Security & data handling

How client data is handled on every WebGx Pro engagement — automation, AI agents and assistants, integrations, forms, documents and SaaS builds. This page is written to be read by the person responsible for data in your organisation; if something you need is missing, ask and we will answer in writing.

Principles

  • Your accounts, your data. Everything is built inside the tools and cloud accounts you own. We do not host client data on our own infrastructure and we do not keep copies once an engagement ends.
  • Least privilege. Access is limited to the systems and records a workflow touches, granted by you, documented, and removable at any time. Shared logins are avoided; named accounts and API keys with scoped permissions are used instead.
  • Minimise what reaches a model. AI steps receive only the fields they need. Personal data is redacted or replaced with references where the task allows. Model calls use business-tier APIs whose terms exclude training on customer data.
  • A person for anything that matters. Irreversible, financial or customer-facing actions have a human approval step. Agents run with scopes, budgets and audit logs.
  • Everything is logged. Every workflow keeps a run log — what came in, what was decided, what went out — in your environment.

Where data is processed

DataWhere it livesWho can see it
Your business records (CRM, orders, documents)Your existing systems and cloud accountsYour team; WebGx Pro only within the access you grant, for the duration of the work
Workflow run logsYour automation platform (Make, Zapier, n8n) or your cloud accountYour team and named WebGx Pro engineers during support
Content sent to AI modelsAnthropic / OpenAI / Google business APIs, or a model in your own cloud on requestProcessed per the provider’s business terms; not used for training
Enquiries sent through this websiteThis site’s WordPress database (hosted in the EU by Hostinger) and the notification inboxWebGx Pro only

AI-specific safeguards

  • Grounded assistants answer only from sources you control and say when they do not know.
  • Guardrails are enforced in code, not only requested in prompts: topic limits, output checks, cost ceilings, mandatory hand-off situations.
  • Agents have a written scope (tools and records), a budget per task and checkpoints for irreversible actions; every step is logged.
  • Evaluation sets are kept for each assistant and agent so changes are tested before they go live.
  • Where regulation or policy requires it, models can run inside your own cloud region.

Compliance posture

WebGx Pro is a small, independent practice rather than a certified enterprise vendor, and we say so plainly. We design to the requirements of the UK GDPR and EU GDPR, follow the principles of data minimisation and purpose limitation, sign your data-processing agreement and NDA before seeing any data, and document every data flow we build so that your own compliance review has what it needs. We will tell you when a requirement is outside what we can meet — for example, formal certifications — rather than imply otherwise.

Access, credentials and offboarding

  • Access is requested in writing with the specific systems and permissions listed.
  • Credentials are shared through your password manager or the platform’s own invitation; never by email or chat.
  • At handover, access is reviewed and anything no longer needed is removed. On request we provide a list of every account we were granted.
  • Support engagements use the same rules: scoped, named, logged and revocable.

Incidents

If we become aware of a security incident affecting your data or a system we built, we notify your named contact without undue delay, share what we know, and work with you on containment and remediation. Details of any incident are recorded and shared with you.

Questions

Send security or data questions through the contact page and mark them as such; they are answered by the engineer responsible for your work, in writing.