01 — Overview

A professional obligation, not a compliance exercise

Ori is a solo project management consultancy. This statement describes how I collect, handle, protect, and dispose of client data and personal information across all consulting, coaching, and training engagements.

I apply practical, right-sized controls appropriate for a solo practitioner working with project teams, organizational data, and individual coaching clients. This page is a working record of those practices — updated whenever something material changes.

02 — Scope

What data I may work with

Depending on the nature of the engagement, I may receive or work with:

  • Project documentation, schedules, risk registers, and status reports
  • Organizational charts, team structures, and role information
  • Internal process documents, governance materials, or strategic plans
  • Personal contact details for scheduling and communication purposes
  • Assessment or coaching notes related to individual professional development
  • Financial or performance data provided for project analysis

I collect only what is necessary for the engagement. I do not seek or retain data beyond the scope of agreed work.

03 — Controls

How I protect your data

These controls are active across all client engagements, not applied selectively.

Device security

Full-disk encryption on all devices used for client work. Password-protected with short screen-lock timeouts.

Credentials

All account credentials managed via NordPass with unique, strong passwords and MFA on every business account.

Network security

NordVPN active on all public or unsecured networks. Threat protection blocks malicious sites and downloads.

Cloud storage

Client files stored in Google Workspace, encrypted at rest and in transit, in clearly labeled per-client folders.

Email

All client communication via ben@findyourori.com on Google Workspace. Sensitive documents moved to Drive promptly.

Breach monitoring

Active monitoring for credential exposure in known data breaches via NordPass's breach scanner.

04 — AI Tools

My policy on AI tools

I use AI tools to support my work. Enterprise clients increasingly ask about this — here is my practice in plain terms:

  • Client-identifiable data is never input into consumer AI tools without explicit written consent
  • Where AI tools are used, only anonymized or aggregated information is included
  • Client-specific AI restrictions are accommodated on request and documented in the engagement agreement

If your organization has an AI usage policy for vendors, I will review it before the engagement begins and confirm compliance in writing.

05 — Retention

How long I keep data

I retain client data only as long as necessary to deliver the engagement, fulfill post-engagement obligations, and meet applicable legal requirements.

  • Active engagement files: retained for the engagement duration plus 90 days
  • Final deliverables and engagement records: up to 3 years for professional and legal reference
  • Data is securely deleted on request or at engagement close — not just moved to trash
  • Any published case study material is fully anonymized, with all identifying details removed before use
06 — Confidentiality

How I treat client information

All client information is treated as confidential by default — formal NDA or not. I do not disclose, share, or reference client-identifiable information without explicit permission.

All engagements are conducted under a confidentiality agreement. A mutual NDA is standard; client-provided templates are welcome.

Any articles, workshop materials, or case studies that draw on real engagement experience are anonymized to remove organizational identifiers, individual names, and any detail that could reasonably identify the client or situation.

07 — Subprocessors

Third-party tools that may process your data

The following tools are used in the course of client work. I do not sell, license, or share client data with any third party for marketing or commercial purposes.

Google Workspace
Email and document storage. Google LLC, United States.
NordPass
Credential management. Nord Security, Lithuania / Panama.
NordVPN
Network security and threat protection. Nord Security.
Scheduling tools
Calendar and meeting coordination. No client project data is shared.
08 — Incidents

What happens if something goes wrong

In the event of a confirmed data security incident affecting client information, I will notify the affected client within 72 hours of becoming aware — consistent with California law (CCPA) and professional best practice.

That notification will include a clear account of what data was affected, the likely cause, and the steps taken to contain and remediate the incident. I will cooperate fully with any reasonable client investigation or response requirements.

09 — Your rights

What you can ask of me

Regarding any data I hold about you or your organization, you may request:

  • A summary of what data I hold and how it is being used
  • Correction of any inaccurate information
  • Deletion of your data, subject to any legal retention requirements
  • Withdrawal of consent for any processing based on consent

To exercise any of these rights, contact me directly at ben@findyourori.com.

10 — Contact

Questions about this statement

If you have questions about this statement or my data handling practices, or if you'd like to discuss specific requirements for your engagement, please reach out.

Name Ben Ori
Business Ori — findyourori.com
Location Monterey, California, USA
Download full statement (PDF)