Trust center · Privacy
Customer context stays bounded by purpose and audience.
The Workspace separates public intake, client-visible delivery context and Wythin-only engineering records instead of treating every field as equally shareable.
Data boundaries
WythinForge stores relationship and delivery metadata: organizations, requests, messages, attachments, estimates, decisions, previews, releases, owners and next actions. Operational transaction data remains in the customer systems that own it.
- Internal engineering references, internal messages and internal files remain outside client-readable projections.
- Attachments remain private and are exposed through signed, expiring URLs after authorization checks.
- Telemetry allowlists exclude request text, file contents, e-mail addresses, company names and authentication tokens.
- Optional analytics, browser diagnostics and external embeds are disabled until the visitor grants the corresponding consent category.
Control and accountability
Significant mutations produce append-only activity. Immutable estimate decisions and versioned delivery artifacts keep later changes distinguishable from the record a customer reviewed.
The legal privacy notice describes processing purposes, legal bases and data-subject rights. Contract-specific retention and processor terms belong in the applicable agreement and DPA.
