Legal

Privacy policy

This policy explains what personal information ISO Security collects through this website, why we collect it, how long we keep it and what rights you have.

Who we are

ISO Security is a UK-based information security consultancy providing ISO/IEC 27001:2022 implementation and ongoing CISO services. For the purposes of UK data protection law we are the data controller for personal information collected through this website. You can contact us at info@isosecurity.co.uk.

Information we collect

  • Enquiry information. When you contact us through the website or by email, we collect your name, organisation, email address and the content of your enquiry.
  • Correspondence. Emails and messages you send us, and our replies.
  • Technical information. Standard information recorded when a website is accessed, which may include IP address, browser type, referring page and pages viewed.

We do not ask for special category personal data through this website, and you should not include confidential or sensitive information in an initial enquiry.

Why we use it and our lawful basis

  • To respond to your enquiry and provide services. Lawful basis: performance of a contract, or steps taken at your request before entering into a contract.
  • To manage our business, records and correspondence. Lawful basis: our legitimate interests in operating and administering the consultancy.
  • To meet legal and regulatory obligations. Lawful basis: compliance with a legal obligation.

We do not sell personal information, and we do not use it for automated decision-making or profiling.

Sharing

We may share personal information with service providers who support our business, such as email, IT and website hosting providers, and with professional advisers or authorities where we are legally required to do so. Providers act on our instructions and are required to protect the information they process for us.

Retention

Enquiries that do not lead to an engagement are retained only for as long as they remain relevant to a possible engagement, and are then deleted. Records relating to client engagements are retained for the duration of the engagement and afterwards for the period necessary to meet contractual, legal, tax and professional obligations.

Security

As an information security consultancy we apply appropriate technical and organisational measures to protect personal information, including access control, encryption in transit and controlled retention. No transmission over the internet can be guaranteed to be completely secure.

International transfers

Our service providers may process information outside the UK. Where that happens we take steps to ensure an appropriate level of protection, using recognised safeguards such as the UK International Data Transfer Agreement or Addendum.

Your rights

Under UK data protection law you have rights to access your personal information, request correction or erasure, restrict or object to processing, request portability where applicable, and withdraw consent where processing relies on consent. To exercise any of these rights, contact info@isosecurity.co.uk.

If you are unhappy with how we have handled your information you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve the matter first.

Cookies

Information about cookies and similar technologies used on this website is set out in our cookie policy.

Changes

We may update this policy from time to time to reflect changes to our services or legal obligations. The current version is always published on this page.