Data Processing
Last updated: 30 July 2026
Our role
When we deliver analytics, AI or software projects, we typically act as a data processor on behalf of our client, who remains the data controller. We process client data only on documented instructions and only for the agreed project purposes.
Confidentiality
All client information, datasets, documents and business knowledge shared with us are treated as confidential. Access is limited to the team members working on the engagement, who are bound by confidentiality obligations.
Security practices
We apply access control on project systems, encrypted transport for data in transit, and the principle of least privilege. Credentials and secrets are never shared in plain text through public channels.
Data minimization
We ask for the smallest dataset needed to deliver the work, and we prefer anonymized or sample data where it is sufficient.
Sub-processors
Where a project relies on third-party hosting or cloud services, those providers are named in the project agreement before the work starts.
Return and deletion
At the end of an engagement we return or delete client data on request, subject to any legal retention obligations.
Shared responsibility
TidalEx is responsible for the practices described here. Our clients remain responsible for the lawfulness of the data they share with us and for informing their own users. This page describes our commitments and is not an independent certification or audit report.
Contact
Data and confidentiality questions: tidalexsolutions@gmail.com.
