Data Protection Privacy Notice
Closed Door Security LTD
Last reviewed: May 2025
1. Introduction and Summary
Closed Door Security LTD, a company registered in Scotland under company registration number SC690859, with its registered office at Unit 4, Habost Workshops, Isle Of Lewis, HS2 9QB ("we", "us", "our", or "the Company"), has prepared this data protection privacy notice ("the Notice") to describe its practices regarding the collection, use, storage, transfer and other processing of individually identifiable information about you ("Personal Data").
For the purposes of data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Closed Door Security LTD is the controller responsible for the processing of Personal Data described in this Notice.
2. How We Collect Your Personal Data
We will collect personal data in the following ways:
- When you provide your contact details to our sales department requesting information about our cybersecurity services or to request a demonstration, by telephone, e-mail or via our website.
- When you provide your contact details to our marketing department requesting relevant and useful information about our services through lead generation submission forms, by telephone or e-mail.
- When you provide your contact details through an exhibition, event, networking meeting or targeted research.
- When you engage our cybersecurity services, including penetration testing, vulnerability assessments, security audits, or managed security services.
- When you apply for employment at Closed Door Security LTD.
- When you visit our website.
3. The Types of Personal Data We Collect
3.1 Contact and Business Information
The personal data we routinely collect includes:
- Title, full name, and job role
- Organisation name and business address
- Telephone number(s)
- E-mail address
3.2 Job Applicant Information
If you are applying for a position at Closed Door Security LTD, we will collect:
- Title and full name
- Education details and professional qualifications
- Work experience and employment history
- Contact details (telephone, e-mail, address)
- Your CV and any supporting documents
- References (where provided)
3.3 Website Usage Information
With regard to each of your visits to our website, we will automatically collect the following technical information:
- The Internet Protocol (IP) address used to connect your device to the Internet
- Browser type, version, and plug-in types and versions
- Time zone setting, operating system and platform
- Full Uniform Resource Locators (URL), clickstream data, page response times, download errors, length of visits, and page interaction information
4. How We Use Your Personal Data
This section explains how and why we process your personal data, as well as the legal basis on which we carry out this processing.
4.1 Communications
Sending communications related to Closed Door Security LTD, keeping a record of your relationship with us, and ensuring we know how you prefer to be contacted.
Legal Basis: Your consent (Article 6(1)(a) UK GDPR)
4.2 Information and Services
Providing you with information and access to cybersecurity services that you have requested from us or which we feel may be of interest to you, where you have consented to be contacted for such purposes.
Legal Basis: Performance of a contract (Article 6(1)(b) UK GDPR). You may opt-out of some communications.
4.3 Enquiries
Providing you with information about our services that you have requested via exhibitions, events, or networking where we identify you as a prospect.
Legal Basis: Legitimate interests (Article 6(1)(f) UK GDPR)
4.4 Service Delivery
When delivering penetration testing and cybersecurity services, we collect and process:
- System and network configuration information
- Vulnerability findings and security assessment data
- Access credentials provided for testing purposes
- Technical logs and test results
- Remediation recommendations and reports
- Communication records related to the engagement
This data is processed on Cyver Core, our SOC2-compliant pentest management platform hosted on Microsoft Azure infrastructure in the Netherlands (EU).
Legal Basis: Performance of a contract (Article 6(1)(b) UK GDPR)
4.5 Job Applications
Processing applications for positions at Closed Door Security LTD.
Legal Basis: Your consent (Article 6(1)(a) UK GDPR) and taking steps at your request prior to entering into a contract (Article 6(1)(b) UK GDPR)
5. Confidentiality and Security
Closed Door Security LTD will store your data safely and maintains appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Personal Data and against accidental loss, alteration, disclosure, access, or destruction of your Personal Data.
Our security measures include:
- Encryption of data in transit and at rest
- Strong password policies and multi-factor authentication
- Physical security measures at our premises
- Regular security assessments and penetration testing
- Staff training on data protection and information security
- Access controls limiting data access to authorised personnel only
Only a limited number of persons within our organisation are authorised to access, delete or modify your data. These measures are aimed at ensuring the ongoing integrity and confidentiality of Personal Data. We evaluate these measures on a regular basis to ensure the security of processing.
Our employees and any contractual partners who have access to your data are contractually obliged to keep such information confidential and may not use these data for any purpose other than performing their contractual obligations.
6. Sharing Your Personal Data
We will not transfer personal data about you to third parties for the purpose of providing or facilitating third-party advertising. We will not sell personal data about you to any third party.
We may transfer your personal data to third parties in the following circumstances:
- Where sharing is required to fulfil the contract between us
- Where you have consented to us sharing your personal data with other parties involved in the service we provide to you
- Where you have requested it via a data portability request
- To a service provider or partner who meets our data protection standards
- Where disclosure is required or permitted by law (for example to government bodies, law enforcement agencies, or regulatory authorities)
We require all third parties to comply strictly with our instructions and to process your personal data only for the purposes specified. They must not use your personal data for their own business purposes.
6.1 Third-Party Service Providers
We use the following third-party service providers to deliver our services:
Cyver Core (Pentest Management Platform)
- Provider: Cyver B.V., Netherlands
- Purpose: Hosting and managing penetration testing engagements, vulnerability findings, reports, and engagement management
- Location: Microsoft Azure, Netherlands (EU)
- Safeguards: Data Processing Agreement, SOC2 Type 2 compliance
- Data stored: Pentest findings, vulnerability reports, client project data, security assessment reports, project communication and engagement records
We have conducted comprehensive due diligence on Cyver Core, including verification of SOC2 Type 2 compliance, review of security policies and GDPR compliance, and execution of a Data Processing Agreement. We remain the data controller and are responsible for ensuring your data is processed lawfully. Cyver Core processes data only on our documented instructions and is contractually obligated to maintain appropriate security measures, assist with data subject rights requests, and delete or return data upon service termination.
7. International Data Transfers
Where we transfer your personal data outside the United Kingdom, we will ensure that appropriate safeguards are in place to protect your data in accordance with UK GDPR requirements. These safeguards may include:
- Transferring data to countries that have been deemed to provide an adequate level of protection by the UK Government (the EU has adequacy status)
- Using Standard Contractual Clauses approved by the Information Commissioner's Office
- Implementing additional technical and organisational measures where necessary
8. Data Retention
Closed Door Security LTD will retain your Personal Data in accordance with applicable legal requirements, and only for as long as necessary for the purposes described in this Notice.
Our retention periods are as follows:
- Communications and marketing data: 3 years from last contact
- Information, enquiries and service-related data: 3 years from end of service relationship
- Job applications (unsuccessful): 12 months from decision, in case a suitable role becomes available
- Contract and service delivery records: 7 years (for legal and regulatory compliance)
After the applicable retention period, we will securely delete or anonymise your personal data.
9. Cookies
Our website uses cookies or similar technologies to collect information about your access to the website. Cookies are small text files that include a unique reference code that a website transfers to your device to store and sometimes track information about you.
9.1 Types of Cookies We Use
Essential Cookies: These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you such as setting your privacy preferences, logging in, or filling in forms.
Analytics Cookies: We use Google Analytics to understand how visitors interact with our website. These cookies collect information in an anonymous form, including the number of visitors, where visitors have come from, and the pages they visited.
Marketing Cookies: We use HubSpot cookies to track interactions with our marketing content and forms. These help us understand how you engage with our services and provide relevant information.
9.2 Managing Cookies
You can control and manage cookies in various ways. Most browsers allow you to refuse to accept cookies or delete cookies. The methods for doing so vary from browser to browser. Please note that blocking all cookies may have a negative impact upon the usability of many websites.
10. Your Rights
Under the UK GDPR and Data Protection Act 2018, you have the following rights regarding your personal data:
Right of Access: You have the right to request copies of your personal data.
Right to Rectification: You have the right to request that we correct information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure: You have the right to request that we erase your personal data in certain circumstances.
Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.
Right to Object: You have the right to object to the processing of your personal data in certain circumstances, including processing for direct marketing purposes.
Right to Data Portability: You have the right to request that we transfer your data to another organisation, or to you, in certain circumstances.
Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
10.1 Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
To exercise any of these rights, please contact our Data Protection Contact using the details provided below. We will respond to your request within one month of receiving it.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms:
- We will notify the ICO within 72 hours of becoming aware
- We will notify you without undue delay where the breach poses a high risk to your rights and freedoms
- We will describe the nature of the breach, likely consequences, and measures taken to address it
- We will take immediate steps to contain and remedy the breach
12. Changes to This Privacy Notice
Closed Door Security LTD may periodically update this Notice to reflect changes in the law, best practice, changes in our services, or changes in how we process your personal data. Where necessary, we will notify you of these changes. We will always display the date when the Notice was last amended on our website.
13. Contact Us
If you have any questions about this Privacy Notice or wish to exercise your rights, you can contact our Data Protection Contact:
By Email:
[email protected]
By Post:
Data Protection Contact
Closed Door Security LTD
Unit 4, Habost Workshops
Isle Of Lewis
HS2 9QB
By Telephone:
0131 460 4180
Note: While we have designated a Data Protection Contact for privacy inquiries, the size and nature of our operations do not require us to appoint a formal Data Protection Officer under Article 37 of the UK GDPR.
14. How to Complain
Closed Door Security LTD is committed to working with you to obtain a fair resolution of any complaint or concern about privacy.
If, however, you believe that we have not been able to assist with your complaint or concern, you have the right to make a complaint to the Information Commissioner's Office (ICO), the supervisory authority for data protection issues in the United Kingdom.
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
— End of Privacy Notice —