Direct answer
We ask for identity and company documents only when a specific step needs them, through a channel agreed with you; we never ask for passwords or payment card details through website forms.
Scope
This policy covers personal and company data INCORPSYS handles when you enquire or engage our services, including documents such as passports, company records and proof of address. It works alongside the Privacy Policy.
Data minimisation
- We collect only what an authority, bank or service step actually requires.
- Website forms do not accept document uploads.
- We separate what an authority requires from what a service provider or bank asks for, so you know why each item is needed.
How documents are shared
Documents are exchanged through a channel agreed with you for each engagement: [To be confirmed: approved secure channel(s), e.g. encrypted email or client portal]. Never send passwords or payment card details.
Security
- Access is limited to team members working on your engagement.
- The website uses a strict Content-Security-Policy and does not store enquiry data in a public database.
- Security controls for stored client files: [To be confirmed: storage and access controls].
Transfers to authorities and partners
Filings require us to submit information to the competent authority in the jurisdiction you choose. Where a local professional or partner is involved, we tell you before sharing your information.
Retention and deletion
Client files are kept for [To be confirmed: retention period] after an engagement ends, unless the law requires longer, then securely deleted. You can request deletion earlier where the law allows. Contact INCORPSYS through the Contact page or email hello@incorpsys.com.
Data incidents
If we become aware of a security incident affecting your data, we will inform you without undue delay and explain the steps taken.
