Skip to main content

Data handling · last updated 19 September 2026

Send less data, through the right channel.

This describes the process actually used for the three fixed-scope pilots. It is not a claim of compliance with a particular jurisdiction. Review the processing agreement before sending real data.

Minimum fields

Delivery payouts: platform and settlement ID; transaction and deposit dates; gross sales; fees, promotions, refunds and adjustments; net payout; matching deposit amount; and existing account mapping if relevant.

PAT register: asset ID, site code, appliance description, test date and result, supplied retest interval and the import fields needed by the buyer’s existing system.

Completed-work invoice audit: job ID, status, completion date, agreed value, invoice ID, invoice date and invoice amount for the same period.

Remove first

Replace customer or restaurant names with neutral codes. Remove addresses, customer-level orders, bank and routing numbers, employee information, unrelated transactions and any fields not needed for the agreed comparison. Never send passwords, full card data, identity documents, special-category data or criminal-offence data unless separately agreed in writing.

Transfer and storage

After payment and scope checks, the buyer receives a first-party encrypted upload route on audits.modestambitions.studio. TLS protects transfer. Each operational file is encrypted and authenticated with AES-256-GCM before persistent storage; protected application fields use application-level encryption. The service and files are hosted by Hetzner in Nuremberg, Germany. Do not send operational files by ordinary email.

Access and purpose

Duarte alone handles the files. Operator access uses a password, TOTP multi-factor authentication, lockout controls and a 20-minute inactivity timeout. Buyer access uses one-use email links that expire after 30 minutes and encrypted sessions that expire after seven days. Data is used only to fulfil the agreed engagement. The current process does not send operational file contents to an AI provider.

Subprocessors

Hetzner hosts the application and encrypted files. Resend handles transactional email and delivery metadata, not file contents. Stripe handles payment, not file contents.

Retention and incidents

Raw files and working outputs are deleted 30 days after delivery and never more than 90 days after upload. Encrypted backups age out after 35 days and are not deliberately restored after the applicable deletion date. Request earlier deletion or report an incident at hello@modestambitions.studio.