How CRV Digital Protects Confidential Information

CRV Digital treats confidentiality as a core obligation. Information received, created, stored, shared, or handled in the course of our work is protected so it is accessed only by those who need it, used only for legitimate business purposes, and safeguarded through appropriate technical, organisational, and behavioural controls.

Need-to-Know Access
Secure Handling
Immediate Escalation

What clients can expect

Access is limited. Information is shared only with people who need it for the relevant task and who have appropriate authority.
Secure systems are used. Working files, evidence, and communications are stored and transferred using approved locations, channels, and protections.

How confidential information is handled

Classified at the start. Matters are assessed to identify whether information is client confidential, legally privileged, commercially sensitive, personal data, or otherwise restricted.
Protected in storage and transfer. Working files, client communications, CCTV, and case materials are kept in approved locations with suitable access controls, backups, and device security.
Handled discreetly. Confidential matters are not discussed in public places, on unsecured calls, or where others do not need to know. Screens, printouts, and whiteboards are protected from casual viewing.
Copies are controlled. Copies, extracts, screenshots, exports, and local downloads are only created where needed for the work and are deleted or archived when no longer required.

Confidentiality in practice

This policy covers confidential information in digital, physical, verbal, visual, and other forms, including client instructions, case materials, photographs, CCTV, video files, 3D models, working files, reports, drafts, legal correspondence, expert communications, personal data, pricing, and internal business records.

Need-to-Know Basis
Approved Channels Only
Secure Return or Deletion

Need the full policy?

This page summarises the client-relevant points of the Confidentiality Policy and is intended as an accessible overview. Use the buttons below to download the full policy or see our other policies.

If something goes wrong

Any loss, suspected loss, misdirection, unauthorised disclosure, security weakness, or uncertainty relating to confidential information must be acted on immediately.

Contain the issue Take immediate steps to limit further exposure and preserve evidence of what happened.
Escalate promptly Notify the Policy Owner or relevant manager without delay so the incident can be recorded and managed.
Follow proper retention rules At the end of a project, information must be returned, archived, or securely deleted in line with client instructions, legal obligations, and company retention requirements.