Purpose limitation
Data is used only for the purpose defined in the engagement.
This page presents the operational principles used to frame an engagement. It does not claim to be a security certification.
Data is used only for the purpose defined in the engagement.
Only necessary data is requested and processed.
The transfer channel is agreed before sensitive data is exchanged; email is not assumed to be the default channel.
Access is limited to the people, scope and tools required.
No reuse for another client, marketing or model training without written authorization.
When Article 28 applies, roles, instructions, obligations and subprocessors are documented in writing.
Incident handling, contacts and notification duties are defined for the engagement context.
Retention, return and deletion are framed around the engagement and applicable obligations.
Depending on the data and engagement, safeguards may include encryption in transit, access control, environment separation, logging, backups and incident procedures. Applicable safeguards are documented before sensitive data is transferred.
When Pretoria BI processes personal data on behalf of a client, roles and instructions are documented in writing when required by the GDPR. CNIL guidance states that a written contract is mandatory when Article 28 applies.
External providers actually used — hosting, LLM, forms, storage or booking — must be listed before production and assessed against the data involved.
Pretoria BI is designed to confirm four points with the client: purpose and data categories, transfer channel, authorized people, then retention and deletion rules. Applicable safeguards are confirmed before the exchange, not after it.
Do not share passwords, API keys or sensitive data.