DeboSecure -Privacy Notice

Website Privacy Notice

Last updated: 23 August 2026

1. Introduction

This Website Privacy Notice explains how DeboSecure Limited collects, uses, stores and protects personal data when you use our website.

This notice applies to users of:

https://www.debosecure.co.uk/

It covers personal data collected when you visit our website, submit an enquiry or contact form, book a consultation through Calendly, communicate with us, or otherwise interact with our website and its services.

We are committed to handling personal data responsibly and in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations 2003 (PECR).

2. Who we are

Organisation: DeboSecure Limited

Trading name: DeboSecure Limited

Website: https://www.debosecure.co.uk/

Business address: 61 Bridge Street, Kington. HR5 3D

Privacy contact: info@debosecure.co.uk

For the purposes of applicable UK data protection law, we are the data controller for personal data collected through this website, except where a third party processes information on our behalf as a data processor.

3. Personal data we collect

Category Examples
Contact and enquiry data Name, email address, telephone number, company or organisation name, job title and enquiry details.
Consultation and booking data Name, email address, telephone number, organisation, booking details, meeting preferences and information you provide when arranging a consultation through Calendly.
Communication data Emails, replies, correspondence, enquiry history and information contained in communications with us.
Technical data IP address, browser type, device type, operating system, language, referring website and technical information generated when using the website.
Website analytics data Information about how visitors use our website, including pages viewed, visits, traffic sources, approximate geographical information and device or browser information.
Cookie and similar technology data Information collected through cookies and other storage or access technologies used by our website.
Voluntary information Any other personal information you choose to provide when contacting us or using our website.

4. How we collect personal data

  • We may collect personal data when you:

  • submit a contact or enquiry form;

  • request information about our services;

  • book a consultation or meeting through Calendly;

  • email us or communicate with us;

  • browse or interact with our website;

  • use features or forms provided through our website;

  • provide information voluntarily during a consultation or enquiry;

  • interact with cookies, analytics or similar technologies; or

  • our website and hosting systems generate technical or security information.

Some information may also be provided to us by third party services integrated with our website, such as Calendly, where you use those services to arrange a consultation.

5. How we use personal data

  • We may use personal data to:

  • receive, review and respond to website enquiries;

  • arrange and manage consultations and meetings;

  • communicate with prospective and existing clients;

  • provide information about our cyber security services;

  • understand the requirements of prospective clients;

  • manage business relationships;

  • follow up on enquiries;

  • provide quotations, proposals or other pre contractual information;

  • maintain the security and functionality of the website;

  • understand how visitors use our website;

  • analyse website performance and improve content and user experience;

  • maintain appropriate records of communications and enquiries;

  • prevent or investigate misuse, security incidents or fraudulent activity;

  • handle complaints, disputes, legal claims or regulatory matters; and

  • comply with legal and regulatory obligations.

We will only use personal data for purposes that are compatible with the purposes described in this notice or otherwise permitted by law.

6. Lawful basis for processing

We do not intend to collect special category personal data or criminal offence data through our website.

Please do not provide unnecessary sensitive personal information through contact forms, booking forms or general enquiries.

Purpose Lawful basis
Responding to website enquiries Legitimate interests
Responding to requests for information Legitimate interests
Taking steps at your request before entering into a contract Pre contractual steps
Providing and managing consultations requested by you Contract or pre contractual steps
Managing client and business communications Legitimate interests and/or contract
Website security and technical operation Legitimate interests
Website analytics and non essential cookies Consent where required
Compliance with legal obligations Legal obligation
Establishing, exercising or defending legal claims Legitimate interests and/or legal obligation

Depending on the circumstances, we rely on one or more of the following lawful bases under the UK GDPR:

7. Squarespace and website analytics

Our website is built and hosted using Squarespace.

We use Squarespace Analytics to understand how visitors interact with our website and to help us improve website content, performance and user experience.

Squarespace Analytics may provide information such as:

  • pages viewed;

  • number of visits;

  • unique visitors;

  • traffic sources;

  • referring websites;

  • device and browser information;

  • approximate geographical information; and

  • information about how visitors interact with website content.

Squarespace states that certain analytics and performance cookies may be used to provide analytics information, including information about visitors, visits and traffic sources.

Where applicable law requires consent for non essential cookies or other storage and access technologies, we will seek that consent before using them. The ICO's current guidance confirms that PECR can apply to cookies and other technologies that store information on, or access information from, a user's device.

You can manage your cookie preferences using the cookie controls provided on our website where available.

8. Cookies and similar technologies

Our website uses cookies and similar technologies.

Some are necessary for the website to operate correctly, maintain security or provide functionality requested by visitors.

Other cookies or similar technologies may be used for analytics, performance or other purposes.

Where consent is required, non essential cookies will not be used until you provide the appropriate consent.

The ICO's current guidance requires organisations to provide appropriate information about storage and access technologies and, where an exception does not apply, obtain prior consent.

For detailed information about the cookies and similar technologies used on our website, please see our Cookie Notice and the cookie settings provided on the website.

9. Calendly and consultation bookings

We use Calendly to allow visitors to schedule consultations and meetings with us.

When you use our Calendly booking facility, Calendly may process information such as your name, email address, telephone number, booking information and any other information you choose to provide through the booking process.

Calendly states that customer data submitted through its services is processed on behalf of its customers in accordance with the customer's instructions and applicable contractual arrangements.

Calendly currently states that its data is hosted in United States based data centres operated using Google Cloud Services and Amazon Web Services. Its current Data Processing Addendum provides contractual safeguards for UK personal data transfers, including the UK Addendum to the Standard Contractual Clauses where applicable.

By using our consultation booking facility, you should also review Calendly's own privacy information.

Calendly Privacy Notice:

https://calendly.com/legal/privacy-notice

10. Website hosting and third party services

Our website is provided using Squarespace.

We may also use third party service providers to provide functions such as:

  • website hosting and infrastructure;

  • website analytics;

  • consultation scheduling;

  • email and communications;

  • website security;

  • information technology support;

  • professional services; and

  • other services required to operate our business.

Third party providers may process personal data on our behalf where necessary to provide their services.

We seek to ensure that appropriate contractual and data protection safeguards are in place where third parties process personal data on our behalf.

11. Who we share personal data with

We may share personal data where necessary with:

  • authorised members of our organisation;

  • Squarespace and associated service providers;

  • Calendly for consultation and appointment scheduling;

  • email and communications providers;

  • website developers or technical support providers;

  • cyber security, IT or managed service providers where required;

  • professional advisers, such as legal or accountancy advisers;

  • insurers where necessary;

  • regulators and public authorities where legally required;

  • courts, law enforcement agencies or other competent authorities where required by law; and

  • third parties where necessary to establish, exercise or defend legal rights.

We do not sell personal data.

We will only disclose personal data where there is a lawful basis for doing so and only to the extent reasonably necessary for the relevant purpose.

12. International transfers

Some of the service providers we use may process personal data outside the United Kingdom.

Where personal data is transferred outside the UK, we will take appropriate steps to ensure that the transfer is lawful and that suitable safeguards are in place where required.

These safeguards may include:

  • UK adequacy regulations;

  • the UK International Data Transfer Agreement;

  • the UK Addendum to the EU Standard Contractual Clauses;

  • applicable certification or recognised transfer mechanisms; or

  • another lawful transfer mechanism permitted by UK data protection law.

For example, Calendly currently states that its services process customer data in the United States and that contractual safeguards are used for relevant UK data transfers.

13. How long we keep personal data

We do not keep personal data for longer than is reasonably necessary for the purposes for which it was collected.

Our retention periods will depend on the nature of the information and why we need it.

Our legitimate interests may include operating and securing our website, responding to genuine business enquiries, developing and managing business relationships, improving our services, preventing misuse and protecting our legal rights.

Where we rely on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Data type Typical retention approach
Website contact and enquiry information Normally retained for up to 18 months from the enquiry or last relevant communication, subject to periodic review.
Consultation and Calendly booking information Normally retained for as long as reasonably necessary to manage the enquiry or business relationship and for appropriate business records.
Related email correspondence Normally retained for up to 18 months after the last relevant communication, unless a longer period is justified.
Website analytics information Retained in accordance with the relevant Squarespace settings and applicable service configuration.
Technical and security information Retained only for as long as reasonably necessary for security, troubleshooting, administration or legal purposes.
Information required for legal, contractual or regulatory purposes Retained for as long as necessary for the relevant purpose.

The UK GDPR does not prescribe a single universal retention period. Organisations must consider and justify how long personal data is retained and regularly review whether it is still required.

We may retain information for longer where reasonably necessary because of an ongoing enquiry, client relationship, contract, complaint, dispute, legal claim, regulatory matter, debt recovery matter, audit requirement or other legitimate business or legal purpose.

14. Contact form retention and deletion

Website contact form submissions and related correspondence are normally retained for up to 18 months from the date of the enquiry or the last relevant communication, subject to periodic review.

We may retain information for longer where there is a valid documented reason, including:

  • an ongoing enquiry;

  • an existing client relationship;

  • an ongoing contract;

  • a complaint;

  • a legal claim;

  • a regulatory matter;

  • debt recovery;

  • an audit requirement; or

  • another legitimate legal or business requirement.

We periodically review retained enquiry information and will delete or anonymise personal data that is no longer required.

15. Security

We take appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

These measures may include:

  • access controls;

  • account security measures;

  • strong passwords and authentication controls;

  • restricting access to authorised persons;

  • secure website hosting arrangements;

  • appropriate use of security software and controls;

  • secure handling of exported or downloaded information;

  • periodic review and deletion of retained information; and

  • limiting the personal information collected through the website to information reasonably necessary for the relevant purpose.

However, no transmission or storage system can be guaranteed to be completely secure.

16. Special category and criminal offence data

Our website is not intended to collect special category personal data or criminal offence data.

Special category data may include information concerning health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, sex life or sexual orientation.

Criminal offence data relates to criminal convictions and offences and related security measures.

Please do not provide this type of information through our website unless it is genuinely necessary for your enquiry.

Where such information is provided, we will only process it where there is an appropriate legal basis and where the processing is permitted by applicable data protection law.

17. Children

Our website and services are primarily intended for businesses, organisations and adults.

We do not knowingly seek to collect personal data from children through the website.

If you believe that a child has provided personal data to us unnecessarily, please contact us so that we can review and, where appropriate, delete the information.

18. Automated decision making

We do not use personal data collected through this website to make solely automated decisions that have legal or similarly significant effects on individuals.

We do not use website enquiries, Calendly bookings or Squarespace Analytics to make automated decisions about whether an individual is entitled to receive our services.

19. Your data protection rights

Depending on the circumstances, you may have rights under applicable UK data protection law, including the right to:

  • request access to your personal data;

  • request correction of inaccurate or incomplete personal data;

  • request deletion of your personal data;

  • object to processing based on legitimate interests;

  • request restriction of processing;

  • request data portability where applicable;

  • withdraw consent where processing is based on consent; and

  • complain to the Information Commissioner's Office.

These rights are subject to certain legal conditions and exemptions. For example, we may need to retain certain information where we have a legal obligation or a legitimate need to establish, exercise or defend legal claims.

20. How to exercise your rights

To exercise your data protection rights or ask a question about how we process personal data, please contact us using the details below:

Email: info@debosecure.co.uk

Postal address: 61 Bridge Street, Kington. HR5 3DJ

We may need to ask for additional information to verify your identity before responding to a data protection request.

21. Complaints

If you have concerns about the way we handle your personal data, please contact us first so that we have an opportunity to investigate and resolve the matter.

You also have the right to complain to the Information Commissioner's Office (ICO), which is the UK's independent supervisory authority for data protection.

Information Commissioner's Office

Website: https://ico.org.uk/

The ICO's guidance recognises the right of individuals to complain to the supervisory authority where they believe their personal data has not been handled in accordance with applicable data protection law.

22. Changes to this Privacy Notice

We may update this Website Privacy Notice from time to time to reflect changes to our website, services, third party providers, legal requirements or data processing activities.

The latest version will be published on this page together with the date it was last updated.

We recommend checking this page periodically for the latest version.

23. Contact us

For questions about this Privacy Notice, our website or how we handle personal data, please contact:

DeboSecure Limited

Website: https://www.debosecure.co.uk/

Email: info@debosecure.co.uk

Address: 61 Bridge Street, Kington. HR5 3DJ