How we handle your data.
Consulting firm = access to sensitive information. Here is exactly what we commit to — and what we don’t do.
- CONFIDENTIALITY
NDA available before any detailed scoping
Standard FR/EN NDA template signed within 24 h. Clear framing on duration, scope, sub-processors, data return at engagement end.
- CLIENT DATA
EU residency, limited retention period
All data exchanged during an engagement is stored in the EU (Belgium, France, Germany depending on service). Deleted on request, default 90-day erasure after engagement end.
- GDPR
Documented sub-processors, DPA available
Up-to-date list of technical sub-processors used by MACC available on request. Standard Data Processing Agreement (DPA) provided before any personal data handling.
- OPERATIONAL SECURITY
Hardened firm, MFA, no third-party access
Hardened workstations (FDE, EDR, MFA), enterprise password manager, no third-party access to your data (single consultant per engagement).
- ENCRYPTED COMMUNICATION
Signal · ProtonMail · OpenPGP available
For sensitive engagements, end-to-end encrypted communication on request. Public OpenPGP keys published in security.txt.
- RESPONSIBLE DISCLOSURE
Public policy in security.txt
Found a vulnerability in this site or our services? Report via security.txt. Reply within 48 working hours, fix before public disclosure.
Question about our policies?
We answer procurement, compliance and CISO questions within 48 working hours.
Book a meeting