Standard v1.0 · 4 September 2026
Back to SecurityBook a 25‑minute fit call

Data Handling Standard

Version 1.0 · 4 September 2026 · Print this page for your file
No certification claimed
Give this to your controller or IT before you send anything

This is the whole of it. Weekgrade is a small firm and this document says so plainly rather than implying a security programme it does not have. Everything below is a commitment we will put in the engagement agreement, not marketing language.

1. What we ask for, and what we refuse

We ask for three exports: job cost detail, general ledger detail for job cost and revenue accounts, and payroll summarised by job. Nothing else is required.

We do not want a payroll register, a payroll journal, or an employee master file, and we will not ask for one. We do not need employee names, individual pay rates, Social Security or taxpayer numbers, addresses or bank details. If a file arrives containing them we stop, tell you within one business day, and permanently delete it within two business days unless you direct otherwise in writing. Sending them is not a breach by you and does not reduce our obligations.

2. How files reach us

ControlWhat we do
TransferA private upload link we issue to you after a mutual NDA is signed. Links are per company, never shared or reused.
EmailWe never accept records by email attachment, and will not review or use anything sent that way.
Your systemsWe hold no credentials to your accounting, payroll or project systems unless you separately grant them in writing. Upload‑first is the default and the recommendation.
In transitTLS, enforced by the provider. The website itself is HTTPS‑only, enforced by redirect, with a strict content security policy.

3. Where your files live

ItemDetail
PlatformGoogle Workspace, operated by Google LLC, United States.
IsolationA storage folder isolated to your company, shared with no other client or prospect.
AccessOnly the Weekgrade personnel working on your engagement. Access is by named account, not a shared password.
Working copiesA working copy may sit on a device we control. That device has full‑disk encryption enabled and is password protected. It is deleted when your files are.
At restEncryption at rest is provided by Google Workspace.
RegionUnited States. We do not offer data residency elsewhere and will say so rather than pretend otherwise.

4. How long we keep them, and how they are destroyed

SituationDeletion
Free preview filesPermanently deleted 30 days after upload, whether or not a preview is ever sent.
Engagement filesPermanently deleted 30 days after we deliver, and never held beyond 90 days from upload.
On your requestWithin 10 business days of a written request, at any time.
Personal data caught in errorWithin 2 business days, with no derived record kept.
MethodA scheduled job runs daily and deletes through the storage provider's API. Deletion is permanent and not recoverable from a trash folder.
EvidenceEvery deletion is written to a log. On request we issue a deletion certificate covering your files only — we do not hand over the raw log, because it names other clients' folders.
BackupsProvider backups that are not readily accessible are overwritten in the ordinary course. We do not maintain separate backups of client source files.
Legal holdDeletion is suspended only to the extent a litigation or preservation duty applies, and resumes as soon as it lifts.
What we keepOur own workpapers and the deliverable. Retained workpapers do not contain your company name, job identifiers, employee data, or customer or supplier names.

5. Artificial intelligence

Your information is never used to train, fine‑tune or otherwise improve any AI model, public or private. Your files are stored and processed only in Google Workspace. No AI service processes your data, and your information is never entered into a personal or consumer AI account. If that ever changes we will tell you in writing before it does, not after.

6. Subprocessors

ProviderPurposeTouches client files?
Google LLC (Google Workspace)Storage, mail, calendar, documentsYes
Cloudflare, Inc.Website hosting, DNS, cookieless page‑view analyticsNo

That is the complete list. We will notify you in writing before adding any provider that would touch your files.

7. If something goes wrong

We will tell you without undue delay, and in any event within 72 hours of becoming aware of any unauthorised access to or disclosure of your information. You decide whether notice to any individual, regulator or attorney general is required and you give it; we will not notify anyone on your behalf without your written direction unless the law requires it.

Incident contact: hello@weekgrade.com.

8. What we do not claim

We hold no SOC 2 report, no ISO 27001 certificate and no third‑party security attestation, and we do not display badges suggesting otherwise. We do not run a formal penetration‑testing programme. Weekgrade is a small firm, and the honest position is that these controls are operational commitments backed by a contract and a deletion log you can inspect — not an audited security programme.

If your insurer, lender or customer requires a vendor with an audited certification, we are not that vendor, and we would rather tell you now than at the point of a questionnaire.

9. Status of this document

This standard is incorporated into the mutual NDA and the engagement letter, so it is contractual rather than descriptive. Where this document and a signed agreement differ, the signed agreement governs. We version it and date it; ask for the current version at any time.

Weekgrade Data Handling Standard · Version 1.0 · 4 September 2026
Questions, or a copy for your IT or insurance file: hello@weekgrade.com
This page is written to print cleanly. Use your browser's print or save‑as‑PDF to keep a copy.

Most of what passes for vendor security is a badge. This is what actually happens to your files, written down so you can hold us to it.

Book a 25‑minute fit call