At a glance
- We collect only what we need for each purpose, and never sell personal data.
- Our website uses only an essential cookie to remember your cookie choice, and no analytics or advertising trackers.
- When we work inside client systems, the client stays in control of their data and we act only on their instructions.
- Job applications are kept for 6 months (12 with your permission), and equality monitoring is anonymous.
- You can ask to see, correct or delete your data at any time by emailing privacy@anthrasec.com.
1.Introduction
Anthrasec Limited (“we”, “us”, “our”) is a software engineering and cybersecurity company. We design, build, secure and run technology for organisations across healthcare, retail, finance, corporate and the public sector. Protecting information is at the heart of what we do, and that includes your personal data.
This policy explains what personal data we collect, why, how we protect it, how long we keep it and the rights you have. It covers:
- visitors to our website, anthrasec.com
- people who contact us, book a meeting or subscribe to our newsletter
- our clients' representatives and other business contacts
- personal data we handle while delivering services to clients
- people who apply for a job with us
We follow the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
2.Who we are
Anthrasec Limited is a company registered in England and Wales under company number 17472650, with our office at Hill House, High Street, Uxbridge, England UB8 1JT.
For most of the activities in this policy, such as running our website, handling enquiries and recruiting, we are the data controller: we decide how and why your personal data is used. When we deliver services for a client and handle personal data held in that client's systems, we usually act as a data processor on the client's behalf, and the client remains the controller (see section 6).
For any privacy question or request, contact us at privacy@anthrasec.com, by phone on +44 7899 838792, or by post to the address above, marked “Data protection”.
3.Information we collect through our website
We only collect what we need for the purpose you're using. Required fields on each form are clearly marked.
| Where | What we collect | Why |
|---|---|---|
| Newsletter sign-up | Email address, the page you signed up on, the wording you agreed to and when, and a history of confirmations and unsubscribes | To send the Anthrasec Briefing, and to keep a record of your consent |
| Business enquiries | Name, work email, company, and optionally phone, job title, location, services of interest, budget, timeline, how you heard about us and your message | To respond to your enquiry and discuss how we can help |
| Customer enquiries | Name, email, company, preferred reply method, phone if you choose a call, customer reference, related service, your message and any files you attach | To support you as a client |
| Urgent support | Name, email, company, phone, customer reference, the nature and severity of the issue, affected systems and a description | To respond to live incidents as quickly as possible |
| Meeting booking | Chosen date, time and length, services of interest, what you'd like to discuss, company size, timeline, name, work email, company, and optionally job title and phone | To arrange and prepare for the meeting. Your booking is added to our Microsoft 365 calendar and Microsoft Teams sends you the meeting invitation, which includes the details you gave us |
| Job applications | Personal and contact details, CV, cover letter, links, answers to role questions, right to work, availability and preferences (see section 9) | To assess your application |
| Site search | The words you type | Searching happens entirely in your browser. Your searches are not sent to us or stored |
| Server logs | IP address, browser type, the page requested, date and time | To keep the website running securely, prevent abuse (for example rate-limiting forms) and diagnose faults |
Our website uses one essential cookie to remember your cookie choice, and no analytics or advertising trackers. We keep an anonymous record of cookie choices (no IP address or identifying details) to show we respect them. See our cookie policy.
When you send one of our contact forms, your message and any files you attach are emailed to the Anthrasec team that handles that kind of enquiry, and a copy is kept in our private website storage so nothing is lost. The email is delivered by Resend, an email delivery service that acts as our processor (see International transfers), into our Microsoft 365 mailboxes.
If you phone or email us directly (for example reach@anthrasec.com, customer@anthrasec.com or urgency@anthrasec.com), we'll hold your contact details and the content of your message so we can respond.
4.Information from business relationships and other sources
Clients and business contacts
When you work with us, we hold business contact details, contracts and statements of work, project communications, meeting notes, support records, and billing details. We don't store full payment card numbers.
Other sources
- Public sources such as Companies House and professional networks, when researching a prospective client or partner
- Referrals from clients and partners, including technology partners such as AWS
- Subcontractors working with us on a joint engagement
- Threat intelligence sources, which may reference identifiable people (for example an email address found in a data breach) when we monitor risks for a client
Sensitive information
We don't routinely collect special category data (such as health or ethnicity) or criminal offence data. It may arise in limited circumstances: in client systems we investigate during an incident, when a candidate tells us about a disability so we can make adjustments, or in anonymous equality monitoring. Where it does, we only process it under the conditions allowed by Articles 9 and 10 UK GDPR and Schedule 1 of the Data Protection Act 2018, with extra safeguards.
5.How we use your information and our legal bases
We only use personal data where the law allows it. The main purposes and legal bases (Article 6 UK GDPR) are:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and preparing proposals | Legitimate interests, and steps before entering a contract |
| Arranging meetings you book | Legitimate interests, and steps before entering a contract |
| Delivering our services | Performance of a contract |
| Supporting clients and responding to urgent incidents | Performance of a contract; legitimate interests |
| Sending our newsletter | Consent, which you can withdraw at any time |
| Recruitment | Steps before entering a contract; legitimate interests; legal obligation (right-to-work checks) |
| Equality monitoring (optional, anonymous) | Consent, with the equal-opportunity monitoring condition in Schedule 1 DPA 2018 |
| Billing, accounting and tax | Legal obligation |
| Securing our website and systems, and preventing fraud and abuse | Legitimate interests |
| Handling legal claims and regulatory requests | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we balance our interests against your rights, and you can object at any time (see section 14).
6.Personal data in the services we deliver
Our work often gives us access to client systems that contain personal data about the client's staff, customers or patients. In this work the client is the controller and we are a processor. We only act on the client's documented instructions, under a written contract and data processing agreement, and never use that data for our own purposes.
AI & Automation
Building assistants and automations can involve connecting to documents, email, databases or business systems. We minimise and, where practical, anonymise or pseudonymise data before it reaches an AI model, choose models and settings that don't use client data for training, and agree with the client which AI providers may be used. See section 7.
Managed Cybersecurity
- Monitoring and response: monitoring client environments involves security logs that can include usernames, IP addresses and email metadata. We use them only to detect, investigate and respond to threats, with access restricted to the analysts working on that client and all access logged.
- Security assessments and vulnerability management: all testing is authorised in writing and follows agreed rules of engagement. If we uncover personal data, we access only what's needed to prove the issue, never copy data in bulk, and keep any evidence encrypted and deleted on the agreed schedule.
- Incident response: investigations may involve logs, emails, disk and memory images. Evidence is kept encrypted under chain-of-custody procedures and used only to investigate and remediate the incident. If we find a personal data breach, we support the client in meeting their own notification duties.
Application Development
We build and test applications using synthetic or anonymised data wherever possible. Where real data is needed, for example during a migration, access is limited, logged and removed when the work is finished.
Modern Workplace
Migrating and managing Microsoft 365, Teams or Google Workspace means handling mailboxes, files, user accounts and devices. We work under the client's instructions with the least access needed, and hand back or delete migration copies on completion.
Cloud Platforms and Enterprise Infrastructure
Designing, migrating and running cloud and on-premises environments, including backup and disaster recovery, can involve administrative access to systems holding personal data. We follow agreed data residency requirements and don't move data to another country without the client's written approval.
Sector-specific care
- Healthcare: patient information is special category data. We apply the strictest access controls and follow the client's information governance requirements.
- Finance: we support clients' regulatory obligations on operational resilience, record-keeping and audit.
- Retail: we design payment systems so that card data is protected in line with the client's payment security obligations.
- Public sector: we meet the client's security, vetting and data-handling requirements, including any personnel vetting.
7.Our use of AI
We may use AI tools to help with tasks such as triaging security alerts, correlating threats, summarising information and drafting reports. When we do:
- we minimise the personal data involved and anonymise it where practical
- we don't allow client data to be used to train general-purpose AI models
- third-party AI providers are treated as sub-processors, disclosed to clients and bound by data protection terms
- people review AI outputs before they're relied on or shared
8.Newsletter and marketing
We send the Anthrasec Briefing, our monthly newsletter, only to people who have subscribed and then confirmed their address by clicking the link in our confirmation email (“double opt-in”). We keep a record of what you agreed to and when, so we can show you gave consent. We may also send relevant updates to existing business contacts about similar services, as PECR allows, and you can opt out at any time.
The newsletter is sent through Resend, an email delivery service that acts as our processor. Resend stores your email address and delivery records in the United States, protected by the EU-US Data Privacy Framework and its UK Extension. We don't use open or click tracking in our emails.
Every email includes a one-click unsubscribe link, most email apps also show their own unsubscribe button, and you can use our unsubscribe page or email privacy@anthrasec.com. When you unsubscribe, we stop sending the newsletter straight away but keep a minimal record that you opted out, so we never add you back by mistake. Unsubscribing doesn't affect service messages, such as project updates or security advisories for active engagements.
9.Job applicants
When you apply for a role through our careers pages, we collect:
- your name, preferred name, contact details, country and town
- your CV, any cover letter, and links you choose to share (such as LinkedIn or GitHub)
- your answers to role-specific questions
- your right to work in the UK, notice period, salary expectations and working preferences
- any adjustments you ask for during the hiring process
- notes from interviews and, if we make an offer, references and right-to-work documents
Equality monitoring questions are optional. Your answers are stored separately from your application, without your name or contact details, and are never seen by anyone assessing your application. We use them only in aggregate to check our hiring is fair.
Applications are stored securely with access limited to the people involved in hiring. We don't make hiring decisions by automated means. In future we may use a recruitment platform such as Workday to manage applications; if we do, it will act as our processor under a data processing agreement and we'll update this policy.
If you're unsuccessful, we delete your application 6 months after the process ends, unless you asked us to keep your details for 12 months to consider you for future roles. If you join us, your data becomes part of your employee record.
11.International transfers
We aim to store and process personal data in the UK or the European Economic Area. If data is transferred elsewhere, for example to a cloud or software provider in the United States, we make sure it's protected by UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework, which covers our email delivery provider Resend), the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. For client data, we follow the data residency terms agreed with each client.
12.How long we keep information
We keep personal data only as long as we need it, then securely delete or anonymise it.
| Information | How long |
|---|---|
| Enquiries and meeting requests that don't lead to work | Up to 2 years after our last contact |
| Client and contract records | The length of the relationship plus 6 years |
| Financial and accounting records | 6 years from the end of the financial year |
| Newsletter subscriptions and consent records | Until you unsubscribe, plus a record that you did |
| Job applications (unsuccessful) | 6 months after the process ends, or 12 months with your permission |
| Equality monitoring (anonymous) | Kept in anonymous form only, for reporting |
| Website server logs | Up to 90 days |
| Anonymous cookie consent records | Up to 2 years |
| Security assessment evidence | As agreed with the client, typically no more than 90 days after the report |
| Incident response evidence | As agreed with the client, or longer if needed for legal proceedings |
13.How we protect information
As a security company, we hold ourselves to a high standard. Our measures include:
- encryption of data in transit and at rest
- role-based access with the least privilege needed, and multi-factor authentication
- logging and monitoring of access to systems holding personal data
- separate, isolated environments for testing and security work
- regular testing of our own systems, and secure development practices
- confidentiality agreements and data protection training for everyone who handles personal data
No system can be guaranteed completely secure, but we continually review and improve our protections.
14.Your rights
Under UK GDPR you have the right to:
- be informed about how your data is used
- access a copy of your personal data
- correct inaccurate or incomplete data
- erase your data in certain circumstances
- restrict how we use your data
- data portability, to receive your data in a reusable format
- object to processing based on legitimate interests, and to direct marketing at any time
- withdraw consent at any time, where we rely on it
- not be subject to decisions made solely by automated means that significantly affect you
To use any of these rights, email privacy@anthrasec.com. We'll reply within one month, or tell you if we need longer for a complex request. We may ask you to confirm your identity first. If your request concerns data we process for one of our clients, we'll pass it to that client and help them respond.
15.Automated decision-making
We don't make decisions with legal or similarly significant effects about people, such as hiring decisions, by automated means alone. Where tools help us analyse information, a person always makes the decision.
16.Children
Our services are for businesses and professionals. We don't knowingly collect personal data from anyone under 18, and will delete it if we find we have.
17.Data breaches
If a breach affects personal data we control and is likely to put people at risk, we will report it to the ICO within 72 hours of becoming aware of it, and tell affected people without undue delay where the risk is high. Where we act for a client, we will notify that client without undue delay so they can meet their own obligations.
18.Changes to this policy
We update this policy when our services, systems or the law change. The date at the top shows the latest version. If we make significant changes, we'll highlight them on our website or contact you directly where appropriate.
19.Complaints
If you're unhappy with how we've handled your data, please contact us first at privacy@anthrasec.com so we can put it right.
You can also complain to the Information Commissioner's Office: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; helpline 0303 123 1113; ico.org.uk/make-a-complaint.
20.Contact us
Anthrasec Limited, Hill House, High Street, Uxbridge, England UB8 1JT
Email: privacy@anthrasec.com
Phone: +44 7899 838792