01Roles and scope
For website requests and engagement intake, eSora Labs Ltd. is the controller of the personal information involved. For client engagements that require us to process personal data on the client’s behalf, we act as processor under a written data-processing agreement, on documented instructions.
02What we process
Contact and identity details of the people we work with; the contents of brief requests and uploaded documents; research material gathered for an engagement, which may incidentally contain personal data; and technical security logs. We do not seek special-category data unless an engagement explicitly requires it and a lawful basis is agreed.
03Lawful bases and instructions
We process website data to respond to requests and to operate the service (legitimate interest or contract steps), and with consent where the law asks for it. As processor, we act only on the controller’s documented instructions, including for international transfers, which are made under appropriate safeguards.
04Sub-processors
Hosting, email, and file-handling providers may process engagement data on our behalf. Each is bound by contract to equivalent data-protection and confidentiality obligations, processes data only on our instructions, and is listed in the engagement’s data-processing agreement where one applies.
05Retention and deletion
Engagement data is retained for the engagement and a defined records period, then deleted or anonymised. On request at the end of an engagement we return or delete client data, subject to legal hold obligations. Backups expire on a fixed rotation.
06Safeguards
Access is limited to people who need it for the work, under confidentiality obligations, with access logging and least-privilege controls. Incidents affecting personal data are assessed promptly and notified to controllers or individuals where the law requires. See also Confidentiality and Privacy.