Confidentiality Policy
At Sienda Ltd, confidentiality is a fundamental part of every professional engagement.
Our work may require clients to share commercially sensitive information about their organisation, operations, people, processes, projects, markets, systems, customers, suppliers, strategy or future plans.
We treat that information with discretion and use it only to the extent reasonably necessary to perform the agreed work.
This Confidentiality Policy explains the principles we apply when handling confidential information supplied in connection with Sienda services.
1. Scope of confidentiality
Confidential information may include, among other things:
- business plans, strategies and commercial objectives;
- internal processes, procedures and workflows;
- operational and organisational information;
- financial, pricing and commercial information;
- customer, supplier, partner and employee information;
- contracts, correspondence and internal documentation;
- project, product and technology information;
- research, data, analyses and reports;
- quality, certification and compliance documentation;
- policies, controls, risk assessments and audit-related information;
- information concerning planned transactions, investments, changes or opportunities;
- access information provided specifically for an agreed assignment;
- any other information that is identified as confidential or which would reasonably be understood to be confidential.
Information disclosed verbally, electronically, in writing or through access to client systems may all be treated as confidential.
2. How confidential information is used
Client information is used only for legitimate purposes connected with the relevant engagement.
This may include:
- understanding the client’s circumstances;
- conducting analysis or research;
- preparing recommendations;
- producing agreed reports or documentation;
- reviewing processes, projects, products or systems;
- supporting business-engineering work;
- providing advisory or decision support;
- fulfilling contractual, administrative or legal obligations.
We do not sell or trade client confidential information.
We do not use confidential client information for unrelated marketing purposes.
3. Disclosure
Sienda does not disclose confidential client information unnecessarily.
Information may be disclosed only where reasonably required:
- to personnel or authorised collaborators involved in delivering the engagement;
- to professional advisers or service providers where necessary;
- where the client has authorised disclosure;
- where disclosure is required by law, court order or competent authority; or
- where otherwise permitted under an applicable contractual agreement.
Where appropriate, access is limited to the information reasonably required for the relevant purpose.
Sienda does not publicly identify a client, describe an engagement, publish a case study or disclose confidential details about work performed without appropriate authorisation.
4. Independent engagements and discretion
Sienda may work with organisations operating within the same industry, market or professional sector.
Doing so does not permit information belonging to one client to be disclosed to another.
Client information, strategies, documents and commercially sensitive circumstances are treated separately and confidentially.
Where an engagement requires particular confidentiality arrangements, additional restrictions may be agreed in writing.
Sienda is also willing to enter into a separate non-disclosure agreement where appropriate.
5. Personal data and privacy
Where confidential information contains personal data, Sienda handles that information in accordance with applicable data-protection requirements, including UK GDPR and, where applicable, EU GDPR.
Our approach includes principles such as:
- data minimisation;
- purpose limitation;
- appropriate access controls;
- storage limitation;
- reasonable security measures;
- appropriate handling of data-subject rights.
Clients should avoid providing personal or sensitive information that is not reasonably necessary for the assignment.
Further information about the processing of personal data is provided in Sienda’s Privacy Policy.
6. Information security
Sienda applies reasonable organisational and technical measures appropriate to the nature of the information being handled.
Depending on the engagement, these may include:
- access-controlled systems and storage;
- strong authentication and password practices;
- multi-factor authentication where available and appropriate;
- limiting access to those who reasonably require it;
- separation of client materials;
- secure methods of exchanging sensitive information;
- deletion of working material that is no longer reasonably required;
- minimisation or redaction of confidential information where practical.
No electronic system can be guaranteed to eliminate every security risk, but confidential information is handled with reasonable care appropriate to the engagement.
7. Research, analytical and technology tools
Sienda may use professional research, analytical, data-processing, automation or artificial-intelligence tools internally where appropriate to assist with an engagement.
Confidential information is not submitted to external tools unnecessarily.
Where third-party systems are used, Sienda seeks to limit information to what is reasonably required for the task and to use appropriate professional or business service arrangements where available.
Sienda does not intentionally use client confidential information to train its own artificial-intelligence models or create datasets for unrelated purposes.
The use of internal tools does not alter Sienda’s confidentiality obligations to the client.
8. Reports and deliverables
Reports, analyses, recommendations, assessments and other materials specifically prepared for a client are treated as confidential unless:
- the client authorises wider disclosure;
- the information is already lawfully public;
- disclosure is required by law; or
- different arrangements have been agreed in writing.
Sienda will not use identifiable confidential client information in public presentations, marketing materials, demonstrations, articles or case studies without appropriate permission.
9. Retention
Confidential information is retained only for as long as reasonably necessary for:
- performing the engagement;
- dealing with subsequent questions relating to the work;
- maintaining appropriate business records;
- satisfying contractual obligations; or
- meeting legal, regulatory, insurance, tax or accounting requirements.
Information that is no longer reasonably required may be deleted or securely disposed of in accordance with Sienda’s normal information-management practices.
10. Information not considered confidential
Confidentiality obligations do not generally apply to information that:
- is already lawfully in the public domain;
- becomes public through no breach by Sienda;
- was already lawfully known to Sienda;
- is obtained lawfully from another source without confidentiality restrictions;
- is independently developed without use of the client’s confidential information; or
- must legally be disclosed.
11. Separate confidentiality agreements
Where an engagement involves particularly sensitive information, the parties may agree additional confidentiality obligations through a non-disclosure agreement, engagement letter, data-processing agreement or other written agreement.
Where such an agreement conflicts with this general policy, the specific written agreement will prevail.
12. Contact
Questions concerning confidentiality or privacy may be directed to:
Sienda Ltd
Third Floor, 207 Regent St
London W1B 3HH
United Kingdom
Email: privacy@siendaweblines.com
Website: sienda.co.uk
Last updated: 9 September 2026
