Trust & Privacy
Our Privacy Commitments
Privacy is treated as an engineering, governance and customer-trust responsibility — not simply a legal notice. These commitments describe the principles Raeburn Consulting applies to personal data and client-confidential information across its services.
Last reviewed: 27 August 2026
Data minimisation
We seek to collect and process only personal and customer data that is relevant and proportionate to the defined service, contractual, security or legal purpose. New workflows should avoid collecting data simply because it is technically available.
Defined retention
Personal and customer information is subject to defined retention requirements appropriate to its purpose, sensitivity, contractual obligations and applicable law. Data should not be retained indefinitely without a justified purpose.
Deletion mechanisms
We maintain processes for deletion, expiry or anonymisation where appropriate. Valid data-subject and customer deletion requirements are assessed against applicable contractual, legal, security, backup and record-keeping obligations.
Encryption
Sensitive and customer information is protected using encryption in transit and, where supported and appropriate to the service, encryption at rest. Secrets and credentials are handled separately from ordinary application content.
No sale of customer data
Raeburn Consulting does not sell customer personal data or client-confidential information. Customer information is not treated as an advertising-data asset.
Restricted staff access
Access to personal and customer information is restricted according to role, operational need and least-privilege principles. Privileged access receives additional protection and is not granted merely for convenience.
Supplier and subprocessor review
Material suppliers and subprocessors are reviewed proportionately for privacy, security, data handling, location, contractual safeguards and dependency risk before or during approved use.
DPIAs and privacy by design
High-risk processing and material changes involving personal data are assessed for privacy risk. Data Protection Impact Assessments are used where required or appropriate, with privacy considerations incorporated into service design rather than deferred until launch.
AI safeguards
AI-enabled processing is subject to additional governance around data minimisation, sensitive information, provider/model selection, retention and training settings, access controls, prompt injection and exfiltration risk, human oversight and consequential output review.
Security and incident response
Privacy depends on security. We apply technical and organisational safeguards and assess material security incidents for potential personal-data impact, escalation, notification and remediation obligations.
Accountability and questions
Privacy requirements are reviewed when services, suppliers, data categories, AI capabilities or processing purposes materially change. Privacy enquiries can be directed to dpo@theraeburngroup.com. Security concerns can be reported to security@theraeburngroup.com.
For AI-specific safeguards, see our AI Responsible Use & AI Security Standard. These commitments complement, rather than replace, applicable privacy notices, contracts and statutory rights.