Privacy Policy
This Privacy Policy explains how All-Secure Consultancy Ltd (“All-Secure”, “we”, “us”) collects, uses, and protects personal data. It applies to visitors of all-secure.co.uk, people who contact us, and clients of our services.
1. Information we collect
1.1 Information you provide directly
- Contact form submissions: name, email, company, service of interest, and the message you send.
- Client engagement data: information shared under a signed scoping or services agreement, including technical details necessary to deliver security services.
We normally collect personal data directly from you. Where your employer or another organisation engages us, we may receive your business contact details from them or from an authorised representative.
Incidental access during testing. When we perform security testing, our consultants may incidentally access personal data held within systems that are in scope. Such access is limited to what is necessary to perform the agreed services and is governed by our Data Processing Agreement, under which the client is the controller and All-Secure is the processor.
1.2 Report access credentials
We do not offer public accounts or sign-in on this website. Where we provide you with credentials to access a report or deliverable, we collect only the details needed to create and secure that access, protected with a session cookie and optional two-factor authentication. We do not use third-party or social sign-in.
1.3 Information collected automatically
- Server logs: IP address, user-agent, request URLs, and timestamps, retained for up to 30 days for security and troubleshooting.
- Cookies: we use only strictly necessary cookies required for the security and operation of the website (for example session management). We do not use advertising or analytics cookies.
2. How we use your data
- To respond to enquiries and provide the services you request.
- To provide and secure access to any reports or deliverables we share with you.
- To meet our legal, regulatory, and contractual obligations.
- To protect our systems from abuse, fraud, and unauthorised access.
3. Legal bases (UK GDPR)
- Contract: where you contact us to request information, a quotation or services, and to deliver an engagement.
- Legitimate interests: to respond to enquiries, operate and secure our business and services. Where we rely on legitimate interests, we balance them against your rights and only proceed where they are not overridden.
- Consent: only where you specifically opt in, such as to receive marketing communications. You may withdraw consent at any time.
- Legal obligation: where required by applicable law.
4. Marketing
We do not send marketing communications unless you have specifically requested them or applicable law permits it. Where we do, you can opt out at any time using the unsubscribe link or by emailing [email protected].
5. Sharing and disclosure
We do not sell personal data. We share data only with:
- Vetted sub-processors strictly necessary to operate the service, namely cloud hosting providers, secure report delivery, email providers and, where applicable, encrypted backup storage.
- Law enforcement or regulators where legally compelled.
- Professional advisers bound by confidentiality.
6. Data retention
- Contact form submissions: retained for up to 24 months unless a client relationship begins.
- Engagement records, reports and contractual documentation: retained for the duration of our engagement and for 7 years thereafter, in line with UK tax and professional-indemnity requirements.
- Report-access credentials: deleted within 30 days after access to the report is withdrawn.
7. Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. Where our processing is based on consent, you have the right to withdraw that consent at any time, which does not affect processing already carried out. To withdraw consent, or to exercise any other right, email [email protected]; we respond within one month.
You also have the right to lodge a complaint with the Information Commissioner’s Office (www.ico.org.uk) if you believe your personal data has been processed unlawfully.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
8. International transfers
All-Secure is UK based and we do not routinely transfer personal data outside the UK. Where a transfer becomes necessary, we will ensure appropriate safeguards are in place, such as an adequacy decision or the UK International Data Transfer Agreement / Addendum.
9. Children
Our website and services are intended for businesses and are not directed at children under 18. We do not knowingly collect personal data relating to children.
10. Security
We apply the security practices we recommend to our clients: least-privilege access, strong authentication, encryption in transit (TLS 1.3) and at rest, logging and monitoring, and regular security assessments and testing.
11. Responsible disclosure
No system is perfect. If you believe you have identified a security vulnerability affecting our website or services, please disclose it responsibly to [email protected]. We welcome such reports and will not pursue researchers acting in good faith.
12. Changes
We may update this policy. We will post updates on this page and revise the “last updated” date above.
13. Contact & company details
All-Secure Consultancy Ltd
Registered in England & Wales, Company No. 17276857
Registered office: 128 City Road, London, EC1V 2NX
Data protection enquiries: [email protected]
Given our size and the nature of our processing, we are not required to appoint a Data Protection Officer. Data protection is handled by the company directors.