Skip to content

Trust

These are the practices we actually apply, and each one has a counterpart in the contract.

Scope and acceptance criteria in writing

We define the scope, control points and deliverables in writing before work begins. That same document states what counts as accepted, and a working demo is never acceptance on its own.

Least-privilege access

We ask for the narrowest access that lets the agreed workflow run, scoped to the systems and records it actually touches.

Human approval before high-impact actions

Irreversible, financial, legal, account-changing or externally published actions wait for a named person to approve them. The system prepares, a person decides.

Evaluation before production

Every workflow is measured against a representative test set with its edge cases before it handles real work, and the same set is rerun after changes.

Monitoring, rollback and a safe-disable path

Live workflows are observable, and every one of them has a defined way to be rolled back or switched off without leaving work stranded.

Data minimisation and agreed retention

We read the fields the workflow needs and no more. How long anything is kept is decided per engagement rather than left to a default.

Third-party dependency transparency

Which providers are used, where data is processed, how long it is retained and who can access it are agreed together with scope before a project goes live. Dependencies are disclosed, including the ones outside our control.

Access revocation stays with you

Access is granted from your side and can be withdrawn from your side at any time, without asking us first and without depending on our systems.

How we approach data

What KVKK, GDPR and UK GDPR require depends on your role, the data involved and the use case. We build workflows with the least data that works, human oversight and defined logging boundaries. The specific controls are agreed for each engagement. Where high-risk personal data is involved, an impact assessment may be needed before work starts.

Company details

Filova Ltd is registered in the UK. We provide services in English and Turkish.

  • FILOVA LTD
  • Company No: 17263134
  • Registered in England and Wales
  • 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
  • info@filova.io

Where our role ends

Filova provides implementation support. What we deliver is not legal advice and does not replace independent assurance or audit. For a final view on regulatory obligations you need your own legal counsel.