NUMEXS / LEGAL / 07
Data Security & Confidentiality Notice
How authorized system access, client materials, and confidential information should be addressed in a NUMEXS engagement.
Purpose and limits of this notice
NUMEXS Corp may need access to business applications, cloud workspaces, API settings, sample records, dashboards, or a remote support session to perform agreed work. This notice describes the issues that should be considered when that access is planned and the boundaries of this public statement. A signed agreement may establish more specific duties for a client project.
The notice does not assert an unverified certification, audited security standard, fixed data location, or zero-risk environment. The security controls that can be used depend on the client's systems, the nature of information involved, the permitted access, and the third-party providers selected.
Authorization and least necessary access
Before access is granted, the parties should identify the system owner, intended task, access level, and duration. NUMEXS personnel should use an authorization path approved by the client. A role with limited permissions is preferable when it can complete the agreed task; a broad administrator credential should be used only when the task requires it and the client approves.
The client should create, monitor, and revoke accounts according to its own administration procedures. Shared passwords sent through an ordinary enquiry increase risk and should be avoided. Where remote access is needed, the parties should agree on the tool, session control, and any required supervision before the session begins.
Confidential project information
Project discussions may reveal internal workflows, vendor arrangements, employee details, business records, configuration, or technical weaknesses. Such information should be used for the agreed service and disclosed only to people or providers who need it for that purpose, subject to the accepted confidentiality terms.
A public website message is not the place to send unrestricted production data or secrets. The client should identify restricted material and any contractual, industry, or legal controls before it is shared. If a project involves personal information processed for the client, a separate data processing agreement may be appropriate.
Data flow and third-party vendors
An integration, dashboard, cloud setup, or AI workflow can move information to a third-party system. The scope should state what information moves, its source and destination, the applicable account owner, and any limits on storage or reuse. Vendor terms and technical documentation should be reviewed for the intended use.
NUMEXS cannot independently guarantee a vendor's security, uptime, geography, data retention, or model behavior. The client is responsible for deciding whether an external product fits its own data policies and regulatory obligations. An agreed implementation can include vendor-related configuration, but ownership of the vendor relationship should remain clear.
Changes, backups, and testing
Changing a live configuration can affect other users, automation, data, or access. Before work that could materially alter production operations, the parties should identify relevant dependencies, an appropriate backup or recovery path, a suitable time for change, and a person who can validate the result.
The accepted scope should say whether NUMEXS is responsible for making a backup or whether the client provides one. Testing with representative, appropriately protected data is preferable where practical. A test cannot eliminate every later failure, especially when third-party systems change after handoff.
Remote support and credentials
A remote support session should begin only with authorization from a person entitled to approve it. Access should be limited to the reported issue or agreed maintenance task. The client should understand that information visible on a shared screen or in an account may be exposed during the session.
After work ends, the client should close temporary sessions, revoke accounts or tokens no longer needed, and rotate credentials under its own policies where appropriate. Ongoing support requires a separate written description of any persistent access, covered systems, and request procedures.
Incidents and records
If either party identifies a suspected exposure or unauthorized action related to an engagement, it should promptly communicate through the project contact path and preserve relevant information for investigation. Specific notification timing, roles, cooperation, and remediation obligations should be agreed in the applicable contract and applied in accordance with law.
NUMEXS may keep appropriate records of work, approvals, support activity, and business correspondence for operational, billing, security, or legal reasons. Retention and deletion of client data should be defined by the service relationship and the Privacy Policy; a public notice alone cannot describe every system's storage configuration.
Review and contact
This notice can be revised as actual service practices and technical tools change. It is intended to help clients ask concrete questions about authorized access and confidentiality before a project begins. It is not a substitute for a tailored security review, legal advice, or a signed data processing arrangement where one is needed.
Use the contact details below to raise a security or confidentiality question. Explain the relevant project and issue, but do not include passwords or sensitive records in a general enquiry. An authorized channel for exchanging those materials can be agreed separately.

