AGMM / Security and data protection

What we do with your data, written down.

This is the page a buyer usually has to ask for. It describes how AGMM handles client information during a £2,000 constraint audit and during a build: where data sits, what reaches a third-party model, who has access and what happens at the end. It claims no certification, because AGMM holds none.

During the audit

Does the audit need a copy of our systems?

No. The fourteen-day constraint audit is a diagnostic, not a migration. It runs on conversation, screen shares and documents you choose to share, and in most audits nothing leaves your estate at all.

Where a real sample is genuinely needed, we ask for the smallest one that answers the question, agree in writing what happens to it, and prefer anonymised or redacted data. A screenshot of a structure is often enough, and it is always better than an export.

The four documents you keep at the end are yours. AGMM does not publish them, reuse them as a case study or name you as a client without written permission. That is why the evidence page shows one job and says what it cannot show.

Third-party models

What reaches a third-party AI model, and what does not?

Only what the design says reaches it, and the design is agreed with you before anything is built. When a build uses an external provider's model, the proposal names the provider, what is sent, what is retained and for how long, and whether the provider trains on the content. If that is not acceptable to your business, it is a design constraint and we build to it.

Some data should not leave a client's estate at all. That is a normal answer, not a failed project. It changes the architecture, sometimes the cost, and occasionally the conclusion.

AGMM does not use your data to train anything of its own, and does not feed one client's information into another client's system.

Access and people

Who has access, and for how long?

The people doing the work. Access is requested per engagement, scoped to the task, held under named accounts rather than shared logins, protected by multi-factor authentication where the system offers it, and removed when the work ends or when you ask. We would rather have a read-only export than an administrator account.

Subprocessors are the services AGMM uses to do the work: hosting, source control, the model providers named in a design and the ordinary tools behind email and invoicing. The list for your engagement is provided in writing on request before work starts, not published here: it changes per engagement, and a stale list is a false statement rather than a reassurance.

The legal position

How does this sit with UK GDPR?

For your business and customer data, you are the controller and AGMM is a processor under written terms agreed before any client data is touched. Those terms cover purpose, duration, security measures, subprocessors, data-subject requests and what happens at the end. AGMM is the controller only of its own records, described in the privacy notice.

Retention follows the same logic. Working copies go at the end of the engagement or on your written request. What remains is the business record and the design documentation needed to support a system still in production, confirmed to you in writing.

If AGMM becomes aware of a personal data breach affecting your data, you are told without undue delay and within 24 hours, with the facts as they stand. The statutory reporting decision is the controller's, which means it is yours.

AGMM LTD is registered in England and Wales, company number 16384156. Check the register.

Boundaries

What this page does not cover

  • A certification. AGMM holds no ISO 27001, SOC 2 or Cyber Essentials, and does not imply one here.
  • Legal advice. Your own data protection adviser decides whether these arrangements satisfy you.
  • Your contract. Where this page and a signed agreement differ, the agreement binds both sides.
  • Your own obligations. AGMM cannot be the controller of your customer data, and does not ask to be.
  • A published subprocessor list. It is provided in writing before work starts instead.

Questions before a call

Frequently asked questions

Where does our data live during an audit?

In your systems. The constraint audit runs on three sixty-minute working sessions, screen shares and documents you choose to share. It does not need a copy of your production database. Where a real sample is genuinely needed, we ask for the smallest one that answers the question, agree in writing what happens to it, and prefer anonymised or redacted data.

Is our data sent to a third-party AI model?

Not without your agreement, and not by default. Where a build uses a third-party model, the provider, what is sent, what is returned and what is retained are written into the design before anything is built, and you approve it. Where data is too sensitive to leave your estate, that is a design constraint we build to, not an objection we argue with.

Are you the controller or the processor of our data?

For your business and customer data, AGMM acts as a processor and you remain the controller. AGMM is the controller only of its own records: your enquiry, the contract, the invoices and its correspondence. Processing terms are agreed in writing before any client data is touched, covering purpose, duration, security measures, subprocessors and what happens at the end.

What happens to our data when the work ends?

Working copies are deleted at the end of the engagement or at your written request. What AGMM keeps afterwards is its own business record: the contract, the invoices, the correspondence and the design documentation needed to support a system still in use. AGMM confirms in writing what was held and what was removed.

Do you report a breach, and how quickly?

Yes. If AGMM becomes aware of a personal data breach affecting your data, we tell you without undue delay and within 24 hours of becoming aware, with what we know then rather than after an internal review. You are the controller, so the reporting decision and the statutory clock are yours; our job is to get you the facts fast enough to use them.

Ask before you buy

Bring the security questions to the fit call.

Thirty minutes, free, nothing bought on the call. A data question that would stop the work is better found there than after the invoice. Read the audit page, or what AGMM does.