Initial enquiry boundary
Initial forms collect project context, not project files. Do not submit credentials, private keys, identity documents, health information, criminal offence data, payment details, production exports or confidential source code through these forms.
Discovery and classification
Before receiving project data, NORYVIA and the client should identify data categories, sensitivity, ownership, purpose, location, access needs and retention. Higher-risk material may require additional contractual, security and technical controls.
Client authority
The client is responsible for ensuring it has authority and a lawful basis to provide data, content, systems and access. Test or minimised data should be used where practical. The client must not disclose more information than the agreed work requires.
Secure transfer and access
Where files or system access are necessary, the parties agree an appropriate route. Access should be least-privilege, time-bounded where possible, individually attributable and removed when no longer required. Secrets should not be embedded in ordinary email or project documents.
Use, segregation and suppliers
Project data is used only for agreed purposes. Hosting, collaboration or specialist suppliers are assessed according to the project context, and relevant locations or subprocessors are addressed in contractual documents where NORYVIA acts as processor.
Retention and deletion
Working data should be retained only for the period needed for delivery, support, legal obligations or claims. Project-specific return, export, deletion and backup treatment should be recorded in the agreement or handover notes.
Incidents
Suspected loss, unauthorised access or disclosure should be reported promptly through the agreed contact route. NORYVIA will investigate within its role, preserve relevant evidence, mitigate where possible and support applicable notification decisions.
Questions
Discuss data requirements before sharing material by contacting support@noryviasoftware.tech.