Data security
Financial data is a company’s most sensitive asset. This page describes how we handle it.
Effective from: [KUUPÄEV] · Version 1.0
1. Principle
We process only the data needed to do the work, only for as long as needed, and keep it separate from everything else. If a set of data is not needed for the work, please do not send it.
2. Transferring data
- Data is transferred over an encrypted channel (TLS) or as an encrypted file.
- For larger volumes we provide a separate secure upload link. Please do not send financial data as an ordinary email attachment.
- Passwords and access credentials are sent over a separate channel, not in the same message as the file.
- We never ask for your online-banking passwords, PIN codes or ID-card codes.
3. Storage and access
- Client data is kept in an isolated working environment, separated from general day-to-day work.
- Storage media are encrypted (full-disk encryption).
- Access is limited to those working on the specific engagement. Access rights are reviewed at the start and end of each engagement.
- All accounts use two-factor authentication.
- Data is not copied to personal devices or personal cloud services.
4. Access to your systems
Where the work requires access to your accounting software or bank statements, we:
- prefer read-only access and the smallest necessary set of rights;
- use a named user account, not a shared one, so that actions are traceable;
- end access when the work is complete, and ask you to close it from your side too.
5. Use of artificial intelligence
We use AI as a supporting tool — for example to help review data, draft documents and summarise information. It assists the work; it does not replace professional judgement. A qualified person reviews, and is responsible for, every conclusion and recommendation we give.
Where AI is involved, it runs inside enterprise-grade software provided under business terms — principally Microsoft 365 and Microsoft Copilot. Under those terms:
- your data is not used to train the provider’s AI models, and it stays within our own tenant;
- it is processed under a data-processing agreement, within the European Economic Area;
- identifiable client financial data is never entered into public or consumer-version AI tools;
- where practical, identifying details are removed or replaced before analysis.
6. Sub-processors and providers
We use a limited number of providers (productivity, cloud storage and email — principally Microsoft 365 — a booking environment, and accounting software). A data-processing agreement is in place with each, and data is processed preferably within the European Economic Area. We provide the current list of sub-processors on request.
7. Confidentiality
All information received during the service is confidential. The confidentiality obligation applies indefinitely, including after the engagement ends. On request we sign a separate confidentiality agreement before data is shared — one email is enough.
8. Return and deletion of data
When the work ends, we return or delete client data within 90 days at the latest, unless otherwise agreed in writing. The exception is documents whose retention is required by law (for example, accounting source documents). On request we provide written confirmation of deletion.
9. Breach notification
If a personal-data breach occurs, we notify the affected client without undue delay and in any case within 72 hours of becoming aware of the breach. The notice includes a description of the breach, the categories of data affected, the likely consequences and the measures taken.
10. Limitations
No security measure is absolute. We describe here our actual working practice, not a guarantee. If your company has stricter requirements — for example a specific data location, working in your own environment, or an additional audit — we agree these separately before the work begins.
11. Questions
Send data-security questions to info@i-consult.ee. We respond within one business day.
