Legal

Data Processing Information

How client data is handled during engagements and inside the application: roles, sub-processors, security measures and responsibilities.

Scope

During engagements we typically access client systems (analytics, Search Console, CMS, Google Business Profile) containing limited personal data such as reviewer names or enquiry records. For that data we act as a processor on the client’s documented instructions under a data processing agreement issued with every service contract.

The HighRegard application

Where a client’s workspace connects Google Ads, Search Console or Google Analytics 4, we process the resulting performance data as a processor on the client’s instructions, expressed by the act of connecting a source. Access is read-only and revocable by the client at any time from the workspace or from their Google account permissions. Connection tokens are encrypted per workspace with keys held separately from the database. The application is designed to hold aggregate figures rather than customer-level records; rows matching personal-data patterns are dropped before storage. Tokens are deleted immediately on disconnection; stored facts are deleted when the workspace is closed, or sooner on the client’s instruction.

Sub-processors

Current sub-processors: HubSpot (CRM), Make (automation), Resend (email, including application sign-in links), Stripe (payments), Vercel (website and application hosting), Neon (application database, managed PostgreSQL), Google (Ads, Search Console and Analytics APIs read at the client’s instruction), Anthropic (AI processing for the Live AI Visibility Test and for the application’s written assessment, which receives aggregate metrics only), and Google Workspace (business systems). Clients are notified of sub-processor changes in advance through the mechanism in the DPA.

Security measures

Access by invitation rather than shared passwords; multi-factor authentication on all business systems; a password manager with per-client vaults; least-privilege access; encrypted devices; documented offboarding that revokes access at engagement end.

Client responsibilities

Clients remain controllers of their customer data and are responsible for the lawfulness of their own marketing lists and review practices. We will decline instructions that would breach data protection law — for example, scraping personal data or fabricating reviews.

The other documents

Everything that governs this website and the application, in one place.