MEMON SYSTEMS

trust

Where client data goes, who holds access to it, and how each claim below is verified.

This page covers client data in engagements. The privacy policy covers visitors to this website.

1. Jurisdiction and data transfers

I am resident in Pakistan. Companies House publishes every director's country of usual residence on the public register.

The contracting entity is Memon Systems Ltd, Company No. 17284215, registered in England & Wales. Engagements are governed by English law and the exclusive jurisdiction of the English courts (MSA clause 20.12).

Cover is placed with UK underwriters. Work may be performed in any territory outside the USA and Canada, and the policy accepts claims brought in any court outside the USA and Canada — including the English courts named in the contract. Counterparty, governing law, forum and insurer are English or UK throughout. No part of that chain runs through Pakistan.

Adequacy and restricted transfers

Remote access is a transfer. Making personal data accessible to someone outside the UK is a restricted transfer under Chapter V of the UK GDPR (Articles 44–49). Storage location does not change this. Data held in eu-west-2 and read from outside the UK has been transferred.

Pakistan is not covered by UK adequacy regulations, so a transfer to me would require Article 46 safeguards. Under the delivery model below no personal data is made accessible to me: no transfer occurs and no mechanism is required. One is available regardless.

Delivery model: no access

Separation of Duties. Your personnel hold production credentials. I write the Infrastructure-as-Code and hand it over; your engineers or your CI/CD deploy it. I never log into production interactively. Development happens against a structure-preserving masked corpus.

This is the only delivery model. There is no tier that includes access.

Backstop instrument

My UK entity will sign an IDTA (or the UK Addendum to the EU SCCs) plus a completed Transfer Risk Assessment, alongside the DPA. It grants no access. It covers two cases: a masking pass that misses a field or a real document that reaches a development environment, and a buyer whose process requires an IDTA from any supplier outside the UK regardless of the technical position.

An unlawful restricted transfer is the controller's breach. The instrument removes that exposure.

Technical: Masked-with-a-mapping is pseudonymisation, not anonymisation, and pseudonymised data is still personal data. Whether it is anonymous in my hands while you alone hold the mapping is unsettled in law. The backstop instrument removes the dependency on that question.

2. Zero data access

I host nothing. Systems are built into your cloud tenancy and run there. No production data leaves your environment, because nothing is ever copied into mine.

This has an operational consequence: I cannot debug your production system myself. Where that binds, the two routes are break-glass access under your named approval with session recording, or a screen-share with your engineer at the keyboard. Credentials are not held outside those routes.

Handover

Documentation ships with the work: architecture, data flow, deployment procedure and operational runbook. Your engineers are taken through it, and questions on any part of it are answered until the team can run the system without me. Zero access is a constraint on credentials, not on support.

Monitoring

Monitoring telemetry carries no personal data. The pipeline is designed not to log document content or matter identifiers, and a proprietary masking engine — not the public demo harness on /tools — runs over the fields it does emit. Retrieval quality is tracked continuously against public statutory corpora, so drift is detectable without any client document. Updates are built against that public data and signed with the key in §4.

3. No sub-processors

There are no sub-processors in the delivery of client work. The practice is one person.

Where a specialist is engaged for a narrow task, the terms are fixed: they work only in an isolated development environment against synthetic or masked data, hold no production access, commit under a named individual with a GPG-signed identity, and are under NDA and written agreement before starting. Deployment still happens only through the delivery model above.

4. Verifiable artefacts

Each row states the artefact and its status. No certification is listed that is not held.

Artefact Detail and status
UK company Memon Systems Ltd, Company No. 17284215, England & Wales. Registered office: 60 Tottenham Court Road, Office 1418, Fitzrovia, London, W1T 2EW.
ICO registration Reference ZC208663, searchable on the ICO's public register of fee payers. Tier 1. Assessed as not exempt under the self-assessment, and paid.
GPG-signed commits Ed25519, valid to 28 July 2028. Commits from 29 July 2026 are signed; earlier commits are not. A487 3AE7 AEE6 56BF F54E C751 B5C9 93EA B678 58DE Public key · fingerprint also published on /about as a second source.
Police Character Certificate Issued by SSP Hyderabad, Hyderabad District, Pakistan — the jurisdiction of residence. A UK Basic DBS searches UK police records only and would return clear by construction, there being no UK residence history. It has not been obtained.
Professional indemnity £2,000,000 any one claim, unlimited in the aggregate. Nil excess. Retroactive cover unlimited. Dishonest or malicious acts are excluded.
Cyber liability £100,000 total limit in any period of insurance, with individual sections between £20,000 and £100,000 and a £100 excess per claim. A distinct limit from the professional indemnity cover above, covering distinct claims. The two are not combined.
Other cover Public liability £1,000,000 · products liability £1,000,000 · employers' liability £10,000,000. The employers' liability limit is included in the policy as standard. The company has no employees and is not taking any on; it is the same fact as §3.
Territorial and jurisdiction limits Territorial limit — where the work may be performed: worldwide, excluding the USA and Canada. Jurisdiction limit — where a claim may be brought: any court, excluding US and Canadian courts. English courts are within limits.
No cookies, no analytics This website loads no third-party asset and sets no cookie. Stated in full in the privacy policy, and reproducible in a browser network panel.
IDTA · Transfer Risk Assessment Signed as a backstop instrument. Grants no access.
CAIQ · SIG Lite · NIST AI RMF and ISO 42001 crosswalks Control sets designed against, with evidence produced for each. No ISO 27001, SOC 2 or Cyber Essentials certification is held.

5. What I will not do

  • No production data leaves your environment.
  • No client system is written about without written consent, and no client-system numbers are published, including anonymised ones. Everything measured in public runs against public corpora.
  • No named client work is published without your approval.
  • No analysis of your system is published if a conversation ends without agreement.

The diagnostic runs entirely under the no-access model.

Deployment Audit: £500, fixed scope. Planting, hashing, validation and generation run on your side. Scoring runs offline and opens no sockets.

What this costs