LEGAL

Data Policy

LAST UPDATED: 2026-07-20

THIS POLICY HAS NOT YET BEEN REVIEWED BY AN ATTORNEY. IT DESCRIBES CURRENT ENGINEERING PRACTICE FOR CLIENT ENGAGEMENTS.

Account ownership

Client systems are deployed on client-controlled accounts whenever practical — the client's hosting, automation, database, and broker accounts. The client is the owner of record; Sovereign-Minds works inside accounts the client can lock us out of at any time. This is the point of the model, not an inconvenience.

Credential handling

Client data segregation

Each client's data lives in that client's own infrastructure. We do not pool client data into shared databases, and we do not use one client's business data for another client's benefit.

Retention

During an engagement we retain working copies of configurations and documentation needed to deliver. After handover, we retain the engagement's documentation set and correspondence for support purposes for up to 24 months unless the client requests earlier deletion.

Export and deletion

Client data is exportable — deliverables include the data model and documented export paths so nothing is trapped. On written request, we delete our working copies of client materials within 30 days, subject to legal retention obligations.

Subcontractors

Engagements are delivered by Sovereign-Minds directly. If a subcontractor is ever engaged for part of a build, the client is informed first, and the subcontractor is bound to equivalent confidentiality obligations.

Incident response

If we become aware of a security incident affecting a client system or client data, we notify the affected client promptly with what is known, what has been contained, and recommended next steps — and we document the incident and remediation.

Handover process

Every completed build hands over: an architecture diagram, a runbook, the credential map, documented data flows, a rollback plan, and a recorded walkthrough. From that point the client can operate, modify, or replace the system without us.