01
Start with a boundary
Every engagement starts with an audit of the workflow, systems, people, and decisions involved. Before we build, we agree what the system is allowed to see, change, and own.
- Access is scoped to the audit or implementation.
- The client keeps control of its accounts, data, and permissions.
- We do not ask for broad access when a narrower path will do.
02
Human review is part of the system
Automation is not a reason to remove judgement from a consequential workflow. We define approval rules, escalation paths, and the point where a person takes over.
- Human review is used where the scope, confidence, or consequence requires it.
- Operational decisions should have an owner, not disappear into a model.
- Logs and handoff notes make the decision path inspectable.
03
Ownership is written down
At handover, the important parts are named: code, data, accounts, documentation, maintenance, and the person responsible for the next decision.
Kratt can remain the managing technical partner for monitoring, fixes, and roadmap decisions. If the client takes over, we leave a documented operating path rather than a black box.
04
Retention and deletion have a reason
We retain information only for the work it supports. Our operating policy distinguishes cold prospect records, active client work, and call recordings rather than treating everything as permanent.
- Cold prospect dossiers are reviewed after 90 days.
- Client engagement records are reviewed after two years and personal data is redacted where appropriate.
- Call recordings and transcripts are retained for up to one year unless they are still needed for a live deal reference.
- Deletion requests are handled as a human-reviewed redaction or erasure task.
05
Backups are documented, not exaggerated
We maintain weekly Git bundle backups for the brain and active repositories and have tested restoring from a backup. That is the practice we can currently stand behind.
What this does not mean: we do not present the current setup as automated off-site disaster recovery, a certified business-continuity programme, or a universal uptime promise.
06
Our GDPR position
Propertybase OÜ is an Estonian company. Depending on the workflow, we may act as a controller for our own prospect and contact records or as a processor when building and operating a system for a client.
We work from purpose limitation, data minimisation, access control, retention, and human review. We do not claim a certification we do not hold. For a specific engagement, the contract and any required data-processing terms define the exact responsibilities.
Our Privacy Policy explains visitor and contact data in more detail.
07
What we will not pretend
Trust is more useful when it includes the edges. We do not claim that every AI system should be autonomous, that every workflow needs a model, or that a launch date is a guarantee of business results.
The audit identifies the highest-value boundary. We then build, measure, review, and change the system with the people who own the work.
Want to understand your boundary?
Start with the free 30-minute audit. Karl is on the call and will say plainly if we are not the right partner.
Book the audit call →