Client Data
Data handling starts with collecting less.
This public website is brochure-only. It does not accept client file uploads.
Do not send operational files by email
Email may be used to describe a problem and arrange a conversation. Do not attach MES or OEE exports, production histories, schedules, reason-code records, maintenance records, staffing data, financial data, credentials, trade secrets, or other confidential material. No operational dataset is accepted until a secure transfer method and written handling terms are in place.
Data that may be requested
If a contracted engagement requires analysis, Crusoe Advisory may request the minimum fields needed from production, downtime, schedule, quality, maintenance, inventory, staffing, or cost records. The requested fields and exclusions will be documented before transfer. Direct personal identifiers and credentials are not requested unless the engagement expressly requires them.
Purpose and access
Client data is used only to perform the agreed analysis, produce contracted deliverables, validate findings, and meet documented legal or security obligations. Access is limited to Brian Crusoe and any specifically disclosed service provider approved for that engagement. Client data is not sold or used for advertising. Client data is not used to train general-purpose or publicly available machine-learning models.
Transfer, storage, and service providers
Before any operational file is accepted, the engagement record must identify a customer-specific, expiring transfer link and storage location that encrypts data in transit and at rest, limits access by least privilege, and records access. No public bucket, public directory, permanent website credential, or ordinary email attachment is an approved transfer method.
Subcontractors and AI providers do not receive client operational data unless the provider, purpose, fields, location, and applicable retention terms are disclosed and approved in writing before processing. Where an approved AI service is used, client data may not be used to train the provider's general models.
Retention and deletion
Because the public website does not accept operational data, it has no client-file retention period. For a future engagement, the active retention period and deletion date must be written into the engagement terms before transfer. Unless those terms require a different period, working copies must be deleted within 30 days after the final deliverable is accepted, and encrypted backup copies must expire within 90 days. A client may request earlier deletion when it does not conflict with a legal or contractual duty. Deletion confirmation is available on request.
Security incidents
If Crusoe Advisory confirms unauthorized access to client data under its control, affected clients will be notified without unreasonable delay and in accordance with the engagement terms and applicable law. The notice will describe the known scope, the containment work, and the next actions when that information is available.
Questions and requests
For security questions, approved-transfer coordination, access questions, or deletion requests, email brian@crusoeadvisory.com. Do not include confidential files in that message.