Document handling
Allowed file types, maximum size and accepted formats are shown at upload. Documents are stored in private storage with path-scoped access control, are used only for the service you requested, and are never publicly accessible. You can delete documents you uploaded unless they must be retained for a legal or dispute reason.
Access rules
| Who | Access | | --- | --- | | Customer | Own documents | | Selected consultant | Documents shared for that service | | Administrator | Limited, role-based, logged | | Other users | None | | Public | Never |
Retention (configurable)
Account information, bookings, payments, invoices, reviews, support tickets, uploaded documents, verification records, audit logs and marketing consent each have a defined retention period: [ADMIN CONFIGURATION REQUIRED]. Nothing is retained indefinitely without a legitimate purpose.
Processor register
Payment gateway, email provider, SMS provider, analytics, maps, cloud storage, authentication and customer support. Purpose, data shared and privacy link for each: [ADMIN CONFIGURATION REQUIRED].
Hosting
Primary hosting region, backup region and transfer mechanisms: [ADMIN CONFIGURATION REQUIRED].
Security
HTTPS, hashed credentials, role-based access control, session security, input and file validation, rate limiting, audit logging, encrypted secrets, database access controls, backups and monitoring.
Incident response
Security incidents are detected, classified, contained, investigated, documented, notified to the appropriate parties or authorities where legally required, remediated and closed.