NeedSec logo
Privacy Policy

How NeedSec handles personal data

This policy explains what information NeedSec collects, why it is used, how it is protected, and the choices you have. It is written for website visitors, people requesting quotes, clients, and anyone contacting NeedSec.

Last updated: 15 May 2026UK-focused data protection

Minimal data

We collect the information needed to respond to enquiries, scope services, and operate the website.

Security first

Information is handled with care because cyber security enquiries can contain sensitive context.

No public secrets

Passwords, API keys, private keys, and highly sensitive system data should not be sent through public forms.

Data We May Process

Information covered by this policy

Name, email address, phone number, company name, and job role if you provide them.

Service interest, project details, message content, and preferred contact method.

Technical or organisational context shared when requesting a quote or security assessment.

Basic website and security logs such as IP address, browser details, timestamps, and request metadata.

Admin, audit, or authentication records where access to protected NeedSec systems is required.

Why We Use It

Main purposes

Responding to enquiries and quote requests

Scoping penetration testing, Cyber Essentials, secure development, or security advisory work

Providing services, support, reporting, retesting, and client communication

Protecting the website, preventing abuse, investigating suspicious activity, and keeping audit records

Meeting legal, regulatory, accounting, and contractual obligations

Improving website content, service quality, and operational reliability

1. Who this policy applies to

This policy applies to visitors to the NeedSec website, people who submit contact or quote forms, clients, suppliers, and people who communicate with NeedSec about cyber security services.

NeedSec provides cyber security services including penetration testing, Cyber Essentials certification assessment, secure web development, cloud security assessment, API testing, and related advisory work.

2. Personal data we collect

We collect information you choose to provide and technical information generated when the website is used. This may include contact details, business details, service requirements, message content, and limited website security logs.

Where an enquiry relates to security testing, you may choose to provide asset names, system types, URLs, compliance requirements, testing windows, or other scoping information. Please only provide information that is necessary at the enquiry stage.

3. How we use personal data

We use personal data to respond to enquiries, prepare quotes, deliver requested services, manage client relationships, protect the website, maintain records, and meet legal or contractual duties.

We do not sell personal data. We do not use enquiry information for unrelated third-party advertising.

4. Legal bases

Depending on the context, we may process personal data because it is necessary to take steps before entering into a contract, to perform a contract, to comply with legal obligations, or because NeedSec has a legitimate interest in responding to enquiries, operating securely, and improving services.

Where consent is required, you may withdraw consent at any time by contacting NeedSec.

5. Security testing information

Cyber security enquiries can contain sensitive details. NeedSec treats scoping information, vulnerability details, reports, credentials provided for authorised testing, and client system information as confidential.

Do not submit passwords, private keys, seed phrases, production secrets, payment card data, patient data, or other highly sensitive information through public website forms. Safer transfer methods can be agreed when needed for a project.

6. Cookies and analytics

The website may use necessary cookies or similar technologies to support core functionality, security, admin access, abuse prevention, and basic site operation.

If analytics or optional tools are used, they should be configured to collect only proportionate information for understanding website performance and improving content.

7. Sharing information

We may share information with trusted service providers who help operate the website, email, hosting, security, administration, or client delivery processes. They should only process information for agreed purposes.

We may also share information if required by law, regulation, court order, professional advisers, insurers, or where necessary to protect rights, safety, systems, or services.

8. International transfers

Some technology providers may process data outside the UK. Where this happens, NeedSec expects appropriate safeguards to be used, such as adequacy regulations, standard contractual clauses, or equivalent protections.

9. Retention

We keep personal data only for as long as needed for the purpose it was collected, including enquiry handling, project delivery, reporting, legal, accounting, compliance, dispute, and security requirements.

Enquiry data that does not become a client relationship is normally retained only for a reasonable business period unless there is a need to keep it longer.

10. Your rights

You may have data protection rights under UK data protection law, including access, correction, deletion, restriction, objection, and portability. These rights are not absolute and may depend on the context.

To make a request, contact NeedSec using the details below. We may need to verify your identity before acting on a request.

11. Changes to this policy

NeedSec may update this policy to reflect service, legal, operational, or website changes. The latest version will be published on this page with an updated date.

Your data rights

Data protection rights depend on the type of information, why it is held, and any legal or contractual duties that apply.

Access the personal data we hold about you

Ask us to correct incomplete or inaccurate information

Request deletion where we no longer need the data

Object to or restrict certain processing

Request a portable copy of your data where applicable

Raise a concern with the UK Information Commissioner's Office

Questions about how your data is handled?

Contact NeedSec before sending sensitive security information through a public form. Safer transfer arrangements can be agreed for active projects.

Speak With NeedSec