Trust Centre

How we handle your data

We sell governance, so we publish ours. This page describes how client and enquiry data is handled during an engagement. It is written to be answerable in a procurement questionnaire.

What we collect during an engagement

  • Software inventory and deployment records
  • Entitlement documents, contracts and purchase records
  • User and device records needed for licence reconciliation
  • AI consumption and usage telemetry where in scope

We request the minimum needed for the position we are asked to produce, and will decline data outside that scope.

What we collect from this website

  • Enquiry form fields you complete
  • Limited technical metadata attached to the submission
  • No advertising or cross-site tracking cookies

Full detail is in the Privacy Policy.

Access control

  • Access limited to consultants assigned to your engagement
  • Least-privilege access, reviewed when engagement staffing changes
  • Access removed on engagement closure

Retention and deletion

  • Engagement data retained per the contracted retention period
  • Deletion or return of data on request at engagement close
  • Enquiry data deleted on request to enquiry@kriviksha.com

Subprocessors

  • Website hosting and email transmission providers
  • Cloud infrastructure for engagement workspaces
  • AI model providers, where AI-assisted analysis is in scope and agreed

A current named subprocessor list is available on request under NDA.

AI-assisted processing

  • Client data is not used to train general-purpose models
  • AI-assisted output is reviewed by a consultant before issue
  • Use of AI in your engagement is agreed in writing beforehand

See Responsible Technology.

Incident handling

If we become aware of an incident affecting your data, we will notify your named contact without undue delay, describe what is known and what is not, and agree remediation steps with you. Notification timelines applicable to your jurisdiction and contract take precedence over this summary.

What we do not claim

We do not currently hold ISO 27001, SOC 2 or equivalent third-party security certification, and we will not imply otherwise. Our SAM process work is aligned to ISO/IEC 19770-1, which is a software asset management standard, not a security certification.

If your procurement process requires certified controls, tell us early and we will be straight with you about what we can and cannot satisfy today.

Security or privacy questions

Send security questionnaires, DPA requests or privacy questions to enquiry@kriviksha.com. Mark them for the attention of the engagement lead if you already have one.