Collect less
Request only information necessary to assess, deliver, reconcile and support the approved workflow.
Data handling
We collect the minimum needed to determine fit, use controlled access during an approved project and design the finished workflow for client ownership.
Data principles
These are practical launch standards. Project-specific obligations are confirmed in the diagnostic, proposal and statement of work.
Request only information necessary to assess, deliver, reconcile and support the approved workflow.
Use client-controlled accounts, clear owners, access records and named approval points wherever practical.
Apply least privilege, MFA and time-bounded access appropriate to the approved task.
Reconcile source totals, dates, filters, formulas, exceptions and final release status.
Agree retention and deletion points rather than keeping raw samples or access indefinitely.
Stage-by-stage policy
The public website is designed to qualify a reporting problem without receiving the report itself. The fit-check form asks for a name, work email, organisation, report frequency, format, high-level input description, approximate production time, primary problem, sensitive-data screening answer and a non-confidential workflow summary.
Fit-check submissions may be sent by email to the business and saved in a protected server-side backup so an enquiry is not lost if email delivery is delayed. The configured retention period is documented in the website configuration and should be reviewed regularly.
After the fit check, a suitable prospect may purchase the Report Workflow Diagnostic. Before any current report or sample data is requested, Client Report Works confirms:
Health, student and highly sensitive personal information, and regulated tax, investment or clinical calculations, are outside the standard launch scope. A request may be declined or referred to a provider with the necessary specialist controls.
Where practical, work is carried out in accounts, folders or environments controlled by the client. Access should be:
Credentials should not be emailed in plain text. The agreed project method may use delegated access, a password manager, a client-created temporary account, a secure upload location or an equivalent controlled approach.
The technical method is chosen after the outcome and control requirements are understood. A workflow may use the client’s existing spreadsheet, document, presentation, dashboard, query or scripting tools.
The workflow identifies the source, reporting period, transformation rules, known exceptions, review owner and release status. Depending on the report, the QA checklist may cover:
Automation is not treated as proof of accuracy. The output is released only after the agreed checks and human approval are complete.
The proposal or statement of work should identify what is retained, where, by whom and until when. At handover:
A suspected loss, unauthorised access, incorrect disclosure or material integrity problem should be contained, recorded and assessed promptly. Relevant access may be disabled, affected material preserved for investigation, and the client notified in accordance with the engagement terms and applicable obligations. Client Report Works maintains a named contact for privacy and data-handling questions.
For a question about this data-handling approach, email privacy@clientreportworks.co.nz. For access or correction requests relating to website enquiry information, see the privacy statement.
Start without sharing the report
Do not upload or email confidential material until authority, scope and a controlled transfer method are agreed.