Security & data handling

Website data and client-project data are different things.

This page describes the public Sirrius website. Every client workflow receives its own written data map, provider choices, approval rules, and retention decisions before implementation.

The principles

How we handle your data.

We collect as little as possible

The website collects the information you deliberately submit: contact details, project descriptions, booking details, and optional assessment answers when you request an emailed result. Do not submit health information or other protected data through these public forms.

The Fit Check is private by default

Your score is computed on your device. If you request an emailed breakdown, the answers are sent once to the website service and Resend to create and deliver that email. The application does not write them to a database.

Encrypted in transit

Connections to the website and its forms use HTTPS. Hosting and email providers necessarily process submitted content while delivering the service, so this is transport encryption rather than end-to-end encryption.

Provider terms are documented per build

A client system may use different providers and configurations. Before implementation, the selected provider, account type, contractual data treatment, retention setting, and available data region are documented for that engagement.

Guardrails are part of the build

The workflow specification identifies what data the system may use, who can access it, which outputs need review, and what the system must never send automatically. Project-specific controls are agreed in writing.

Deletion on request

You can ask us to delete website contact information by emailing hello@sirrius.net. Project data is handled under the retention and termination terms agreed for that engagement.

Who else touches your data

The website services that process submissions.

These providers support the public website. A client project may use a different set of providers, which are documented for that engagement before work begins.

Stripe

Payment processing

Billing details, handled entirely by Stripe. We never see or store full card numbers.

Resend

Transactional email

Your email address and the contents of booking confirmations and replies.

Vercel

Hosting

Serves the site and executes form handlers. Platform logs and retention are governed by the active Vercel account configuration.

Looking for the formal version? Our Privacy Policy covers your rights and how to exercise them.

A security question we have not answered?

If your organization needs specifics before we start, ask. We will give you a straight answer in plain language, not a compliance brochure.