Data handling

Baseline data-handling approach

This page describes the operating principles PartCairn intends to use for early client engagements. Project-specific requirements should be written into the relevant agreement.

1. Minimum necessary access

PartCairn requests only the product, supplier and evidence information needed to perform the agreed scope. Access should be limited to the systems, folders, records and people necessary for the work.

2. Confidentiality

Client and partner information is treated as confidential. NDA or confidentiality terms can be agreed before sensitive BOM, supplier or product information is shared.

3. Supplier outreach authority

PartCairn does not present itself as the manufacturer. Supplier outreach should occur under a client-approved authority model, such as an introduction, written authorization or approved email identity or alias.

4. Storage and access control

Project records should be stored only in approved business systems with appropriate account security and access controls. Access is limited to people assigned to the engagement.

5. Retention and deletion

The client and PartCairn should agree what must be retained, returned or deleted at project close. PartCairn's default intent is not to keep client data longer than needed for the agreed service or legitimate business obligations.

6. AI and external tools

Client-confidential data should not be submitted to unapproved public AI services or other external tools. Any use of third-party systems for client information should follow the client's agreed requirements and applicable contractual restrictions.

7. Incident communication

If PartCairn becomes aware of an incident materially affecting client information handled for an engagement, the client should be informed without unreasonable delay and provided with available facts relevant to the incident.

8. Engagement-specific controls

Clients may require stronger or different controls. Those requirements take precedence when agreed in the applicable contract, order form or security addendum.

Questions: hello@partcairn.com

This document states operational intentions for an early-stage service and does not claim a certification, audit result or compliance status.