All-Secure. ← Home
// legal

Privacy Policy

Last updated: 3 July 2026

This Privacy Policy explains how All-Secure Consultancy Ltd (“All-Secure”, “we”, “us”) collects, uses, and protects personal data. It applies to visitors of all-secure.co.uk, people who contact us, and clients of our services.

We are the data controller. Registered in England & Wales. For any data protection enquiry, or to exercise your rights, email [email protected].

1. Information we collect

1.1 Information you provide directly

We normally collect personal data directly from you. Where your employer or another organisation engages us, we may receive your business contact details from them or from an authorised representative.

Incidental access during testing. When we perform security testing, our consultants may incidentally access personal data held within systems that are in scope. Such access is limited to what is necessary to perform the agreed services and is governed by our Data Processing Agreement, under which the client is the controller and All-Secure is the processor.

1.2 Report access credentials

We do not offer public accounts or sign-in on this website. Where we provide you with credentials to access a report or deliverable, we collect only the details needed to create and secure that access, protected with a session cookie and optional two-factor authentication. We do not use third-party or social sign-in.

1.3 Information collected automatically

2. How we use your data

3. Legal bases (UK GDPR)

4. Marketing

We do not send marketing communications unless you have specifically requested them or applicable law permits it. Where we do, you can opt out at any time using the unsubscribe link or by emailing [email protected].

5. Sharing and disclosure

We do not sell personal data. We share data only with:

6. Data retention

7. Your rights

Under UK GDPR you have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. Where our processing is based on consent, you have the right to withdraw that consent at any time, which does not affect processing already carried out. To withdraw consent, or to exercise any other right, email [email protected]; we respond within one month.

You also have the right to lodge a complaint with the Information Commissioner’s Office (www.ico.org.uk) if you believe your personal data has been processed unlawfully.

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.

8. International transfers

All-Secure is UK based and we do not routinely transfer personal data outside the UK. Where a transfer becomes necessary, we will ensure appropriate safeguards are in place, such as an adequacy decision or the UK International Data Transfer Agreement / Addendum.

9. Children

Our website and services are intended for businesses and are not directed at children under 18. We do not knowingly collect personal data relating to children.

10. Security

We apply the security practices we recommend to our clients: least-privilege access, strong authentication, encryption in transit (TLS 1.3) and at rest, logging and monitoring, and regular security assessments and testing.

11. Responsible disclosure

No system is perfect. If you believe you have identified a security vulnerability affecting our website or services, please disclose it responsibly to [email protected]. We welcome such reports and will not pursue researchers acting in good faith.

12. Changes

We may update this policy. We will post updates on this page and revise the “last updated” date above.

13. Contact & company details

All-Secure Consultancy Ltd
Registered in England & Wales, Company No. 17276857
Registered office: 128 City Road, London, EC1V 2NX
Data protection enquiries: [email protected]

Given our size and the nature of our processing, we are not required to appoint a Data Protection Officer. Data protection is handled by the company directors.