A professional obligation, not a compliance exercise
Ori is a solo project management consultancy. This statement describes how I collect, handle, protect, and dispose of client data and personal information across all consulting, coaching, and training engagements.
I apply practical, right-sized controls appropriate for a solo practitioner working with project teams, organizational data, and individual coaching clients. This page is a working record of those practices — updated whenever something material changes.
What data I may work with
Depending on the nature of the engagement, I may receive or work with:
- Project documentation, schedules, risk registers, and status reports
- Organizational charts, team structures, and role information
- Internal process documents, governance materials, or strategic plans
- Personal contact details for scheduling and communication purposes
- Assessment or coaching notes related to individual professional development
- Financial or performance data provided for project analysis
I collect only what is necessary for the engagement. I do not seek or retain data beyond the scope of agreed work.
How I protect your data
These controls are active across all client engagements, not applied selectively.
Full-disk encryption on all devices used for client work. Password-protected with short screen-lock timeouts.
All account credentials managed via NordPass with unique, strong passwords and MFA on every business account.
NordVPN active on all public or unsecured networks. Threat protection blocks malicious sites and downloads.
Client files stored in Google Workspace, encrypted at rest and in transit, in clearly labeled per-client folders.
All client communication via ben@findyourori.com on Google Workspace. Sensitive documents moved to Drive promptly.
Active monitoring for credential exposure in known data breaches via NordPass's breach scanner.
My policy on AI tools
I use AI tools to support my work. Enterprise clients increasingly ask about this — here is my practice in plain terms:
- Client-identifiable data is never input into consumer AI tools without explicit written consent
- Where AI tools are used, only anonymized or aggregated information is included
- Client-specific AI restrictions are accommodated on request and documented in the engagement agreement
If your organization has an AI usage policy for vendors, I will review it before the engagement begins and confirm compliance in writing.
How long I keep data
I retain client data only as long as necessary to deliver the engagement, fulfill post-engagement obligations, and meet applicable legal requirements.
- Active engagement files: retained for the engagement duration plus 90 days
- Final deliverables and engagement records: up to 3 years for professional and legal reference
- Data is securely deleted on request or at engagement close — not just moved to trash
- Any published case study material is fully anonymized, with all identifying details removed before use
How I treat client information
All client information is treated as confidential by default — formal NDA or not. I do not disclose, share, or reference client-identifiable information without explicit permission.
All engagements are conducted under a confidentiality agreement. A mutual NDA is standard; client-provided templates are welcome.
Any articles, workshop materials, or case studies that draw on real engagement experience are anonymized to remove organizational identifiers, individual names, and any detail that could reasonably identify the client or situation.
Third-party tools that may process your data
The following tools are used in the course of client work. I do not sell, license, or share client data with any third party for marketing or commercial purposes.
What happens if something goes wrong
In the event of a confirmed data security incident affecting client information, I will notify the affected client within 72 hours of becoming aware — consistent with California law (CCPA) and professional best practice.
That notification will include a clear account of what data was affected, the likely cause, and the steps taken to contain and remediate the incident. I will cooperate fully with any reasonable client investigation or response requirements.
What you can ask of me
Regarding any data I hold about you or your organization, you may request:
- A summary of what data I hold and how it is being used
- Correction of any inaccurate information
- Deletion of your data, subject to any legal retention requirements
- Withdrawal of consent for any processing based on consent
To exercise any of these rights, contact me directly at ben@findyourori.com.
Questions about this statement
If you have questions about this statement or my data handling practices, or if you'd like to discuss specific requirements for your engagement, please reach out.