Your client's data, treated like it is yours. Because it is.
Agencies hand us logins, client names and campaign data. This page says exactly what happens to them — and what goes into the contract so you do not have to take our word for it.
- Before the briefMutual NDA
- CredentialsIn a shared vault only
- At handoverAccess revoked and confirmed
The rules we work to, written down.
Everything below is either already in the contract or can be, before a single credential changes hands.
Handing production to another company means handing over logins, client names, analytics and sometimes payment data. That is a real risk, and “trust us” is not an answer to it. So this page lists what actually happens: where credentials live, who can see them, what we keep after a project ends, and what we sign before it begins.
None of it is aspirational. If a practice is on this page, it is how the work runs today — and the clauses that back it are in the agency protection terms you sign once, not buried in a policy nobody reads.
- Mutual NDA first
- Signed before client names or systems are discussed.
- Vault, never email
- Credentials live in a shared vault with access we can revoke.
- Least access
- The role we need, on the systems we need, for as long as the work runs.
- Clean exit
- Access revoked and confirmed in writing at handover.
Eight things that are true on every project.
- 01
Mutual NDA before the brief
Our template or yours, signed before a client's name is shared. Available on request from the contact form.
- 02
Credentials in a shared vault only
1Password or Bitwarden shared vaults. Never in email, chat or documents. You can rotate or revoke at any time.
- 03
Least-privilege access
A scoped WordPress role, Shopify staff permissions or GA4 property access rather than owner logins. Admin only when the work needs it, and only for as long as it needs it.
- 04
Revoked and confirmed at handover
Our access is removed when the work is delivered, and we confirm the removal in writing with the handover document.
- 05
Encrypted devices, 2FA everywhere
Every workstation is disk-encrypted; every account we hold has two-factor authentication turned on.
- 06
Lawful transfers for EU and UK data
Bangladesh is not on the EU adequacy list. We work under Standard Contractual Clauses, the UK IDTA or Addendum, and an Article 28 data processing agreement.
- 07
Named sub-processors
Hosting, email and tooling providers that could touch client data are listed in the DPA. No surprises.
- 08
Staging that stays private
Staging sites are password-protected, set to noindex, and removed within 14 days of launch unless you ask otherwise.
Your client stays yours. In writing.
Most white-label sites mention an NDA once. These are the terms we work under on every project — the full text goes into your contract.
- §1
Your client stays yours
We will not approach, market to, quote for or accept work from your client — during the project or after it.
- §2
No credit, no footprint
No footer links, no watermarks, no 'built by' anywhere. Commit messages, staging domains and documents carry your brand.
- §3
Confidential by default
Mutual NDA on request before the brief. Credentials live in a shared vault, never in email, and are revoked and confirmed at handover.
- §4
You own the relationship
Strategy, communication, billing and the commercial relationship are yours. We handle production and execution.
- §5
Data handled lawfully
Bangladesh is not on the EU adequacy list, so we work under Standard Contractual Clauses, the UK IDTA and an Article 28 data processing agreement.
Want the NDA before you say anything else? Ask for it in the brief.
It arrives before any client detail is discussed.