Your information, handled properly.
How North Axiom protects client information, and what we will and will not do with it.
Breaches are expensive and common
The cost of getting this wrong is measurable, and regulators now act on records handling as readily as on cyber incidents.
Average cost of a data breach in the UK in 2025.
IBM and Ponemon Institute, Cost of a Data Breach Report 2025Of worldwide turnover, the maximum fine under UK GDPR.
Information Commissioner’s Office fining guidance, via Mayer BrownIn ICO penalties issued in 2025, across six cases.
Information Commissioner’s Office penalties, via Slaughter and MayFill in: check the figures from Information Commissioner’s Office penalties, via Slaughter and May against the original before launch
Security principles
Least privilege, encryption in transit and at rest, logged access, and separation between client environments. Fill in: the controls actually in place, and any certification held, such as Cyber Essentials or ISO 27001
Confidentiality
Client information is used only for the engagement it was provided for, and is not used to train third-party models.
Client data
Held only as long as the engagement and our legal obligations require, then deleted or returned. Fill in: retention periods
AI and data
Client data is not placed into public AI tools. Where AI is used in delivery, the environment, the data and the human review are agreed in writing first.
Data handling
Transfer, storage and destruction follow the same standards we recommend to clients, including secure destruction of physical records.
Information on this website is provided for general information only and does not constitute investment, legal, tax or accounting advice.
