a model for its own use case may itself hold Developer obligations — something most organisations have not yet considered.
We keep our own work well inside these lines, and we help clients assess where they stand. That's a service, not a disclaimer.
This page describes our operating policy. It isn't legal advice — your data protection officer and your lawyers should confirm your own position.