Our approach
Calyxra is a professional-services practice, not a self-service data platform. Before engagement data is transferred or a configuration is changed, we agree what is required, how access will be provided, who can approve the change, how it will be verified, and what happens when the work is complete.
Specific client requirements can be documented in the Scope of Work or a separate data-processing or confidentiality agreement.
Data minimisation
- We begin with the business question and request only relevant evidence.
- We prefer aggregated exports or read-only access where practical.
- We avoid customer-identifying fields unless the agreed method genuinely needs them.
- We document material source, metric, and transformation assumptions.
Access and working practices
Access is limited to people involved in the agreed work. Clients should grant the narrowest practical permissions, keep ownership of their accounts, and revoke access when it is no longer needed. We do not ask clients to email passwords or share personal login accounts.
Write access is requested only when an approved in-scope correction requires it. The client may instead perform the change from a written specification. Material changes, responsible owners, and verification results are recorded in the engagement change log.
Where client-owned environments are available and suitable, analysis can be performed there. Otherwise, the chosen transfer and workspace are agreed during scoping.
Transfer, storage, and service providers
The appropriate method depends on the sensitivity, size, and systems involved. We agree the transfer channel and storage location before receiving engagement data. We may use providers for hosting, email, scheduling, secure transfer, or storage when necessary to deliver the work, subject to access restrictions and applicable contract terms.
Retention, return, and deletion
The engagement agreement sets the working retention period and the return or deletion process for client-provided data. We may retain deliverables, contracts, invoices, and limited business records as required for legal, accounting, security, or dispute-resolution purposes. Deletion cannot remove copies a client retains in its own systems or records another provider must retain by law.
Report a security or data concern
Send relevant details to admin@calyxra.com. Please do not include sensitive client data in the initial message. We will respond with an appropriate channel if more detail is needed.