This policy is a plain-English summary of how this website actually works today — it isn't generic boilerplate. It reflects the specific tools this site uses: our contact form, the Board Assurance Score assessment, and the third parties that help us run them. If you enable new tools (like analytics) or change providers, update this page to match before you switch them on.
This document was drafted as a starting point and has not been reviewed by a solicitor. Given the regulatory obligations involved (and, frankly, given that we're a security and governance consultancy), we'd strongly recommend a qualified data protection professional or solicitor review it before it goes live.
1. Who we are
CSISC ("we", "us", "our") is a UK-based cybersecurity consultancy providing Executive Cyber Leadership for organisations across the UK. This policy explains how we handle personal data when you visit csisc.uk, use our free Board Assurance Score tool, or get in touch with us.
For the purposes of UK data protection law, CSISC is the data controller of the personal data described below.
Contact: info@csisc.uk
2. What data we collect
| Where | What we collect | Why |
|---|---|---|
| Contact form | Name, email address, phone number (optional), and the message you send us | To respond to your enquiry |
| Board Assurance Score | Your answers to the 12 assessment questions (not linked to you unless you choose to unlock your full results). If you unlock them: name, email, company name, and your score and breakdown. | To show you your results, and, if you choose to unlock them, to email you a copy and follow up |
| General site visits | Standard technical data such as IP address and browser type, collected automatically via our hosting provider's server logs | To keep the site secure and working correctly |
| Analytics | We do not currently run analytics or tracking cookies on this site. | If this changes, we'll update this policy and ask for your consent first, where the law requires it |
3. Why we process your data, and our legal basis
- Responding to your enquiry — our legitimate interest in dealing with enquiries efficiently, or steps taken at your request prior to a possible contract with you.
- Sending you your Board Assurance Score results — you've specifically asked us to, by submitting the unlock form.
- Following up about our services, after you've contacted us or completed the assessment — our legitimate interest in growing our business by following up with people who have proactively engaged with us. You can opt out of this at any time, just by telling us.
We do not sell your data, and we do not use it for anything beyond what's described in this policy.
4. Who we share it with
We use a small number of third-party services to run this website. Each of them only processes data on our instructions, as our data processor:
- Web3Forms — handles form submissions from this site and delivers them to us by email. Web3Forms hosts data on AWS with encryption at rest, and automatically deletes submissions after a limited retention period. Their processing of your data is governed by a Data Processing Agreement that includes UK-approved safeguards (such as the UK International Data Transfer Addendum) for any transfer outside the UK.
- Google (Google Sheets, via Google Apps Script) — we keep a running, private record of enquiries and Board Assurance Score leads in a Google Sheet, for our own internal follow-up and business planning. This is accessible only to CSISC.
We don't share your data with any other third party, and we never sell it.
5. International transfers
Some of the processors above may handle data outside the UK. Where that happens, we rely on the UK's approved transfer mechanisms — such as the UK International Data Transfer Addendum or equivalent Standard Contractual Clauses — to keep your data protected to UK standards regardless of where it's processed.
6. How long we keep your data
- Submissions held by Web3Forms are automatically deleted after their standard retention period.
- Records we keep ourselves (in our own Google Sheets, for enquiries and assessment leads) are retained for as long as reasonably necessary for our business relationship with you, or until you ask us to delete them.
- We review the data we hold periodically and delete anything we no longer need.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Ask us to delete your data
- Restrict or object to how we use your data
- Receive your data in a portable format
- Withdraw consent at any time, where consent is our basis for processing
- Complain to the Information Commissioner's Office (ICO) if you think we've mishandled your data
To exercise any of these rights, email info@csisc.uk. We'll respond within one month, as required by law.
8. Cookies
This site currently uses only cookies strictly necessary for it to function, if any. We do not use tracking, advertising, or analytics cookies at present. If that changes — for example, if we enable Google Analytics — we'll update this policy and ask for your consent first, via a cookie banner, where the law requires it.
9. Children
This website and our services are intended for business use by adults. We do not knowingly collect data from anyone under 18.
10. Security
We take reasonable technical and organisational steps to protect the data we hold, including relying on processors (see section 4) who provide encryption and access controls. That said, no method of transmission over the internet is completely secure, and we can't guarantee absolute security.
11. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised.
12. Contact us
CSISC
Email: info@csisc.uk
Phone: +44 (0)74 1265 8173
United Kingdom
Registered company details to be added here once finalised — see the general note about placeholder contact details elsewhere on this site.