GDPR Compliance
Last updated: 2026
SafetyX is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This statement outlines our approach to data protection and your rights as a data subject.
1. Our Commitment
We recognise the importance of protecting personal data. We process data lawfully, fairly and transparently, and only collect information that is necessary for the purposes stated in our Privacy Policy.
2. Data We Process
In the course of providing CyberSecurity services, we may process personal data including contact information, employee records, security assessment findings and incident-related data. We ensure all processing is justified and documented.
3. Lawful Basis
We rely on the following lawful bases for processing personal data:
- Performance of a contract with you or your organisation
- Compliance with a legal obligation
- Protection of vital interests
- Legitimate interests, balanced against your rights
- Consent, where required and explicitly given
4. Your Rights Under GDPR
You have the following rights in relation to your personal data:
- The right to be informed about how your data is used
- The right of access to your personal data
- The right to rectification of inaccurate or incomplete data
- The right to erasure (the "right to be forgotten")
- The right to restrict processing
- The right to data portability
- The right to object to processing
- Rights in relation to automated decision-making and profiling
5. Data Security
We apply technical and organisational security measures appropriate to the risk, including encryption, access controls, staff training and regular security assessments. We treat your data with the same rigour we apply to our clients' environments.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting and reporting requirements. When no longer required, data is securely deleted or anonymised.
7. Third Parties and Processors
Where we use third-party processors, we ensure they provide sufficient guarantees of compliance with UK GDPR and that appropriate data processing agreements are in place.
8. Data Breaches
In the unlikely event of a personal data breach, we will act in accordance with our incident response procedures and notify the relevant supervisory authority and affected individuals where required by law.
9. Contact and Complaints
To exercise your GDPR rights or raise a concern, contact us at info@safetyx.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
10. Policy Updates
This GDPR compliance statement may be updated to reflect changes in law or our business practices. The latest version will always be available on this page.
