Skip to main content
Legal

Data Processing

Last updated: 30 July 2026

Our role

When we deliver analytics, AI or software projects, we typically act as a data processor on behalf of our client, who remains the data controller. We process client data only on documented instructions and only for the agreed project purposes.

Confidentiality

All client information, datasets, documents and business knowledge shared with us are treated as confidential. Access is limited to the team members working on the engagement, who are bound by confidentiality obligations.

Security practices

We apply access control on project systems, encrypted transport for data in transit, and the principle of least privilege. Credentials and secrets are never shared in plain text through public channels.

Data minimization

We ask for the smallest dataset needed to deliver the work, and we prefer anonymized or sample data where it is sufficient.

Sub-processors

Where a project relies on third-party hosting or cloud services, those providers are named in the project agreement before the work starts.

Return and deletion

At the end of an engagement we return or delete client data on request, subject to any legal retention obligations.

Shared responsibility

TidalEx is responsible for the practices described here. Our clients remain responsible for the lawfulness of the data they share with us and for informing their own users. This page describes our commitments and is not an independent certification or audit report.

Contact

Data and confidentiality questions: tidalexsolutions@gmail.com.