Skip to content

Legal

Privacy Policy

Last updated 7 September 2026

This policy explains what personal data innsecs collects, why we collect it, how long we keep it, and the rights you have over it.

01Who we are

innsecs is an information security consultancy providing certification support and security testing services. For the purposes of data protection law we act as a data controller for the personal data described in this policy, and as a data processor for personal data we encounter while delivering services to a client.

You can reach us about anything in this policy at security@innsecs.com.

02What we collect

We keep data collection deliberately minimal. We collect only what we need to respond to you and to deliver our services.

  • Enquiry details you submit through our contact form: name, work email, company, the service you are interested in, your timeline, and the message you write
  • Correspondence: emails, meeting notes and messages exchanged during a scoping conversation or an engagement
  • Engagement data: contract details, billing information, and the client-side contacts we work with during delivery
  • Technical data from testing engagements, which may incidentally include personal data present in the systems we are authorised to test

03What we do not do

  • We do not sell, rent or trade personal data to anyone
  • We do not use enquiry details for unrelated marketing or add you to a mailing list without asking
  • We do not run advertising trackers, fingerprinting scripts or third-party analytics that profile individuals across sites
  • We do not retain testing data beyond the retention period agreed in the engagement contract

04Why we process it, and our lawful basis

  • To respond to your enquiry and prepare a proposal, legitimate interests, and steps taken at your request prior to entering a contract
  • To deliver contracted services, performance of a contract
  • To meet legal, tax and professional record-keeping obligations, legal obligation
  • To secure our own systems and detect abuse of this website, legitimate interests

05Testing data and client confidentiality

Security testing engagements generate sensitive material: findings, evidence, screenshots and occasionally credentials or data extracts. This material is handled under the confidentiality terms of the engagement contract.

We store testing artefacts encrypted, restrict access to the consultants assigned to the engagement, and delete them at the end of the agreed retention period, by default twelve months after the final report, or sooner on written request.

06How long we keep data

  • Enquiries that do not become engagements: up to 24 months, then deleted
  • Engagement records and reports: 7 years, where required for legal, professional and insurance purposes
  • Testing artefacts and evidence: 12 months by default, or as agreed in the engagement contract
  • Billing and tax records: as required by applicable tax law

07Who we share it with

We share personal data only where it is necessary to run the business, and only with providers bound by contractual confidentiality and data protection obligations.

  • Email and productivity providers used to correspond with you and store documents
  • Our transactional email provider, used to deliver contact-form submissions to our inbox
  • Accounting and payment providers, for invoicing
  • Professional advisers and insurers, where required
  • Law enforcement or regulators, where we are legally compelled

08International transfers

Some of our providers process data outside your country of residence. Where personal data is transferred out of the UK or EEA we rely on adequacy decisions or Standard Contractual Clauses, together with appropriate technical measures such as encryption in transit and at rest.

09Your rights

Depending on where you live, you may have the following rights. We will respond to any request within one month.

  • Access a copy of the personal data we hold about you
  • Have inaccurate data corrected
  • Have data erased, where no overriding legal or contractual obligation applies
  • Restrict or object to processing based on legitimate interests
  • Receive your data in a portable, machine-readable format
  • Withdraw consent at any time, where processing is based on consent
  • Complain to your data protection authority

10Cookies and analytics

This website does not set advertising or cross-site tracking cookies. Any strictly necessary cookies exist solely to make the site function. If we introduce privacy-respecting, aggregate analytics in future, we will update this policy before doing so.

11Security

We would be poor advisers if we did not hold ourselves to the standards we recommend. We use multi-factor authentication across business systems, encrypt data at rest and in transit, apply least-privilege access, maintain audit logging, and review access on a regular schedule.

If you believe you have found a vulnerability in our systems, please use our responsible disclosure process rather than the contact form.

12Changes to this policy

We may update this policy as our services or obligations change. The date at the top of this page reflects the most recent revision. Material changes affecting existing clients will be communicated directly.

13Contact

For any privacy question, data subject request, or complaint, email security@innsecs.com with "Privacy" in the subject line.

This document is provided as a starting point and does not constitute legal advice. Have it reviewed by a qualified lawyer in your jurisdiction before you rely on it.