Data Security and Access
What data we process, who has access, how it is controlled, and how it is revoked. Written plainly, because 'we take security seriously' is not an answer.
Working with us means granting access to Search Console, analytics and usually your CMS. Here is exactly what that involves: access is granted to named individuals rather than shared accounts, credentials are stored in an encrypted password manager and never in chat or email, every person with access is listed for you, access is revoked within one working day when someone rotates off your account, and everything is deleted within 30 days of an engagement ending unless you ask otherwise. A mutual NDA is available before the first substantive conversation.
## What we typically need access to
Access we request, and why
- Google Search Console
- Read and settings. The primary diagnostic source — without it we are guessing
- Google Analytics
- Read. Baseline measurement and conversion tracking
- Content management system
- Editor or admin, depending on scope. Required to implement on-page work
- Google Business Profile
- Manager, only for multi-location clients
- Server or CDN logs
- Read-only, only on sites large enough for log analysis to matter
- Git or staging
- Only where we implement template changes, and only on staging first
We ask for the minimum level that lets us do the work. If you would rather grant read-only and implement changes yourself, that works — it is slower, and we will say so, but it is a legitimate choice.
## How access is controlled
– **Named individuals, not shared accounts.** You get a list of every person with access to your properties, kept current.
– **Credentials in an encrypted manager.** Never in email, never in chat, never in a spreadsheet.
– **Two-factor authentication** on every account that supports it, enforced.
– **Revocation within one working day** when someone leaves your account or the company. You are told when it happens.
– **Quarterly access review**, where we remove anything no longer needed and send you the updated list.
## Sub-processors
We use a small set of third-party tools that may process data relating to your account. The current list is supplied at onboarding and updated when it changes. Nothing about your account is shared with anyone outside that list and our own employed staff — we do not subcontract delivery.
## At the end of an engagement
Within 30 days of an engagement ending: all access is revoked, credentials are deleted from our systems, and account data is removed from our tools. You receive an export of everything first — audits, briefs, keyword maps, the complete link list, and reporting history. It is your data and it leaves with you.
If you need a longer retention period for your own compliance reasons, say so and we will accommodate it in writing.
## Legal instruments available
– Mutual NDA, before the first substantive conversation
– Data processing addendum covering UK and EU GDPR, with standard contractual clauses and the UK international data transfer addendum
– Australian Privacy Principles addendum for Australian clients
– Security questionnaire responses — send yours and we will complete it
Security questions
These are the questions that come up most often on first calls. If yours is not here, ask — we answer in writing within one working day.
Will you sign an NDA before we talk?
Yes, mutual, sent the same day you ask. Several clients do this before the first call and it is an entirely reasonable request.
Where is our data processed?
In India, by our employed staff, plus the third-party tools on the sub-processor list supplied at onboarding. For UK and EU clients, transfers are covered by standard contractual clauses and the UK international data transfer addendum.
Do you subcontract any of the work?
No. Every person on your account is directly employed by us. This is partly a quality decision and partly a security one — subcontracting is where access control typically breaks down in this industry.
What happens to our data if we leave?
Full export to you first, then deletion within 30 days: access revoked, credentials removed, account data cleared from our tools. A longer retention period can be agreed in writing if your compliance needs it.
Can you complete our security questionnaire?
Yes. Send it over — we complete these regularly for enterprise clients and it usually takes two to three working days.