Protect information throughout the job.
Classification and authorised purpose
Identify public, internal and restricted project information before sharing it. Access should match the agreed purpose and be limited to people who need it for the engagement. The client should flag special restrictions, export controls and personal information before transfer. Do not assume that an NDA permits every hosting location or subcontractor.
Access and account use
Use individual authorised accounts and protect sign-in credentials. Do not share passwords in project messages or public forms. Report unexpected access or suspicious requests. Administrators manage project access and business records; customers must use their own account and should not attempt to access another customer’s information.
Files and channels
Use the authorised portal or another agreed transfer method for project files. Public media uploads, website examples and the chatbot are not channels for restricted client information. File links and access rights should be checked when responsibilities change. Keep an authoritative source and an agreed revision history for issued work.
Supplier and offshore access
Before restricted work is shared with an external provider, confirm purpose, approved recipients, location restrictions, confidentiality obligations and return or deletion requirements. Technical and contractual safeguards need to match the information. We do not claim a universal data-residency guarantee or certification that has not been independently established.
Incident handling
Report suspected loss, wrong-recipient disclosure, compromised credentials or unauthorised changes promptly through Contact Us without reposting the sensitive material. We assess the affected information, contain the issue where possible and coordinate appropriate investigation and notification. Any mandatory notification is assessed under applicable law; this policy does not invent a fixed legal threshold.
Continuity and limitations
Keep agreed source and issued copies under the project’s retention arrangements. Recovery needs and timeframes should be specified for critical engagements. Hosted services may be unavailable and no system is perfectly secure. A continuity requirement must be agreed rather than inferred from a marketing statement.
For enquiries about this page, email info@cdx.net.au.