Data Processing Statement
How Trevisi Connect processes client-firm data during an engagement.
Roles
In respect of personal information that a client firm shares with us about its own enquiries and clients, the client firm is the responsible party and Trevisi Connect acts as an operator (processor) under POPIA, processing that information only on the firm's documented instructions.
Confidentiality and isolation
Each client firm's data is logically isolated. We never combine, share, or disclose one firm's enquiry, conversion, or client data with or to any other firm. Aggregated, fully de-identified benchmarking may be produced, but never in a form that identifies a firm or an individual.
Security safeguards
We apply access controls on a least-privilege basis, encryption in transit, and audit logging. Access to client data is restricted to personnel who require it to deliver the engagement.
Sub-processors and return of data
Where we use infrastructure sub-processors, we ensure appropriate contractual safeguards are in place. On termination of an engagement, all raw data is returned to the client firm and our copies are deleted within an agreed period.
Questions about data processing can be directed to grant@trevisiconnect.co.za.