Customer ownership

Customer data remains customer data. Marka does not sell it or use it to train shared models without explicit written permission.

Limited access

Project access should be role-based, time-bound, and restricted to the minimum data required for the assigned work.

Secure transfer

Data transfer and storage methods are agreed during scoping according to the project’s sensitivity and technical requirements.

Auditability

Project systems should record access, review actions, corrections, and delivery history where the engagement requires it.

Retention control

Retention and deletion periods are defined in the project agreement rather than left open-ended.

Data minimization

Projects should remove or mask fields that reviewers do not need, especially personal or regulated information.

Customer isolation

Customer projects are separated through access controls and project-specific workspaces.

Incident response

A documented escalation and notification process should be established before sensitive production work is accepted.

Security documentation

Prepare a data-flow diagram, access model, subprocessors list, retention process, and security contact before accepting sensitive enterprise work.

Contractual controls

Use a written services agreement and data-processing terms that define ownership, purpose, permitted processing, confidentiality, deletion, and breach notification.

Compliance roadmap

Begin formal readiness work when customer demand and operational maturity justify it. Never present readiness as certification.

Project review

High-risk domains may require customer-controlled environments, specialized reviewers, stricter access, or a decision not to accept the project.

Need to review data handling before a pilot?

Share the sensitivity, access, retention, and deployment requirements. Marka will identify whether the project is currently supportable.

Start a pilot