1. Before engagement
The open enquiry and WhatsApp routes are for a summary of the problem, not full research files, patient information or restricted data. We first confirm fit, authorised contacts and the transfer route. A mutual NDA can be considered before substantive disclosure.
2. Need-to-know access
Only personnel assigned to the engagement may access its material. A five-person core delivery team coordinates work from a wider specialist network; not every team member receives every file. Specialist access is limited to the minimum material needed for the stated task.
3. Secure transfer and storage
Approved workspaces use encrypted transport, controlled links, access expiry, role-based permissions and activity records. Email attachments and consumer messaging are avoided for high-risk files when a secure workspace is available. Malware and file-type checks may be applied before storage.
4. Restricted material
Do not send identifiable patient information, examination material, institutional secrets, export-controlled information, unlawfully obtained datasets or third-party confidential material without written authority and an agreed handling plan. We may require de-identification or decline the material.
5. Team obligations
Employees, specialists and processors are bound by confidentiality and acceptable-use duties. They may not reuse client content for teaching, training, portfolios, demonstrations, publications or other clients without explicit written permission.
6. Public proof and testimonials
No thesis, manuscript, DOI, identity, testimonial, outcome or before-and-after example is published merely because we supported it. Separate, specific and revocable consent is required. Consent to service is not consent to publicity.
7. Retention and deletion
Working files are normally retained for 180 days after the milestone closes to support agreed review, then removed from active systems unless the service schedule, law or dispute requires otherwise. Backup deletion follows the backup cycle. You may request earlier deletion where no legal or contractual need prevents it.
8. Necessary disclosure
Information may be disclosed where required by law, court order, tax duty, security investigation or defence of legal claims. Where lawful and practicable, we will limit disclosure and notify the affected client.
9. Incident response
Suspected unauthorised access is contained, investigated, documented and remediated. Affected persons and authorities will be notified where applicable law requires it. Report a concern immediately to support@aristocratresearch.com.
10. NDA relationship
This standard is a public operating commitment. A signed NDA and service schedule may add project-specific controls; where they conflict, the more specific signed term governs to the extent permitted by law.