Security & privacy

One system, and no way from one house into another.

A client book is the most valuable thing a tailoring house owns. This page says plainly how yours is kept separate from every other house's, who can see it, where it is held and what we do not claim. Written by us, about our own software — not a badge from anyone else.

Keeping houses apart

What does “multi-tenant” actually mean here?

AtelierSuite runs as one carefully partitioned system rather than a separate copy per house. Every house — every tenant — has its own space inside it: its own staff, clients, commissions, cloth, diary, papers, invoices and settings.

The advantage of one system is that every house gets the same maintained, patched, backed-up software on the same day, instead of an ageing private copy nobody has looked at in a year. The obligation that comes with it is separation, and that is the part we treat as the product's foundation rather than a setting.

How are two houses kept apart?

Every record in the system carries the house it belongs to. Nothing is stored loose. When your workroom asks for its clients, the request is not “give me the clients” — it is answered as “give me the clients belonging to the house this signed-in person works for”.

That rule is enforced inside the database, not in the app. Row-level security is switched on for every table without exception, and each table's policy compares the row's house against the house on the caller's own session. A request for another house's row does not come back empty because the screen filtered it out; it comes back empty because the database will not release it.

This matters because it holds even if a page, an export, a report or a future feature is written carelessly. The last line of defence is the store itself, so a mistake in the interface cannot become a leak between houses.

What can our own staff see, and can that be limited?

Inside a house, access is decided by the role a person holds — held in its own table of roles rather than as a flag on their profile, and checked server-side every time. A cutter, a front-of-house and the house's principal do not see the same things: money, costs and margins, staff hours and house settings are held behind higher standing.

Roles are changed by the house, not by us, and every change is written to the house's audit trail with who made it and when.

One of our people also works for another house. Is anything shared?

No. A person is a member of a house, and their session is scoped to the house they are working in. Being known to two houses gives neither house sight of the other's records, clients or figures — the same rule refuses the request in both directions.

Can our clients see anything beyond their own file?

A client's page is scoped to that one client's record within your house: their commissions, their fittings, their invoices, their appointments. There is no route from a client page into your book, your other clients, your costs or your margins.

Client links are long, unguessable and specific to that client, and a house can withdraw one at any time. Anything sensitive stays behind sign-in rather than being cached on the device.

Can you — AtelierSuite — read our client book?

Not as a matter of course. Support runs from the same house-scoped rules the house uses; day-to-day help does not involve reading your records.

There is a small operator level of access, used to open and close houses, take payment for the subscription and investigate a fault a house has reported to us. It is limited to the people who run AtelierSuite, and what it touches is logged.

If a fault genuinely needs someone to look at a record, we would rather ask you than help ourselves — and you can always ask us afterwards what was looked at.

What stops a mistake in one house's setup affecting another?

A house's own configuration — its measurement fields, production stages, letterhead, cloth list, rush surcharges — lives inside that house's space, so nothing a house changes about its own way of working can reach across.

Automated work such as reminders, invoice dispatch and digests runs per house, and the internal jobs that carry it are stamped with the house they belong to for the same reason every record is.

Privacy, handling and honesty

Who is the data controller — you or us?

For your clients' records, the house is the controller and AtelierSuite is the processor: we hold and process the records on your instructions, and the data processing agreement in our legal pages sets out what we may and may not do with them.

For your own account with us — your staff logins, your subscription, your correspondence — we are the controller.

Where is the data held, and is it encrypted?

Records are held on managed UK infrastructure. Traffic between a browser and the system travels over HTTPS, and the managed database and file storage encrypt what they hold at rest.

The third parties that touch personal data — the hosting platform, the mail sender, the card processor, the model gateway behind the assistant, and the optional bank-feed providers — are each named, with their purpose and location, in the privacy notice. That list is the authoritative one; we would rather you read it than take a summary from us.

Does the assistant do anything with our records we cannot see?

The assistant reads your house's records under the same house-scoped rules a member of staff does, so it cannot reach into another house.

It drafts; it does not act. An invoice, an appointment, a message or a change it proposes waits for a person in the house to read it and confirm it, and both the draft and the confirmation are recorded.

The model gateway it sends a question to is named in the privacy notice, along with what is sent. If a house would rather not use the assistant at all, it can be left switched off.

Can we prove who did what?

Yes. Stage changes, measurement edits, invoices, payments, role changes and confirmations of assistant drafts are written to the house's own trail with the person and the time. It is readable inside the house rather than being something you have to ask us for.

How long do you keep things, and what happens if we leave?

Each kind of record has a stated retention period and a reason for it, listed in the legal pages — some, such as invoices, are kept because tax law requires it.

If a house leaves, its book is exportable, and after that its records are deleted on the schedule set out in the data processing agreement. A client can ask their house for a copy, a correction or an erasure at any time, and there is a page for making that request.

What about backups and losing something by accident?

The managed platform takes regular backups of the database, and deletions inside the workroom are generally reversible for a period rather than instant and final, so a mis-click on a Friday afternoon is recoverable.

Are you certified?

We do not claim any certification, audit report or compliance badge, and you should be wary of a supplier of our size that does without showing you the document. What we will do is answer a security questionnaire in writing, name every third party that touches your data, and describe exactly how separation is enforced — which is what this page is.

Card details are entered on the card processor's own page and never reach our code, servers or logs. We never hold or move house or client money.

We think we have found a weakness. How do we tell you?

Write to us with what you saw and how you came across it. We will acknowledge it, and we would ask that you do not test against another house's data or take more of it than the minimum needed to show the problem.

If something does go wrong at our end, our incident procedure is published, and houses affected are told — not quietly patched.