Privacy Policy
How we handle personal data, what we collect and why, and the control you have over it.
1. Introduction
InfoSec Governance ("we", "our" or "us") respects your privacy and is committed to protecting your personal data. This policy explains what we collect when you visit https://infosecgovernance.com, why we collect it, what we do with it, and the rights you have.
We have deliberately built this website to collect as little personal data as possible. There is no analytics tracking, no advertising pixel, and no third-party script running on these pages. The only personal data we receive through the site is what you choose to send us in an enquiry.
2. Who we are
InfoSec Governance is the data controller for personal data processed through this website. You can reach us at sales@infosecgovernance.com for any privacy matter, including to exercise the rights described below.
3. Data we collect
We collect the following categories of personal data:
- Enquiry data. When you submit our contact form we collect your name, email address, and — where you choose to provide them — your organisation name, phone number, the service you are interested in, and the content of your message.
- Technical data. Our hosting provider automatically records standard web server logs, which include your IP address, the pages requested, the date and time, your browser type and the referring page. These logs are generated by the hosting infrastructure for security and diagnostic purposes.
- Session data. A single strictly necessary cookie is set when you load a page, which allows the contact form to protect against cross-site request forgery. See our Cookie Policy for detail.
We do not collect special category data, we do not carry out any automated decision-making or profiling, and we do not buy personal data from third parties.
4. How and why we use it
We only use personal data where the law allows us to. The lawful bases we rely on are:
| What we do | Data used | Lawful basis |
|---|---|---|
| Respond to your enquiry and discuss whether we can help | Enquiry data | Legitimate interests — responding to a request you initiated |
| Provide a proposal, and deliver services if you engage us | Enquiry data | Performance of a contract, or steps taken at your request before entering one |
| Keep the website secure and diagnose faults | Technical data, session data | Legitimate interests — securing and maintaining our systems |
| Meet legal, accounting and regulatory obligations | Enquiry data where it forms part of a client record | Compliance with a legal obligation |
We do not use your details for marketing. Submitting an enquiry does not add you to a mailing list, and we do not sell or rent personal data to anyone under any circumstances.
5. Who we share it with
We share personal data only where it is necessary to operate, and only with parties bound by appropriate confidentiality and data protection obligations:
- Our hosting provider, which operates the servers this website runs on.
- Our email provider, which delivers and stores enquiry emails.
- Our scheduling provider, if you choose to book a consultation. Booking is optional and takes place on that provider's own platform under its own privacy policy.
- Professional advisers and authorities, where we are legally required to disclose.
We do not share personal data with advertisers, data brokers or analytics networks.
6. International transfers
Some of the providers described above may process data outside your country of residence. Where personal data is transferred internationally, we rely on an appropriate safeguard recognised under applicable data protection law — such as an adequacy decision or standard contractual clauses — so that your data continues to receive an equivalent level of protection.
7. How long we keep it
- Enquiries that do not lead to an engagement: retained for up to 24 months, then deleted.
- Client records: retained for the duration of the engagement and for 6 years afterwards, to meet legal, contractual and accounting obligations.
- Server logs: retained by our hosting provider for a short rolling period, typically no more than 30 days.
- Session cookie: deleted when you close your browser.
You can ask us to delete your enquiry sooner at any time — see your rights below.
8. How we protect it
Security is our profession, and we hold our own systems to the standard we advise for clients. Measures include encryption in transit across the whole site, strict access control on the mailboxes that receive enquiries, multi-factor authentication on administrative accounts, a hardened web server configuration with a strict content security policy, and regular patching.
No transmission over the internet can be guaranteed completely secure. If you need to send us genuinely sensitive material — for example the findings of a security assessment — tell us and we will arrange an encrypted channel rather than using the contact form.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase your data where we no longer have a good reason to keep it.
- Restrict our processing while an issue you have raised is resolved.
- Object to processing carried out on the basis of legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where we rely on consent.
To exercise any of these, email sales@infosecgovernance.com. We respond within one month and there is no charge. We may ask you to verify your identity before we act on a request.
10. Cookies
This site sets one strictly necessary cookie and no others. There are no analytics, advertising or social media cookies. Full detail is in our Cookie Policy.
11. Children
Our services are directed at organisations, not individuals, and this website is not intended for anyone under 16. We do not knowingly collect data relating to children. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We review this policy periodically and will update the "last updated" date above whenever it changes. Where a change materially affects how we handle your data, we will take reasonable steps to bring it to your attention.
13. Contact and complaints
For any question about this policy or how we handle personal data, contact sales@infosecgovernance.com.
If you are not satisfied with our response, you have the right to complain to your local data protection authority. In the United Kingdom that is the Information Commissioner's Office (ICO); within the EEA it is the supervisory authority in your country of residence. We would appreciate the chance to address your concern first.