Data Handling Standard
This is the whole of it. Weekgrade is a small firm and this document says so plainly rather than implying a security programme it does not have. Everything below is a commitment we will put in the engagement agreement, not marketing language.
1. What we ask for, and what we refuse
We ask for three exports: job cost detail, general ledger detail for job cost and revenue accounts, and payroll summarised by job. Nothing else is required.
We do not want a payroll register, a payroll journal, or an employee master file, and we will not ask for one. We do not need employee names, individual pay rates, Social Security or taxpayer numbers, addresses or bank details. If a file arrives containing them we stop, tell you within one business day, and permanently delete it within two business days unless you direct otherwise in writing. Sending them is not a breach by you and does not reduce our obligations.
2. How files reach us
| Control | What we do |
|---|---|
| Transfer | A private upload link we issue to you after a mutual NDA is signed. Links are per company, never shared or reused. |
| We never accept records by email attachment, and will not review or use anything sent that way. | |
| Your systems | We hold no credentials to your accounting, payroll or project systems unless you separately grant them in writing. Upload‑first is the default and the recommendation. |
| In transit | TLS, enforced by the provider. The website itself is HTTPS‑only, enforced by redirect, with a strict content security policy. |
3. Where your files live
| Item | Detail |
|---|---|
| Platform | Google Workspace, operated by Google LLC, United States. |
| Isolation | A storage folder isolated to your company, shared with no other client or prospect. |
| Access | Only the Weekgrade personnel working on your engagement. Access is by named account, not a shared password. |
| Working copies | A working copy may sit on a device we control. That device has full‑disk encryption enabled and is password protected. It is deleted when your files are. |
| At rest | Encryption at rest is provided by Google Workspace. |
| Region | United States. We do not offer data residency elsewhere and will say so rather than pretend otherwise. |
4. How long we keep them, and how they are destroyed
| Situation | Deletion |
|---|---|
| Free preview files | Permanently deleted 30 days after upload, whether or not a preview is ever sent. |
| Engagement files | Permanently deleted 30 days after we deliver, and never held beyond 90 days from upload. |
| On your request | Within 10 business days of a written request, at any time. |
| Personal data caught in error | Within 2 business days, with no derived record kept. |
| Method | A scheduled job runs daily and deletes through the storage provider's API. Deletion is permanent and not recoverable from a trash folder. |
| Evidence | Every deletion is written to a log. On request we issue a deletion certificate covering your files only — we do not hand over the raw log, because it names other clients' folders. |
| Backups | Provider backups that are not readily accessible are overwritten in the ordinary course. We do not maintain separate backups of client source files. |
| Legal hold | Deletion is suspended only to the extent a litigation or preservation duty applies, and resumes as soon as it lifts. |
| What we keep | Our own workpapers and the deliverable. Retained workpapers do not contain your company name, job identifiers, employee data, or customer or supplier names. |
5. Artificial intelligence
Your information is never used to train, fine‑tune or otherwise improve any AI model, public or private. Your files are stored and processed only in Google Workspace. No AI service processes your data, and your information is never entered into a personal or consumer AI account. If that ever changes we will tell you in writing before it does, not after.
6. Subprocessors
| Provider | Purpose | Touches client files? |
|---|---|---|
| Google LLC (Google Workspace) | Storage, mail, calendar, documents | Yes |
| Cloudflare, Inc. | Website hosting, DNS, cookieless page‑view analytics | No |
That is the complete list. We will notify you in writing before adding any provider that would touch your files.
7. If something goes wrong
We will tell you without undue delay, and in any event within 72 hours of becoming aware of any unauthorised access to or disclosure of your information. You decide whether notice to any individual, regulator or attorney general is required and you give it; we will not notify anyone on your behalf without your written direction unless the law requires it.
Incident contact: hello@weekgrade.com.
8. What we do not claim
We hold no SOC 2 report, no ISO 27001 certificate and no third‑party security attestation, and we do not display badges suggesting otherwise. We do not run a formal penetration‑testing programme. Weekgrade is a small firm, and the honest position is that these controls are operational commitments backed by a contract and a deletion log you can inspect — not an audited security programme.
If your insurer, lender or customer requires a vendor with an audited certification, we are not that vendor, and we would rather tell you now than at the point of a questionnaire.
9. Status of this document
This standard is incorporated into the mutual NDA and the engagement letter, so it is contractual rather than descriptive. Where this document and a signed agreement differ, the signed agreement governs. We version it and date it; ask for the current version at any time.
Questions, or a copy for your IT or insurance file: hello@weekgrade.com
This page is written to print cleanly. Use your browser's print or save‑as‑PDF to keep a copy.