Data, security, and control
Professional firms and regulated businesses hold sensitive information about their own affairs and their clients. Everything we build is designed on the footing that every record is confidential, every action is attributable, and nothing is kept longer than the client requires.
Controls
Where data is held
Client data will be stored with a major cloud infrastructure provider in the region set out in each client's agreement. The standard region is Australia for Australian clients and Hong Kong for clients in Hong Kong, and data will be encrypted in transit and at rest.
Model processing
AI models will run in the client's region where one is available, which for Australian clients is Australia. Clients in Hong Kong will have an in-region option through open-weight models hosted in Hong Kong. A model hosted outside the client's region will be used only where the client opts in. The regions in which such a model may process data will be stated in the client's agreement.
No training on client data
Client data will not be used to train models, and we will use model services only on terms that exclude the use of submitted content for training.
Access
Access will be by named account only, with multi-factor authentication and role-based permissions. Every record will be scoped on the server to the permissions of the authenticated user. A record that a user is not entitled to see will be reported as not found, because confirming that a record exists is itself a disclosure.
Our staff will access client content only when the client asks or an implementation or professional services engagement needs it, and every such access will be logged.
Logging
Operational logs will record identifiers, counts, and timings, and they will not record document content.
Engineering partners
Engineering partners will work on code and test data, and they will not receive access to client data in production. Accounts with model providers will be held by ZCM.
Websites we host
Websites we host will be served only over HTTPS with security headers, backed up regularly, monitored for availability, and kept up to date with security updates.
Retention and deletion
Retention will follow each client's settings. At the end of a service, the client will have a period to export its data. The data will then be deleted, including from backups, within the periods set out in its agreement.
Breach notification
Our standard terms require us to notify a client of a data breach affecting its data within 72 hours.
Privacy law
We operate under Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486). We also take account of the guidance on artificial intelligence issued by the Office of the Privacy Commissioner for Personal Data. Our terms are designed to support our clients' obligations under the privacy laws that apply to them, including Australia's Privacy Act 1988 (Cth).
Independent assurance
Independent security review forms part of our roadmap before general release, and a summary of its results will be published on this page.
Talk to us about what you need
We meet clients and business partners by video conference or in person in Hong Kong.