Privacy notice
Plain-language summary of how we handle personal data. Status: draft template — requires review by qualified counsel before publication.
1. Who we are
RASTTSec ("we", "us") provides penetration testing, security assessment and software development services. The registered entity name, company number and registered address must be inserted here. [Placeholder: legal entity details.]
2. What we collect
- Enquiry data — name, company, work email, phone number and the content of your message when you contact us.
- Engagement data — information shared during scoping and delivery, including technical details about systems in scope.
- Technical data — server logs and aggregated, non-identifying usage statistics from this website.
- Recruitment data — CVs and application details where you apply for a role.
3. Why we process it
To respond to enquiries, prepare proposals, deliver contracted work, meet legal and accounting obligations, and — only with consent — send you occasional security updates you can unsubscribe from at any time.
4. Lawful basis
Depending on the activity: performance of a contract, our legitimate interest in responding to business enquiries, compliance with legal obligations, or your consent. Confirm the correct basis for your jurisdiction with counsel.
5. Client data during testing
Any data encountered while delivering an engagement is handled under the engagement contract and NDA, not under this website notice. We work to minimum-necessary access, encrypted storage and agreed deletion timelines. See the trust centre.
6. Sharing
We share data only with subprocessors required to run our business (hosting, email, accounting), under written agreements, and with authorities where legally compelled. We do not sell personal data.
7. Retention
Enquiry records are kept for as long as needed to handle the enquiry and any resulting contract, then for the period required by tax and professional obligations. Retention periods must be stated explicitly here. [Placeholder.]
8. Your rights
Subject to your jurisdiction, you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent at any time. Requests go to the privacy contact below; we respond within the period required by applicable law.
9. International transfers
Where data is processed outside your region we rely on appropriate safeguards. The mechanism used must be documented here. [Placeholder.]
10. Security
We apply encryption in transit and at rest, access control and least privilege for our own systems. No method of transmission or storage is completely secure.
11. Contact
Privacy contact: [placeholder email]. Data protection officer: [placeholder, if applicable]. Postal address: [placeholder].
12. Changes
We will update this notice when our practices change and show the effective date. Effective date: [placeholder].