Last updated: 28 July 2026
1. About this notice
This privacy notice explains how Safestorm Ltd collects, uses, stores and protects personal information when you:
- visit our website;
- contact us through an online form, email or telephone;
- request information about our services;
- discuss or enter into a business relationship with us;
- act as a representative, employee, contractor or supplier of an organisation that works with us.
Safestorm Ltd is the controller responsible for the personal information described in this notice.
2. Who we are
Safestorm Ltd is a private limited company registered in England and Wales.
Company number: 17333583
Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
Privacy contact: privacy@safestorm.co.uk
References in this notice to “Safestorm”, “we”, “us” or “our” mean Safestorm Ltd.
3. Personal information we collect
The personal information we collect depends on how you interact with us.
Information you provide
This may include:
- your name;
- your job title and organisation;
- your business email address;
- your telephone number;
- details included in an enquiry or message;
- information about the security services you are considering;
- proposed scope, testing dates and commercial requirements;
- correspondence and records of discussions;
- billing, contractual and supplier information;
- feedback or testimonial information where provided.
Please do not submit passwords, authentication tokens, vulnerability details, personal datasets or other sensitive client information through the general website enquiry form.
Where sensitive information needs to be exchanged for an engagement, we will agree an appropriate secure transfer method.
Information collected automatically
When you visit the website, our hosting and security providers may process limited technical information such as:
- IP address;
- browser and device type;
- operating system;
- requested pages;
- timestamps;
- referral information;
- security, diagnostic and error logs.
This information may be required to deliver the website, maintain its security and investigate faults or malicious activity.
4. How we use personal information
We may use personal information to:
- respond to enquiries;
- understand your requirements;
- arrange scoping discussions;
- prepare proposals, quotations and statements of work;
- provide contracted services;
- administer client, supplier and business relationships;
- issue and manage invoices;
- maintain business and accounting records;
- protect our website, systems, personnel and clients;
- detect, investigate and prevent fraud, misuse and security incidents;
- improve our website, services and internal processes;
- establish, exercise or defend legal claims;
- comply with legal, regulatory and professional obligations;
- send relevant business communications where permitted by law.
We do not sell personal information.
5. Our lawful bases
Depending on the circumstances, we rely on one or more of the following lawful bases.
Steps before entering into a contract
We may process your information to respond to a request, discuss an engagement, prepare a quotation or take other steps at your request before entering into a contract.
Performance of a contract
We may process personal information where necessary to provide services, manage an engagement or meet our contractual obligations.
Legitimate interests
We may process information where necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.
Our legitimate interests may include:
- responding to business enquiries;
- developing and managing client relationships;
- operating and improving our business;
- securing our website and systems;
- preventing fraud and misuse;
- maintaining appropriate business records;
- managing legal and commercial risks;
- communicating with relevant business contacts about our services.
Where required, we assess the purpose, necessity and potential impact of the processing before relying on legitimate interests.
Legal obligation
We may process information where necessary to comply with applicable laws, taxation rules, accounting obligations, court orders or regulatory requirements.
Consent
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before consent was withdrawn.
6. Marketing communications
We may occasionally contact relevant business contacts about Safestorm services where this is permitted by law.
You can ask us to stop sending marketing communications at any time by:
- using the unsubscribe mechanism provided in the communication; or
- contacting privacy@safestorm.co.uk.
We will retain limited suppression information where necessary to ensure that we respect your request.
Submitting a general enquiry does not automatically subscribe you to a marketing mailing list.
7. Who we share information with
We may share personal information with trusted organisations that support our business, including:
- website hosting and content-delivery providers;
- email and communications providers;
- secure file-transfer and collaboration providers;
- professional advisers, including accountants, insurers and legal advisers;
- payment and banking providers;
- subcontractors or specialist consultants engaged for an authorised client engagement;
- technology and security providers;
- government bodies, regulators, courts or law-enforcement authorities where disclosure is required or legally permitted;
- prospective purchasers, investors or professional advisers involved in a genuine corporate transaction.
Providers acting on our behalf are expected to process information only for authorised purposes and to protect it appropriately.
Where subcontractors may be involved in a client engagement, their use will be governed by the relevant contract, statement of work or other written agreement.
8. International transfers
Some service providers may process or store information outside the United Kingdom.
Where personal information is transferred internationally, we take appropriate steps designed to protect it. Depending on the destination and provider, these steps may include:
- relying on UK adequacy regulations;
- using the UK International Data Transfer Agreement;
- using the UK Addendum to approved standard contractual clauses;
- implementing contractual, organisational and technical safeguards.
You may contact us for further information about safeguards relevant to your personal information.
9. How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and contractual requirements.
Our general retention approach is:
- General enquiries that do not become engagements: normally up to 24 months after the last meaningful contact.
- Proposal and scoping records: normally up to 36 months after the opportunity closes or becomes inactive.
- Client and engagement records: normally seven years after the end of the engagement or business relationship.
- Invoices, accounting and taxation records: normally six years after the end of the relevant financial period, or longer where required by law.
- Supplier and contractor records: normally seven years after the relationship ends.
- Website security and diagnostic logs: normally retained for a limited operational period, unless needed to investigate an incident or protect legal rights.
- Marketing suppression records: retained for as long as necessary to respect an opt-out request.
- Legal claims and incident records: retained for as long as necessary in light of the applicable limitation period, investigation or legal process.
We may retain information for longer where required by law, litigation, insurance obligations or an active security investigation.
10. Security assessment data
Information processed during penetration testing, security assessments or related professional services is governed primarily by the relevant client contract, proposal, statement of work, data-processing terms and rules of engagement.
Depending on the engagement, this information may include:
- target and asset information;
- system configurations;
- vulnerability evidence;
- logs and technical output;
- user or account information encountered during authorised testing;
- screenshots;
- reports and remediation correspondence.
We apply access restrictions and proportionate technical and organisational controls to this information.
Clients should not send assessment data through the website enquiry form unless we have explicitly agreed that method.
11. How we protect information
We use proportionate technical and organisational measures designed to protect personal information against unauthorised access, loss, disclosure, alteration or destruction.
These measures may include:
- access controls;
- multi-factor authentication;
- encryption in transit;
- secure storage and transfer methods;
- device and account security controls;
- data minimisation;
- logging and monitoring;
- supplier due diligence;
- confidentiality obligations;
- secure deletion and retention procedures.
No internet-based service can be guaranteed to be completely secure. You should use an agreed secure channel when sending confidential or high-risk information.
12. Your data-protection rights
Depending on the circumstances, you may have the right to:
- request access to your personal information;
- request correction of inaccurate or incomplete information;
- request deletion of your information;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- request transfer of certain information in a portable format;
- withdraw consent where processing relies on consent;
- complain about how your information is handled.
These rights are not absolute and may be subject to legal exemptions.
To exercise a right, contact privacy@safestorm.co.uk. We may need to verify your identity before responding.
13. Complaints
Please contact us first if you have concerns about how we use your personal information. We will try to resolve the issue.
You also have the right to complain to the UK Information Commissioner’s Office.
Information about making a complaint is available from the Information Commissioner’s Office.
14. Third-party websites
Our website may contain links to websites operated by third parties.
We are not responsible for the privacy practices, security or content of third-party websites. You should review their privacy information before providing personal information to them.
15. Children
Our website and services are intended for organisations and adult business users.
We do not knowingly collect personal information from children through the website.
16. Changes to this notice
We may update this privacy notice to reflect changes to our services, providers, legal requirements or processing activities.
The latest version will be published on this page with an updated revision date.
17. Contact us
Questions about this notice or our use of personal information should be sent to:
Safestorm Ltd
71–75 Shelton Street
Covent Garden
London
WC2H 9JQ
Email: privacy@safestorm.co.uk
Company number: 17333583