We work inside your systems. Here is how that is controlled.
A managed operations partner touches invoices, payment details, vendor records, member and customer data, contracts and accounting systems. The controls below are agreed before work begins and form part of every engagement.
You remain the controller. We act as processor.
Where FINDELIAN processes personal data on your instruction, you determine the purposes and means of that processing and remain the data controller. FINDELIAN acts as a processor and processes personal data only on documented instructions. A Data Processing Agreement setting this out is available on request and is executed before processing begins.
What is in place, and where it applies.
Access control
- Least-privilege access — each professional receives only the permissions their assigned scope requires.
- Access granted per role, reviewed during the engagement and revoked at offboarding or reassignment.
- Approval limits and permitted actions agreed in writing before work begins.
Authentication & devices
- Multi-factor authentication on client systems wherever the client platform supports it.
- Managed password practice — no shared credentials between team members.
- VPN and secure file-handling procedures where the engagement requires them.
People
- Confidentiality agreements signed before any client system access is issued.
- Documented onboarding with a security briefing tied to the assigned scope.
- Offboarding checklist covering credential revocation and device handover.
Data handling
- Work is performed inside client-owned environments wherever the engagement allows, so client data stays under client control.
- Retention and deletion periods agreed per engagement; client data is returned or deleted on termination as instructed.
- Activity records maintained for the work we perform, with exceptions logged and escalated.
Incidents & continuity
- Defined escalation path and named contact for suspected incidents.
- Client notified without undue delay where an incident affects client data.
- Documented procedures and planned handovers so delivery continues when people or volumes change.
GDPR position
- For client personal data processed on instruction, FINDELIAN acts as a processor and the client remains the controller.
- A Data Processing Agreement is available on request and is executed before processing begins.
- Sub-processors are disclosed on request; none are engaged for a client scope without the client’s agreement.
- Where personal data leaves the EEA, transfers are handled under an appropriate transfer mechanism agreed in the DPA.
What we control, and what we do not.
FINDELIAN maintains activity records for the work we perform and operates within the permissions and approval limits agreed with you. Audit and logging capability inside your own platforms remains a function of those platforms and your configuration of them — we work to whatever record-keeping your systems support, and we will tell you where a system does not support the level of traceability a scope requires.
Security is treated as an engagement-level matter: the specific controls, retention periods, permitted actions and escalation contacts are set out for your scope during process mapping and before any system access is issued.
Reviewing us as a supplier?
We are used to security questionnaires and vendor due diligence. A Data Processing Agreement, an access-control summary and our confidentiality terms are available on request — usually before you commit to a discovery call.