How CRV Digital Handles Data

CRV Digital handles business, client, project, personal, and case-related information in a secure and proportionate way throughout its lifecycle. Data is collected, stored, used, transferred, retained, and disposed of with the aim of protecting confidentiality, preserving accuracy, and supporting lawful and professional working practices.

Need-to-Know Access
Secure Storage
Controlled Retention

What clients can expect

Data is classified and protected. Confidential, personal, privileged, and case-related information is identified and handled with controls appropriate to its sensitivity.
Access is restricted. Information is limited to authorised people who require it for legitimate business purposes.

How data is handled in practice

Identified before use. Data is assessed to determine whether it includes confidential, personal, privileged, commercially sensitive, or case-related information.
Stored in approved systems. Information is kept only in approved locations and systems, using access controls, secure passwords, and appropriate sharing restrictions.
Transferred carefully. Data is sent only by approved methods, only to authorised recipients, and only in the minimum amount necessary for the purpose.
Retained and deleted properly. Data is retained, archived, and securely disposed of in line with project, legal, contractual, and operational requirements.

Data controls and safeguards

The policy covers digital and physical information, including client materials, project files, communications, personal data, business records, drafts, and archived materials. CRV Digital applies proportionate controls to reduce unnecessary risk and keep data accurate, secure, and appropriately managed.

Approved Systems Only
Minimum Necessary Sharing
Secure Disposal

Need the full policy?

This page summarises the client-relevant points of the Data Handling Policy and is intended as an accessible overview. Use the buttons below to download the full policy or see our other policies.

If something needs escalation

Breaches, unusual handling needs, and exceptions to normal rules must be dealt with promptly and formally.

Report incidents promptly Any suspected loss, misuse, unauthorised access, accidental disclosure, or security weakness should be raised without delay.
Document exceptions Any exception to normal handling rules must be requested in advance, approved by the Policy Owner, and supported by a clear explanation of the need, risk, and mitigating controls.
Follow review and retention rules Handling practices are monitored through project reviews, file checks, and periodic review of working practices.