Confidential administration requires disciplined handling of information. This Policy describes NCODE BIO’s general confidentiality, access, storage, retention, and incident practices. A separate written agreement may add stricter requirements for a particular client.
1. Purpose
NCODE BIO performs remote administrative work that may involve non-public business information. The purpose of this Policy is to establish reasonable expectations for how client materials, credentials, documents, records, communications, and operational information are accessed and protected.
2. Confidential Information
Confidential information may include business plans, customer and vendor contacts, pricing, schedules, email contents, calendar entries, CRM records, spreadsheets, invoices, internal templates, unpublished documents, workflow information, login access, project files, and any information that a reasonable person would understand to be private in the circumstances.
Information is not confidential when it becomes public without breach, was lawfully known without restriction before disclosure, is independently developed without use of confidential information, is lawfully received from another source without a duty of confidentiality, or is released with written permission.
3. Use Limitation
NCODE BIO uses client confidential information only to perform the agreed services, administer the relationship, maintain security, comply with law, and protect legal rights. Information is not used to build unrelated marketing lists, contact a client’s customers for an independent purpose, or compete with the client.
4. Need-to-Know Access
Access is limited to persons and service providers who reasonably require it for the engagement, administration, security, billing, or legal compliance. NCODE BIO seeks to avoid broad access when a narrower permission, selected folder, delegated mailbox, shared calendar, or restricted CRM role is sufficient.
Clients should identify especially sensitive folders, contacts, projects, or records and should not provide access beyond what is needed.
5. Account Credentials
Role-based access, delegated access, unique user accounts, and multi-factor authentication are preferred. Clients should avoid sending primary passwords through ordinary email. When credential sharing cannot be avoided, a secure channel and temporary credential should be used where available.
NCODE BIO may refuse unsafe credential practices and may request a different method. Clients remain responsible for administrator ownership, recovery information, user removal, and monitoring of their systems.
6. Data Minimization
Only information reasonably necessary for the task should be supplied or retained. A client should redact unrelated personal information, limit date ranges, provide selected records rather than complete databases, and use test data when real data is unnecessary.
NCODE BIO may return, delete, or decline unnecessary information, particularly when it creates avoidable legal, security, or privacy risk.
7. Sensitive and Regulated Information
NCODE BIO is not offered as a specialized repository for highly sensitive or regulated data. Clients should not provide complete payment card data, bank passwords, Social Security numbers, government identification images, medical records, biometric templates, precise authentication secrets, or information subject to specialized legal safeguards unless the task has been expressly accepted and appropriate controls are documented.
NCODE BIO does not represent that ordinary services are compliant with HIPAA, PCI DSS, GLBA, CJIS, export-controlled environments, or another specialized framework unless a separate written agreement explicitly states the applicable obligations.
8. Devices and Work Environment
Administrative work is performed remotely using reasonable device security practices. Measures may include supported software, access controls, screen locking, secure networks, malware protection, updates, separate user profiles, and avoidance of public display of client materials.
No security practice eliminates all risk. Clients should maintain independent backups, activity logs, administrator access, and incident procedures appropriate to their business.
9. Transmission
Documents and data may be transmitted through email, Shopify, cloud storage, communication platforms, or client-selected systems. Encryption in transit is used when supported by the platform. Ordinary email is not appropriate for certain highly sensitive information.
The client and NCODE BIO should agree on a secure transfer method when a task requires sensitive records or large datasets. An incorrect recipient, public link, or open folder should be reported immediately.
10. Cloud Storage and Third-Party Providers
NCODE BIO may use reputable cloud, productivity, communication, security, payment, and document services. Providers may process information in multiple locations and operate under their own security and privacy commitments.
When a client requires a specific platform, the client is responsible for licensing, configuration, access control, retention settings, and confirming that the platform is appropriate for the information involved.
11. Local Copies and Downloads
Local copies may be created when reasonably necessary for editing, organization, upload, conversion, or backup during active work. Downloads should be limited in number and retained only as long as necessary. Temporary copies may be deleted after successful delivery and verification.
12. Subcontractors and Assistance
NCODE BIO may use limited assistance or service providers for operational support. Access to client confidential information will be restricted to what is reasonably necessary, and confidentiality expectations will apply. A project-specific agreement may require advance approval before a subcontractor receives client materials.
13. Client Instructions
NCODE BIO processes client materials according to documented instructions. If an instruction is unclear, conflicts with law, appears unauthorized, or creates material security risk, NCODE BIO may pause and request confirmation.
Clients are responsible for identifying legal retention rules, confidentiality classifications, approved recipients, and restrictions affecting their data.
14. Accuracy and Integrity
Reasonable steps are taken to preserve file names, formatting, source records, and task logs. However, clients must review completed work and maintain authoritative source copies. Administrative services should not be the sole backup for critical information.
15. Retention
Information is retained for the active engagement and a reasonable period for closeout, billing, dispute resolution, security, backup cycles, and legal obligations. Different record types may have different retention periods.
A client may request deletion or return of materials, subject to outstanding payment, legal holds, technical backup cycles, evidence needed for a dispute, and records NCODE BIO must retain by law.
16. Deletion and Destruction
Electronic files may be deleted through normal system functions, access revocation, account removal, or provider deletion tools. Absolute erasure from every backup at the same moment may not be technically possible. Residual backup copies are not intentionally restored except for recovery or legal necessity.
Paper records are not ordinarily required for remote service. If created, they will be stored and destroyed using methods reasonable for their sensitivity.
17. Security Incidents
A security incident may include unauthorized access, accidental disclosure, credential compromise, malware, lost device, incorrect recipient, public link, or suspicious account activity. NCODE BIO will take reasonable steps to contain, investigate, document, and remediate an incident within its control.
Clients will be notified when reasonably appropriate or legally required. Notification timing and content may depend on investigation, law enforcement, platform providers, and the need to avoid increasing harm.
18. Client Incident Duties
Clients should promptly report compromised credentials, unauthorized changes, suspicious messages, or exposure affecting shared systems. Clients should preserve relevant logs and avoid actions that destroy evidence before the issue is understood.
19. Legal Disclosure
NCODE BIO may disclose confidential information when required by subpoena, court order, law, or valid government demand. Where legally permitted and practical, NCODE BIO will notify the client before disclosure and limit the response to information reasonably required.
20. Ownership
Client materials remain the client’s property or the property of the relevant third party. NCODE BIO retains ownership of pre-existing methods, internal tools, reusable workflows, and generalized know-how. Confidentiality obligations do not transfer ownership.
21. End of Engagement
At closeout, the parties should confirm delivery, access removal, credential changes, file location, unresolved tasks, and retention instructions. Clients should revoke accounts and permissions that are no longer needed.
22. No Absolute Security Guarantee
NCODE BIO uses reasonable measures but cannot guarantee that every transmission, device, provider, or account will be immune from unauthorized access or failure. The client should use layered security, backups, and access monitoring proportionate to its own risk.