📄 Policy Document 📅 Effective: Jan 15, 2025 🔒 Restricted Access

Obligations of Confidentiality

This document outlines the binding confidentiality obligations applicable to all clients, contractors, partners, and third parties engaged with That Is A Q. By proceeding with our services, you acknowledge and agree to these terms.

01 Scope & Purpose

That Is A Q ("the Company") handles sensitive technical, commercial, and personal information as part of its design, development, and strategic consulting services. This policy establishes the confidentiality framework that governs how such information must be treated, stored, and disclosed.

All parties receiving Company information under this agreement shall treat it as strictly confidential, exercising a degree of care no less stringent than that used to protect their own proprietary materials.

02 Definition of Confidential Information

"Confidential Information" includes, but is not limited to:

  • Technical documentation, source code, architecture diagrams, API keys, and deployment credentials
  • Business strategies, financial models, pricing structures, and client rosters
  • Unpublished product roadmaps, design systems, UX research data, and marketing campaigns
  • Personal data of employees, users, or stakeholders subject to GDPR, CCPA, or equivalent regulations
  • Any information explicitly marked as "Confidential," "Restricted," or "Proprietary" at the time of disclosure
🔍 Note on Oral Disclosures

Information shared verbally or visually during meetings, demos, or workshops is equally protected if it would reasonably be considered confidential under industry standards.

03 Core Obligations

Receiving parties agree to the following binding commitments:

  • Non-Disclosure: Not disclose, publish, or transmit Confidential Information to any unauthorized third party without prior written consent.
  • Limited Use: Utilize Confidential Information solely for the purpose of fulfilling the agreed-upon scope of work with That Is A Q.
  • Need-to-Know Access: Restrict access to personnel directly involved in the project who have signed equivalent confidentiality agreements.
  • No Reverse Engineering: Refrain from decompiling, reverse engineering, or attempting to derive underlying algorithms, source code, or trade secrets.
  • Return or Destruction: Upon termination of engagement or written request, promptly return or securely destroy all copies of Confidential Information and provide written certification of compliance.

04 Security & Handling

All Confidential Information must be protected using industry-standard security practices, including but not limited to:

  • End-to-end encryption for data in transit and at rest
  • Role-based access controls (RBAC) and multi-factor authentication (MFA) for shared repositories
  • Regular security audits and vulnerability assessments on systems hosting proprietary data
  • Immediate reporting of any suspected or confirmed data breach within 24 hours of discovery

05 Permitted Disclosures & Exceptions

Confidentiality obligations shall not apply to information that:

  • Is or becomes publicly known through no fault of the receiving party
  • Was lawfully in the receiving party's possession prior to disclosure by the Company
  • Is independently developed without reference to or use of Confidential Information
  • Is required to be disclosed by law, court order, or regulatory authority, provided the receiving party gives prompt written notice to the Company (where legally permitted) to allow protective measures

06 Term & Survival

This confidentiality agreement takes effect upon receipt and remains in force for the duration of the business relationship. Obligations regarding trade secrets and proprietary technology shall survive indefinitely. All other confidentiality duties shall persist for a period of five (5) years following termination of services or return of materials, unless otherwise specified in a separate executed contract.

07 Breach & Remedies

Unauthorized disclosure or misuse of Confidential Information may result in irreparable harm to That Is A Q. In addition to monetary damages, the Company reserves the right to seek:

  • Immediate injunctive or equitable relief to prevent further violations
  • Indemnification for legal fees, compliance costs, and third-party claims arising from the breach
  • Termination of all active engagements without notice or penalty

Remedies outlined herein are cumulative and do not exclude any rights available under applicable law.

📝 Acknowledge & Confirm

By submitting your details below, you confirm that you have read, understood, and agree to abide by the Obligations of Confidentiality outlined in this document.