Table of Contents
1. Purpose & Scope
That Is A Q ("Q", "we", "our", or "us") is committed to transparency regarding how we handle, share, and disclose information in the course of our professional services. This Permitted Disclosures policy outlines the specific circumstances under which we may share client, project, or operational information with external parties, ensuring alignment with privacy laws, industry standards, and mutual contractual agreements.
This policy applies to all engagements, including software development, product design, digital strategy, cloud infrastructure, and AI integration services.
2. Client Project Data
2.1 Internal Processing
Project files, source code, design assets, and architectural documentation are processed internally within secured environments. Access is strictly limited to authorized team members assigned to your engagement under the principle of least privilege.
2.2 Cross-Functional Collaboration
In cases requiring specialized expertise (e.g., accessibility auditing, performance optimization, or compliance validation), we may share relevant technical fragments with vetted subject-matter experts. All shared materials are redacted of proprietary business logic unless explicit written consent is provided.
3. Third-Party Integrations & Services
To deliver modern, scalable solutions, we utilize a curated stack of third-party tools and services. Disclosures to these providers are limited to functional necessity:
- Cloud Infrastructure: AWS, Vercel, or equivalent providers for hosting, CI/CD pipelines, and environment provisioning.
- Analytics & Monitoring: Performance tracking, error logging, and uptime monitoring services that aggregate anonymized telemetry.
- Collaboration Tools: Encrypted project management and communication platforms used solely for internal coordination.
All third-party vendors are evaluated against our security standards and bound by data processing agreements that restrict secondary use of transmitted information.
4. Marketing, Portfolio & Case Studies
We believe in showcasing transformative work while respecting client confidentiality. Permitted disclosures for marketing purposes include:
- Published case studies, portfolio entries, or press materials only after written approval from the client.
- Anonymized metrics and technical outcomes where client identity is explicitly removed.
- Use of client logos or branding in partnership directories, subject to mutual agreement.
Clients may request complete exclusion from public-facing materials at any time by notifying our legal or account management team.
5. Legal & Regulatory Compliance
We may disclose information without prior notice when legally compelled or when necessary to:
- Comply with court orders, subpoenas, or regulatory inquiries.
- Protect the rights, property, or safety of That Is A Q, our clients, or the public.
- Enforce contractual terms, including payment collection or intellectual property protection.
Where legally permissible, we will provide advance notice to affected clients before disclosing non-public information.
6. Security & Incident Reporting
In the event of a confirmed or suspected security breach, system vulnerability, or data exposure, we reserve the right to disclose relevant technical details to:
- Authorized cybersecurity firms for forensic analysis.
- Regulatory bodies or industry consortia for threat intelligence sharing.
- Affected clients, stakeholders, or end-users as required by breach notification laws.
All incident-related disclosures follow responsible disclosure frameworks and prioritize containment, mitigation, and transparency.
7. Confidentiality Restrictions
Notwithstanding the permitted disclosures above, we strictly do not share:
- Proprietary algorithms, trade secrets, or unreleased product roadmaps.
- Client PII, financial records, or authentication credentials.
- Unredacted source code or database schemas without explicit contractual authorization.
- Internal strategic communications or pricing structures.
Breaches of confidentiality by team members or subcontractors result in immediate termination of access and appropriate legal recourse.
8. Client Consent & Opt-Out Mechanisms
For any disclosure outside standard operational requirements, we maintain a transparent consent workflow:
- Project Onboarding: Clients receive a disclosure scope matrix outlining anticipated data flows.
- Dynamic Opt-Out: Clients may modify consent preferences at any time via their engagement portal or by contacting their account lead.
- Audit Rights: Enterprise clients may request documentation of data processing activities and third-party sharing logs.
9. Policy Updates & Contact
This policy is reviewed quarterly and updated to reflect changes in technology, service offerings, and regulatory landscapes. Material changes will be communicated via email and client dashboard notifications at least 30 days before taking effect.
Questions About Data Sharing?
Our compliance team is available to clarify disclosure practices, review consent settings, or address specific security requirements.
Contact Legal & Compliance →