Data handling

What happens to anything you send me

Plain language, because the honest version is short.

Who you are dealing with

PackClose is one person: Cody Rasmussen. No employees, no offshore team, no subcontractors, and nobody else is given access to your material. PackClose is a trading name of Lapilo Labs, LLC, a Florida limited liability company in formation; until that formation is effective, the contracting party is Cody Rasmussen personally.

That is a genuine trade-off and you should weigh it. A one-person firm means the smallest possible number of people involved, and no institutional backup if that person is unavailable.

What I ask for

The minimum that answers the question: the packaging rows you already reported, plus the source documents behind a defined sample. Supplier specifications, bills of materials, weighing records, purchase records.

How to send it

A shared folder you control, whether Google Drive, SharePoint, Dropbox or Box, is preferred, because you keep the ability to revoke access and to see what was accessed. Email attachments are accepted but are the weakest option. I will never ask you to email credentials or access tokens.

Where it lives, and for how long

Access

Devices are encrypted at rest and storage access is protected by multi-factor authentication. If a technical reviewer is ever engaged to quality-check a workpaper, you will be told before it happens, that reviewer is bound by equivalent confidentiality obligations, and you can decline.

If your security team has a specific question or a questionnaire, send it. You will get a direct answer rather than a brochure.

If something goes wrong

If I become aware of unauthorised access to your material, you will hear from me within 72 hours of my becoming aware, in writing, with what I know at that point, including where I do not yet know the full extent. You will not learn about it from somewhere else first.

What I am not

Not a law firm, not an accounting firm, not an accredited auditor. I do not file, certify, attest or validate anything with any regulator, and no professional liability insurance is in force at present. Tell your risk team that rather than letting them assume otherwise. Every reporting decision remains yours.

Questions, or a specific requirement from your security team: [email protected]