Data protection

Last updated: 27 July 2026

This statement explains how Kilvora Ltd handles personal data when delivering work inside a client’s environment. It is intended for procurement, security, and data protection teams assessing us as a supplier.

Our Privacy Notice covers personal data we hold as a controller, including website visitors and enquiries.

Controller and processor

For our own business activities, including this website and our client correspondence, we act as a data controller.

When delivering an engagement inside a client’s Microsoft Fabric or Azure environment, we act as a data processor. The client remains the controller of their own data, determines the purposes of processing, and gives the instructions we work to.

How we work with client data

We work in your environment, not ours. Engagements are delivered inside the client’s own tenant, using accounts the client provisions and controls. Client data is not copied to our systems, downloaded to local machines, or moved into any environment we own, unless the client instructs it in writing.

Access is the minimum needed. We ask for the least privileged access that allows the work to be done, and we ask that it be granted through the client’s normal process rather than as a standing exception. We confirm in writing when our work is complete so that access can be revoked.

We work with structure, not content. Architecture, governance, security, reliability, and cost work is concerned with how a platform is built and operated rather than with the records inside it. Where the work can be done without reading personal data, that is how it is done.

Deliverables are anonymised. Reports, assessments, decision records, and diagrams describe systems, patterns, and configuration. Where an example is needed, personal data is masked or replaced.

Confidentiality continues after the engagement. Client information is not disclosed to third parties. No client is named in marketing, case studies, or reference material without written permission.

Contractual arrangements

We are willing to enter into a data processing agreement, a non disclosure agreement, or the client’s own equivalent, and to complete supplier security and data protection questionnaires as part of onboarding.

Sub processors

We do not engage sub processors for client engagements. Work is delivered directly. If that ever changes, affected clients will be informed in advance.

Security practices

  • Work is carried out on an encrypted device with full disk encryption and automatic screen locking
  • Access to client environments uses multi factor authentication
  • Credentials are never stored in pipeline code, notebooks, or configuration tables, and secrets are referenced from a managed store rather than embedded
  • Client documents are stored in a controlled location and removed at the end of the retention period

Breach notification

If we become aware of a personal data breach affecting client data, we will notify the client without undue delay and support their investigation and any reporting they are required to make.

Contact

Kilvora Ltd, registered in England and Wales, company number 13761116.

Email emmanuel@kilvora.co.uk.