Privacy Policy

Welcome to RedSecLabs. We take your privacy very seriously. Please read this privacy policy carefully as it contains important information on who we are and how and why we collect, store, use and share any information relating to you (your personal data) in connection with your use of our website.

Policy Version: 10th August 2025

Introduction

www.redseclabs.com (our website) is provided by RedSecLabs Limited ("we", "our" or "us"). We are the controller of personal data obtained via our website. (For controller/processor concepts, see ICO guidance.)

We collect, use and are responsible for certain personal data about you. When we do so we are subject to the UK General Data Protection Regulation (UK GDPR).

Important: Given the nature of our website, we do not expect to collect the personal data of anyone under 13 years old. If you are aware that any personal data of anyone under 13 years old has been shared with our website, please let us know so that we can delete that data.

What this policy applies to

This privacy policy relates to your use of our public website only. Our client engagements are covered by the service agreement and any client privacy notices. Our site contains links to third-party websites (eg, external resources, Calendly booking pages). Those are governed by their own privacy policies.

Personal data we collect about you

The personal data we collect about you depends on the particular activities carried out through our website. We will collect and use the following personal data about you:

  • Identity and contact data: name, work email, work phone, company, role/title.
  • Enquiry/quote data: the details you provide in contact or "Get a quote" forms.
  • Booking data: meeting details captured when you use our "Book A Consultation" link (Calendly).
  • Usage data: pages visited, referral source and basic device/interaction data collected via essential site technologies and (where enabled) analytics.
  • Public Business Info: your public profile or company web page from public sources only to contextualise and respond to your enquiry.

We do not intentionally collect special category data via the website. Sometimes you can choose if you want to give us your personal data and let us use it. Where that is the case, we will tell you and give you the choice before you give the personal data to us.

How your personal data is collected

We collect personal data from you:

  • Directly from you: when you submit a form, request a quote, or use the Calendly link to book
  • Automatically: via cookies/similar technologies (see Cookies)
  • From public business sources: eg, your company website or professional profile to help respond to your enquiry.
  • Indirectly: such as your browsing activity while on our website; we will usually collect information indirectly using the technologies explained in the section on 'Cookies and other tracking technologies' below

How and why we use your personal data

Under data protection law, we can only use your personal data if we have a proper reason, such as:

  • To respond to your enquiries / provide quotes - Contract (steps prior) / legitimate interests (efficient B2B engagement).
  • To operate, secure and improve our website - legitimate interests and, where applicable, consent for non-essential cookies/analytics.
  • To keep records and comply with law (eg, tax/accounting) - legal obligation.
  • To send B2B marketing to corporate subscribers - legitimate interests under PECR (opt-out always available)
  • To protect our legal rights - legitimate interests / legal obligation (as applicable)

Detailed Usage Table

What we use your personal data for Our reasons
Creating and managing your account with us For our legitimate interests, i.e. to be as efficient as we can so we can deliver the best service to you at the best price
Providing services to you To perform our contract with you or to take steps at your request before entering into a contract
Conducting checks to identify you and verify your identity or to help prevent and detect fraud For our legitimate interests, i.e. to minimise fraud that could be damaging for you and/or us
Customising our website and its content to your preferences Your consent as gathered by the separate cookies tool on our website OR for our legitimate interests where consent is not required
Analytics and performance measurement Your consent for analytics cookies OR legitimate interests where DUAA low-risk analytics exemption applies
Marketing our services to existing and former customers For our legitimate interests, i.e. to promote our business to existing and former customers

Marketing

We will use your personal data to send you updates (by email, text message or telephone) about our products and/or services, including exclusive offers, promotions or new products and/or services.

We may send B2B marketing to corporate subscribers (e.g., your work email) under PECR on a legitimate-interests basis; we include unsubscribe in each message and honour opt-outs. For individuals (e.g., sole traders), we will only send electronic marketing in line with PECR (consent/soft opt-in as applicable)

Who we share your personal data with

We routinely share personal data with:

  • Service providers we use to run our website and handle enquiries (eg, website hosting and email services)
  • Scheduling provider when you choose to book a consultation via our site (Calendly)
  • Professional advisers (eg, lawyers, auditors, insurers) where needed for our business and to protect our legal rights
  • Authorities and regulators where required by law or to respond to lawful requests
  • Other third parties you approve (for example, where you ask us to share details to arrange a joint meeting)

We only allow those organisations to handle your personal data if we are satisfied they take appropriate measures to protect your personal data.

How long your personal data will be kept

We will not keep your personal data for longer than we need it for the purpose for which it is used. For example:

Record Type Typical Retention Rationale
Website enquiries / quotes Up to 24 months from last interaction Manage repeat queries; understand pipeline
Booking metadata (Calendly) Up to 24 months from appointment date Scheduling history and follow ups
Client and contract records Up to 7 years after end of engagement Accounting, tax, legal limitation
Suppression lists (Opt-out) Indefinitely (minimum necessary) Ensure no further marketing is sent

Transferring your personal data out of the UK

Countries outside the UK have differing data protection laws, some of which may provide lower levels of protection of privacy.

It is sometimes necessary for us to transfer your personal data to countries outside the UK. In those cases we will comply with applicable UK laws designed to ensure the privacy of your personal data.

Under data protection laws, we can only transfer your personal data to a country outside the UK where:

  • the UK government has decided the particular country ensures an adequate level of protection of personal data (known as an 'adequacy regulation') further to Article 45 of the UK GDPR.
  • there are appropriate safeguards in place, together with enforceable rights and effective legal remedies for you, or
  • a specific exception applies under relevant data protection law

Cookies and other tracking technologies

We use essential cookies to make the site work. We may also use functionality and analytics cookies to improve the site and understand usage:

  • Where consent is required, we ask via a cookie banner and honour withdrawal.
  • DUAA 2025: we may rely on new PECR exceptions for certain security and low-risk analytics cookies where conditions are met (while preserving transparency and easy opt-out)
  • For our current list of cookies, categories, and lifetimes, see our Cookie Policy (linked from the banner and footer)

Your rights

You generally have the following rights, which you can usually exercise free of charge:

Access to a copy of your personal data

The right to be provided with a copy of your personal data

Correction (rectification)

The right to require us to correct any mistakes in your personal data

Erasure (right to be forgotten)

The right to require us to delete your personal data - in certain situations

Restriction of use

The right to require us to restrict use of your personal data in certain circumstances

Data portability

The right to receive your personal data in a structured, machine-readable format

To object to use

Object to processing based on legitimate interests or to direct marketing at any time

To exercise your rights: Please email us at [email protected]. When contacting us please provide enough information to identify yourself and let us know which right(s) you want to exercise.

Keeping your personal data secure

We implement appropriate administrative, technical and organisational measures (e.g., access controls, encryption in transit, environment hardening, vulnerability management, audit logging) proportionate to risk. While no system is 100% secure, we continually improve controls. We will notify you and the ICO of a personal data breach where legally required.

How to complain

Please contact us if you have any queries or concerns about our use of your personal data (see below 'How to contact us'). We hope we will be able to resolve any issues you may have.

You also have the right to lodge a complaint with the Information Commissioner. They may be contacted using the details at https://ico.org.uk/make-a-complaint or by telephone: 0303 123 1113.

Changes to this privacy policy

We may update this policy from time to time. If changes are material, we will highlight them on this page and, where appropriate, notify you by email.