Skip to main content

Data Security & Confidentiality

Last Updated: August 2026

Protecting client information is a fundamental part of how Pinnacle works.

Our advisory and digital transformation engagements can involve access to business strategies, customer information, CRM data, internal processes, financial information, documents, and other confidential material. Our conferences and forums may also involve attendee, speaker, sponsor, and partner information.

We treat the security of that information as a professional responsibility, not simply a technology issue.

1. Our Approach to Data Security

Pinnacle applies practical safeguards based on the nature of the information, the systems being used, and the requirements of each engagement.


Our approach is built around several principles:

  • Collect and access only the information required.
  • Limit access to people who legitimately need it.
  • Use established and reputable technology platforms.
  • Protect accounts and systems with appropriate security controls.
  • Avoid unnecessary duplication or storage of sensitive information.
  • Maintain confidentiality throughout and after an engagement.
  • Address security concerns promptly when identified.


No technology environment can eliminate every risk. Our objective is to reduce unnecessary exposure and handle client information responsibly throughout its lifecycle.

2. Access Control

Access to client information and systems is provided only where required to perform authorized work.


Where appropriate, we use measures such as:

  • Individual user accounts.
  • Role-based permissions.
  • Strong passwords.
  • Multi-factor authentication.
  • Controlled administrative access.
  • Regular review of user access.
  • Removal of access when it is no longer required.


When implementing systems for clients, we also encourage access structures that reflect actual roles and responsibilities rather than providing unnecessary organization-wide access.

3. Cloud Platforms and Third-Party Systems

Pinnacle uses established cloud-based business and technology platforms to support our operations and client engagements.

These platforms may provide security capabilities such as encryption, authentication controls, access management, backups, monitoring, and infrastructure protection.

Where client information is processed through a third-party platform, the security and privacy practices of that provider also apply.

We do not claim that Pinnacle independently controls the underlying security infrastructure of third-party cloud platforms.

4. Digital Transformation and Client Systems

Our role in digital transformation frequently requires us to configure systems that contain important business and customer information. Security therefore forms part of the implementation process.


Depending on the project, this may include defining:

  • User roles and permissions.
  • Data access levels.
  • Administrative privileges.
  • Authentication requirements.
  • Data sharing rules.
  • Workflow permissions.
  • Integration access.
  • Document access.
  • User onboarding and offboarding procedures.


The objective is not simply to make a system functional. It is to help ensure that people have access to the information they need without unnecessarily exposing information they do not.

5. Client Credentials

Where access credentials are required to perform an engagement, they should be handled carefully and shared only through appropriate methods.


Whenever possible, we prefer clients to create individual authorized user accounts rather than share primary administrator credentials.


Passwords and other authentication information should not be distributed unnecessarily or retained longer than required.

6. Data Minimization

We seek to limit the amount of personal and confidential information collected, transferred, or retained to what is reasonably necessary.

Reducing unnecessary data is one of the simplest ways to reduce security risk.

Where information is no longer required for an engagement or legitimate business purpose, it may be deleted, returned, archived, or otherwise handled in accordance with applicable contractual, operational, and legal requirements.

7. Confidential Information

Information received through our work is treated as confidential where its nature, the circumstances, or contractual arrangements reasonably require confidentiality.


This may include:

  • Business strategies and plans.
  • Customer and prospect information.
  • CRM and sales data.
  • Financial and commercial information.
  • Internal reports and documents.
  • Employee information.
  • Contracts and proposals.
  • Proprietary processes and methodologies.
  • Attendee and registration information.
  • Sponsor and partner information.


Confidential information is not used for purposes unrelated to the engagement without appropriate authorization.

8. Event and Registration Data

Conferences and forums can involve the collection of personal information from attendees, speakers, sponsors, partners, and other participants.

We seek to collect only information reasonably required to manage participation, communication, event operations, reporting, and related activities.

Access to registration information is limited according to operational requirements. Where external registration, payment, communication, or event technology platforms are used, information may also be processed by those providers.

9. Payment Information

Where online payments are required, payment transactions may be processed through specialized third-party payment providers.

Pinnacle does not seek to collect or retain complete payment card information unless there is a legitimate operational requirement and appropriate safeguards are in place.

The security practices and terms of the relevant payment provider apply to information processed through its systems.

10. Responsible Use of AI

Artificial intelligence tools can create additional data security and confidentiality considerations.

We do not consider AI platforms an appropriate destination for confidential client information simply because they make work faster.

Sensitive or confidential information should not be entered into AI systems where doing so would create inappropriate disclosure, privacy, contractual, or security risks.

Where AI tools are used in our work, their use should be consistent with our confidentiality obligations and the requirements of the engagement.

11. Our People and Partners

Technology alone does not provide effective data security.

Employees, consultants, contractors, and other parties working on behalf of Pinnacle are expected to handle information responsibly and follow applicable confidentiality, access, and security requirements.

Where external providers require access to client information, that access should be limited to what is reasonably necessary for their role.

12. Security Incidents

If we become aware of a suspected security incident involving information under our responsibility, we will assess the situation and take reasonable steps to contain and address it.

Where appropriate, this may include working with the affected client, technology provider, or other relevant parties and taking action consistent with contractual and legal requirements.

13. Shared Responsibility

Data security is most effective when everyone involved takes responsibility for it.

Pinnacle is responsible for the systems, access, and information under our control. Clients remain responsible for their own internal security policies, user practices, devices, credentials, access decisions, and systems outside our control.

For digital transformation engagements, we work with clients to establish appropriate controls, but maintaining those controls over time requires continued attention by the organization.

14. Our Commitment

Clients trust Pinnacle with information that can be important to their operations, customers, stakeholders, and reputation.

We take that trust seriously.

Our approach is straightforward: minimize unnecessary access, use appropriate safeguards, work with reputable technology providers, protect confidential information, and make responsible decisions about how information is collected, accessed, shared, stored, and used.