Trust & Security
Data Protection & Security
Trust is not only something we assess in data. It also shapes how REMAVELLE handles information and operates its digital services.
1. Data minimisation
We seek to collect and retain only the information reasonably required for our website, enquiries, advisory engagements, security and legitimate business operations. We do not request confidential datasets, production records or unnecessary sensitive personal data through this website.
2. Security by design
REMAVELLE applies technical and organizational measures proportionate to our operations and the data we manage. Evidenced technical controls across our digital stack include:
- Encrypted Transport: All website traffic is encrypted in transit using modern HTTPS / TLS protocols.
- Server-Side Secret Management: Database credentials, API keys, and sensitive environment variables are isolated server-side and never exposed to client browsers.
- Input Validation & Parameterised Queries: Form inputs are sanitized server-side and database queries use parameterised statements to eliminate injection risks.
- Isolated Persistence: Database access is restricted to secure server environments; raw database instances are never exposed publicly without access controls.
- Anti-Abuse Controls: Inbound form routes use server-side rate limiting and Cloudflare Turnstile bot verification to prevent brute-force attacks and spam.
- Security Headers: Production HTTP response headers enforce HSTS, strict Content-Security-Policy (CSP), Referrer-Policy, and frame protections.
3. Access and confidentiality
Access to submitted enquiry information and client communication records is strictly limited to authorized advisory personnel according to operational need. We treat all business context provided by prospective clients as confidential.
4. Service providers & infrastructure
REMAVELLE uses vetted technology providers to support hosting, managed database storage, transactional email delivery, and bot protection. We evaluate relevant privacy and security capabilities and require appropriate contractual protections appropriate to the services provided.
5. Data location and transfers
Our core database infrastructure is hosted in secure managed facilities. Where service providers process or transfer data across international boundaries, we ensure appropriate transfer mechanisms (such as UK adequacy decisions or Standard Contractual Clauses) are in place where required.
6. Incident management
Suspected information-security or personal-data incidents are assessed, contained and investigated promptly. Where legal notification obligations arise under data protection laws, REMAVELLE will notify affected parties and regulatory authorities as required by law.
7. Responsible AI and data practice
REMAVELLE’s advisory work is built around data quality, data governance, control, and responsible AI readiness. We do not treat automated AI tools as a substitute for human accountability, rigorous data governance, or information security.
8. Questions and contact
If you have questions regarding our data protection or security practices, contact us at advisory@remavelle.com.
Last updated: August 2026.