Security, privacy and data handling.
Operational Alpha only works if the people whose work it observes are protected by it. This brief sets out exactly what is captured, what is never captured, who controls it, and what we commit to. It is written to be handed to a data protection officer, a works council or a security reviewer without translation.
01Three principles
Everything below follows from three commitments that do not change per engagement.
- Instrumentation, not surveillance. We measure how work moves between systems. We do not measure how a person behaves at a keyboard. The distinction is enforced by what we are technically able to ingest, not by policy alone.
- Minimum viable data. Process mining needs three fields to work: a case identifier, an activity, and a timestamp. We start from that floor and add a field only when a specific question cannot be answered without it.
- You hold the asset. The evidence, the skills and the Operational Ledger are yours throughout. We license the engine that operates on them. Ending the relationship does not remove your ability to use what was built.
02What we observe
An audit runs on operational event data you already generate. In most engagements this arrives as system exports rather than any new capture mechanism.
| Field | Purpose | Personal data |
|---|---|---|
| Case identifier | Groups events belonging to one exception or order | No, pseudonymous reference |
| Activity | The step performed, for example "portal dispute raised" | No |
| Timestamp | Sequence and cycle time measurement | No |
| System | Which application the step occurred in | No |
| Actor reference | Distinguishing handoffs between roles and queues | Pseudonymised at capture, role level by default |
| Exception attributes | Type, value band, carrier, resolution outcome | Commercial data, not personal |
Actor references are hashed before they reach our analysis environment. Reports are produced at role and queue level. Where an operation is small enough that a role maps to one identifiable person, we aggregate further or drop the dimension rather than publish a figure that singles someone out.
03What we never observe
These are exclusions, not defaults that can be switched on for a willing client. If an engagement would require any of them, we decline the engagement.
- Keystroke logging, screen recording, screenshots or webcam capture
- The content of emails, messages, calls or documents
- Location tracking, biometric data or any special category data
- Individual productivity scoring, ranking or league tables
- Any output used as an input to performance management, disciplinary process or redundancy selection
The last exclusion is written into the engagement contract as a restriction on your use of the outputs as well as ours. It exists because the value of this work depends on operators telling us how the job really gets done, and nobody does that in front of a system that can be turned against them.
04Consent and works councils
Observation is announced, never covert. Before an audit begins we provide a plain language notice for circulation to affected staff, describing what is collected, why, for how long, and what it cannot be used for.
- Announcement pack. A one page staff notice and a longer document suitable for a works council, union representative or employee forum.
- Named contact. Every notice carries a route for an employee to ask a question or raise an objection, on your side and ours.
- Consultation first. Where a works council, collective agreement or employee representative body has jurisdiction, we do not begin capture until that consultation has concluded.
- Interview participation is voluntary. Shadowing and interviews during an audit are opt in, and declining carries no consequence we will ever know about or record.
05Data protection roles
Engagements are governed by UK GDPR and, where relevant, EU GDPR.
- You are the controller. You determine the purpose and means of processing your operational data.
- We are the processor. We act only on your documented instructions, under a written Data Processing Agreement executed before any data moves.
- Lawful basis. Legitimate interest in operational efficiency is the usual basis, with employment contract or legal obligation applying in some cases. We support your Legitimate Interests Assessment and provide the technical detail a Data Protection Impact Assessment requires.
- Data subject rights. Because actor references are pseudonymised and role level, most reporting falls outside individual identification. Where a request does reach data we hold, we assist you in responding within statutory deadlines at no additional cost.
- Sub-processors. A current list, with purpose and location for each, is provided with the DPA. We give advance notice of any addition and you may object.
06Residency, retention and deletion
- Residency. Data is processed and stored in the United Kingdom or European Economic Area by default. Alternative residency is available where a client requires it, agreed in writing before capture.
- Retention. Raw event data is retained only for the engagement plus an agreed verification window, ninety days unless you specify otherwise. Derived artefacts, meaning the process models, skills and ledger entries, persist because they are the asset you are buying.
- Deletion. On request or at engagement end we delete raw data and confirm in writing what was destroyed and when.
- Exit. You receive a full export of your ledger in the open Operational Skill Schema, in a form that remains readable without our software.
- Cross-client use. Your data is never pooled with another client's by default. Any anonymised contribution to benchmark research is a separate, opt in, revocable agreement, and never includes identifying commercial detail.
07Security controls
- Encryption. TLS 1.2 or above in transit. AES-256 at rest.
- Access control. Least privilege, individually named accounts, multi-factor authentication mandatory. No shared credentials. Access is scoped per engagement and revoked on completion.
- Audit logging. Access to client data is logged. The log is available to you on request.
- Segregation. Client environments are logically separated. Analysis runs against your data only.
- Endpoints. Full disk encryption, automatic screen lock and remote wipe on every device with access.
- Deployment safety. Nothing reaches your live operation without shadow mode comparison, a measured confidence interval, a human approval gate and a tested rollback path. Automation defects are an operational risk, so they are treated as a security control, not a quality nicety.
- Working within your controls. Where you have an established security posture, we operate inside it: your VPN, your SSO, your device standards, your review process.
08AI and model handling
- No training on your data. Your operational data is never used to train, fine tune or improve any model offered to another client, and never leaves the engagement boundary for that purpose.
- Vendor terms. Where a third party model provider is used, it is under enterprise terms that contractually exclude training on submitted data. Providers in use are named in the sub-processor list.
- Human authority. Below autonomy level four, an agent's decision is proposed or gated, never final without a human path to override. Every override is recorded with its context and reasoning.
- Traceability. Every automated decision is reconstructable: the inputs, the skill version that produced it, the confidence, and who approved deployment.
09Ownership and the IP boundary
This boundary is fixed before the first pitch and is not negotiated per deal, because ambiguity here is what turns an operational asset into a vendor dependency.
- Yours: your operational data, the process models derived from it, the compiled skills, the captured corrections and the Operational Ledger in full.
- Ours, licensed to you: the optimisation engine, the simulation framework, the observation tooling and our general methodology.
- Neither party's to take: we acquire no rights over your commercial data, and no engagement grants us a licence to reuse your specific processes elsewhere without a separate written agreement.
10Assurance status
Stated plainly, because a security reviewer will ask and an inflated answer is worse than an honest one.
We do not hold SOC 2 Type II or ISO 27001 certification today. The Efficiency Architects is an early stage firm and claiming otherwise would be false. Formal certification is planned as engagement volume justifies the audit cycle, and we will publish the date achieved rather than the date targeted.
In the meantime we do not ask you to take the gap on trust. We offer:
- Completion of your own security questionnaire and vendor assessment before contract
- A signed DPA with the sub-processor list attached before any data moves
- Operating inside your infrastructure and controls where you prefer that to ours
- A scoped pilot on a single non-critical process, so the first exposure is small and reversible
- Named references from prior professional engagements on request
11Incidents and contact
If we become aware of a personal data breach affecting your data, we notify you without undue delay and within seventy two hours of becoming aware, with what we know, what we are doing, and what we need from you. We support your regulatory notifications rather than making them on your behalf.
Security questions, vulnerability reports and data protection queries: info@theefficiencyarchitects.com. Vulnerability reports made in good faith will be acknowledged and never met with legal threat.