Engagement data controls

The data boundary is agreed before work begins.

Each engagement will start with a written record of access, tools and providers, retention, and exit. Aran will not use client data to train models.

Minimum access · named providers · agreed exit

Before connection
Minimum access agreed
Client data
Not used to train models
At exit
Export and deletion documented

Before connection

Write down what the work needs, then limit access to that.

Aran and the client will agree the boundary before a tool is connected or client data is handled.

  1. 01 / access Scope the minimum access

    The engagement document will name the smallest set of systems, records, fields, and actions needed for the agreed work.

  2. 02 / providers Name tools and providers

    The document will list the tools, model providers, storage services, and other third parties involved in handling the work.

  3. 03 / purpose Record the permitted use

    Client data will be used only for the agreed engagement. Aran will not use it to train models.

  4. 04 / owner Assign review and decisions

    The scope will identify who can approve access, review output, handle exceptions, and authorise consequential actions.

During the engagement

Retention follows the needs of the agreed work.

Retention terms will be specific to each engagement. Aran and the client will agree which records are kept, why they are needed, and how long they are retained.

The written scope will cover

  • Which client data and working records are involved.
  • Which named tools and providers handle them.
  • How long each relevant record is retained.
  • Who can review or approve changes to the scope.

The engagement boundary

  • Client data will not be used to train models.
  • Access will stay within the agreed systems and actions.
  • Provider changes will be documented before use.
  • Client material will stay within the engagement's permitted use.

Export, deletion, and exit

The closeout plan is part of the agreement.

Before work begins, the written terms will state what can be exported, what will be deleted, who receives the handoff, and when access ends.

Document the handoff

  • Records and materials included in the export.
  • The agreed export format and recipient.
  • Open issues that need a client decision.
  • The point at which the engagement closes.

Document the shutdown

  • Access that will be revoked or returned.
  • Records that will be deleted and the agreed timing.
  • Records retained under the written terms.
  • Any separate agreement needed for continuing work.

This page sets a process baseline for Aran engagements. The engagement agreement will record the specific controls. For the public website, read the privacy policy.

Related detail

Start with the workflow and the data it touches.

Book an introductory call