Every engagement should make clear what data is required, where it moves, who can access it, what providers are involved, what is retained, and what evidence exists afterward.
Privacy cannot be repaired solely through website language after a system has been designed. It must appear in data classification, workflow design, permissions, provider selection, logging, retention, and deletion behavior.
Clients are responsible for disclosing relevant data categories, systems, policies, access restrictions, and unauthorized parallel workflows. ProxyScout is responsible for designing and operating the agreed controls within the covered system.
If privacy, retention, or provider exposure is your concern, bring the workflow and we will walk through how it would be designed.