The answer, in five lines.
01
Enterprise terms only
Client documents are processed exclusively through enterprise AI services under commercial terms — no training on your data, ever. Consumer AI tools are prohibited for client work by written policy.
02
Encrypted, one pair of hands
Storage is encrypted, access is one person, and client files never enter our internal knowledge base.
03
Deleted on a schedule
Everything is removed within 30 days of engagement close, or sooner on request — confirmed in writing.
04
A data-minimization option
For heightened-sensitivity engagements, confidential details are replaced with placeholders locally, before anything reaches an external AI service — with coverage measured on your own documents.
05
Governed and versioned
Data handling runs under a documented, version-controlled internal policy, with controls verified before any client data is received. The full data handling summary ships with every proposal; a register of every service provider — terms and security attestations included — is available on request.
When I required all data processing to remain within the US, Tom reworked the system configuration around that constraint on schedule and without friction.
The Research Council of Makeup Artists Inc.