How client data is handled on every WebGx Pro engagement — automation, AI agents and assistants, integrations, forms, documents and SaaS builds. This page is written to be read by the person responsible for data in your organisation; if something you need is missing, ask and we will answer in writing.
Principles
- Your accounts, your data. Everything is built inside the tools and cloud accounts you own. We do not host client data on our own infrastructure and we do not keep copies once an engagement ends.
- Least privilege. Access is limited to the systems and records a workflow touches, granted by you, documented, and removable at any time. Shared logins are avoided; named accounts and API keys with scoped permissions are used instead.
- Minimise what reaches a model. AI steps receive only the fields they need. Personal data is redacted or replaced with references where the task allows. Model calls use business-tier APIs whose terms exclude training on customer data.
- A person for anything that matters. Irreversible, financial or customer-facing actions have a human approval step. Agents run with scopes, budgets and audit logs.
- Everything is logged. Every workflow keeps a run log — what came in, what was decided, what went out — in your environment.
Where data is processed
| Data | Where it lives | Who can see it |
|---|---|---|
| Your business records (CRM, orders, documents) | Your existing systems and cloud accounts | Your team; WebGx Pro only within the access you grant, for the duration of the work |
| Workflow run logs | Your automation platform (Make, Zapier, n8n) or your cloud account | Your team and named WebGx Pro engineers during support |
| Content sent to AI models | Anthropic / OpenAI / Google business APIs, or a model in your own cloud on request | Processed per the provider’s business terms; not used for training |
| Enquiries sent through this website | This site’s WordPress database (hosted in the EU by Hostinger) and the notification inbox | WebGx Pro only |
AI-specific safeguards
- Grounded assistants answer only from sources you control and say when they do not know.
- Guardrails are enforced in code, not only requested in prompts: topic limits, output checks, cost ceilings, mandatory hand-off situations.
- Agents have a written scope (tools and records), a budget per task and checkpoints for irreversible actions; every step is logged.
- Evaluation sets are kept for each assistant and agent so changes are tested before they go live.
- Where regulation or policy requires it, models can run inside your own cloud region.
Compliance posture
WebGx Pro is a small, independent practice rather than a certified enterprise vendor, and we say so plainly. We design to the requirements of the UK GDPR and EU GDPR, follow the principles of data minimisation and purpose limitation, sign your data-processing agreement and NDA before seeing any data, and document every data flow we build so that your own compliance review has what it needs. We will tell you when a requirement is outside what we can meet — for example, formal certifications — rather than imply otherwise.
Access, credentials and offboarding
- Access is requested in writing with the specific systems and permissions listed.
- Credentials are shared through your password manager or the platform’s own invitation; never by email or chat.
- At handover, access is reviewed and anything no longer needed is removed. On request we provide a list of every account we were granted.
- Support engagements use the same rules: scoped, named, logged and revocable.
Incidents
If we become aware of a security incident affecting your data or a system we built, we notify your named contact without undue delay, share what we know, and work with you on containment and remediation. Details of any incident are recorded and shared with you.
Questions
Send security or data questions through the contact page and mark them as such; they are answered by the engineer responsible for your work, in writing.