Trust
Security & Data Handling
Last updated: 1 September 2026
What This Page Is For
If you're considering a Revenue Leak Audit, you need to know how your data is handled. This page explains our security posture in plain language — no corporate jargon, no false promises.
What We Do
- Run the entire site over HTTPS (TLS 1.3 via Vercel)
- Store minimal data — only what you voluntarily provide
- Delete client data after 24 months of inactivity (or sooner on request)
- Use GDPR-compliant processors with Standard Contractual Clauses where needed
- Treat all client information as confidential by default
What We Don't Do
- Store credit card or payment details on this site
- Sell, rent, or share your data with third parties for marketing
- Use your CRM data, sales figures, or process details for anything other than the agreed audit
- Train AI models on your proprietary data without explicit written consent
- Claim ISO 27001 certification (we don't have it — see below)
How Audit Data Is Handled
During a Revenue Leak Audit, you may share sensitive information: CRM exports, sales process documentation, pipeline data, or customer communication samples. Here's how that works:
- Scope: Data is used only for the specific audit engagement
- Storage: Kept in encrypted cloud storage (Google Workspace) with 2FA access control
- Retention: Deleted 90 days after final deliverable is accepted, unless you request earlier deletion
- Sharing: Not shared with any third party unless you explicitly authorise it (e.g., a case study)
- Anonymisation: Where possible, customer names and contact details are redacted in analysis
Third-Party Services
We use a small number of services to run the business. Each has its own security posture:
- Vercel — Hosting and form handling (SOC 2 Type II, GDPR-compliant)
- Google Workspace — Email and document storage (ISO 27001 certified)
- Calendly — Meeting scheduling (SOC 2 Type II)
- Formspree — Form submission backup (TLS encryption, no data retention)
- ConvertKit — Email marketing (GDPR-compliant, EU data processing)
On ISO 27001
We do not hold ISO 27001 certification. For a solo consulting operation, the cost and time to certify (typically £15K–£50K and 6–12 months) is disproportionate to the risk profile.
If your procurement process requires ISO 27001, we can discuss a tailored data handling agreement or refer you to an accredited partner. For most Irish and UK B2B companies at this stage, our practical security measures and clear data handling policy are sufficient.
Reporting a Security Issue
Found something? Email colin@colinmiley.com with "Security Issue" in the subject line. We respond within 48 hours and treat all reports confidentially.
Questions?
If you need a Data Processing Agreement (DPA) for a specific engagement, or want to discuss security requirements before signing, just ask: colin@colinmiley.com.