How We Protect Your Personal Data
Date: April 2026
We implement a range of technical and organisational measures to protect your personal data:
- Encryption of all data in transit (TLS) and at rest (AES-256 or equivalent)
- Strict role-based access controls i.e. personal data accessible only on a need-to-know basis
- Multi-factor authentication for all internal system access
- Regular penetration testing and security vulnerability assessments
- Documented incident response, business continuity, and disaster recovery procedures
- PCI DSS-compliant handling of payment card data via certified processors
- Ongoing staff training on data protection and information security
- Third-party processor security assessment as part of our DPA onboarding process
Our security practices are aligned with ISO 27001 and SOC 2 Type II frameworks. However, no system can be fully secure. You are responsible for maintaining the confidentiality of your account credentials.
Personal data breach notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority as required by applicable law in the UK, within 72 hours of becoming aware.
Where a breach is likely to result in a HIGH RISK to your rights and freedoms, we will also notify you directly and without undue delay, setting out: the nature of the breach; the personal data affected; the likely consequences; and the steps we are taking to address it.