Responsibility boundaries
Security, deployment, and legal boundaries
Security controls, deployment topology, third-party dependencies, and legal responsibilities must be confirmed per project. This page states principles and boundaries, not certifications or guarantees.
Boundary register
Security scope
Controls are selected from the project's data, identity, permission, logging, provider, and threat conditions. This page does not claim certification, a passed audit, or universal compliance.
Deployment responsibility
Hosting ownership, environments, backups, recovery objectives, monitoring, updates, and service levels are scoped per project. A published template is not a guarantee of availability.
Third-party dependencies
Model, cloud, identity, analytics, email, and publishing services remain subject to their own terms, configuration, quota, and availability. Failure and fallback paths must be defined per project.
Legal and commercial terms
Intellectual property, data responsibility, confidentiality, support, fees, and termination are governed by signed agreements. This page describes scope and is not legal advice.
Privacy requests
Form data and request path
These principles apply to the Start Project form and related communication. Project-specific data responsibilities remain subject to the applicable agreement.
- 01
Lead-form purpose
Information in the Start Project form is used to assess project fit and respond to the submitted request, and to prepare follow-up communication. Submitting the form does not create a contract.
- 02
Data minimization
We ask for only the information needed to assess project fit and respond, and optional fields remain clearly marked. Do not submit sensitive information unrelated to the project.
- 03
Retention principle
Information is retained only as long as needed to handle the request and applicable contractual or legal obligations. This page does not invent a universal retention duration.
- 04
Third-party processor disclosure
If hosting, form, email, or analytics services act as third-party processors, the applicable categories, purposes, and responsibilities should be disclosed for the relevant service or project. This page does not claim every processor is always used.
- 05
Access, correction, and deletion requests
Use the privacy and security request path below to request access, correction, or deletion. Requests are assessed against verifiable identity and applicable contractual or legal obligations; unconditional deletion is not promised.
For a privacy or security question, use the same controlled form and describe the request. This site does not publish an unverified email address or office address.
Submit a privacy or security requestStart from the current problem and first decision
Start Project