DeboSecure -Privacy Notice
Website Privacy Notice
Last updated: 23 August 2026
1. Introduction
This Website Privacy Notice explains how DeboSecure Limited collects, uses, stores and protects personal data when you use our website.
This notice applies to users of:
It covers personal data collected when you visit our website, submit an enquiry or contact form, book a consultation through Calendly, communicate with us, or otherwise interact with our website and its services.
We are committed to handling personal data responsibly and in accordance with applicable UK data protection law, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations 2003 (PECR).
2. Who we are
Organisation: DeboSecure Limited
Trading name: DeboSecure Limited
Website: https://www.debosecure.co.uk/
Business address: 61 Bridge Street, Kington. HR5 3D
Privacy contact: info@debosecure.co.uk
For the purposes of applicable UK data protection law, we are the data controller for personal data collected through this website, except where a third party processes information on our behalf as a data processor.
3. Personal data we collect
| Category | Examples |
|---|---|
| Contact and enquiry data | Name, email address, telephone number, company or organisation name, job title and enquiry details. |
| Consultation and booking data | Name, email address, telephone number, organisation, booking details, meeting preferences and information you provide when arranging a consultation through Calendly. |
| Communication data | Emails, replies, correspondence, enquiry history and information contained in communications with us. |
| Technical data | IP address, browser type, device type, operating system, language, referring website and technical information generated when using the website. |
| Website analytics data | Information about how visitors use our website, including pages viewed, visits, traffic sources, approximate geographical information and device or browser information. |
| Cookie and similar technology data | Information collected through cookies and other storage or access technologies used by our website. |
| Voluntary information | Any other personal information you choose to provide when contacting us or using our website. |
4. How we collect personal data
We may collect personal data when you:
submit a contact or enquiry form;
request information about our services;
book a consultation or meeting through Calendly;
email us or communicate with us;
browse or interact with our website;
use features or forms provided through our website;
provide information voluntarily during a consultation or enquiry;
interact with cookies, analytics or similar technologies; or
our website and hosting systems generate technical or security information.
Some information may also be provided to us by third party services integrated with our website, such as Calendly, where you use those services to arrange a consultation.
5. How we use personal data
We may use personal data to:
receive, review and respond to website enquiries;
arrange and manage consultations and meetings;
communicate with prospective and existing clients;
provide information about our cyber security services;
understand the requirements of prospective clients;
manage business relationships;
follow up on enquiries;
provide quotations, proposals or other pre contractual information;
maintain the security and functionality of the website;
understand how visitors use our website;
analyse website performance and improve content and user experience;
maintain appropriate records of communications and enquiries;
prevent or investigate misuse, security incidents or fraudulent activity;
handle complaints, disputes, legal claims or regulatory matters; and
comply with legal and regulatory obligations.
We will only use personal data for purposes that are compatible with the purposes described in this notice or otherwise permitted by law.
6. Lawful basis for processing
We do not intend to collect special category personal data or criminal offence data through our website.
Please do not provide unnecessary sensitive personal information through contact forms, booking forms or general enquiries.
| Purpose | Lawful basis |
|---|---|
| Responding to website enquiries | Legitimate interests |
| Responding to requests for information | Legitimate interests |
| Taking steps at your request before entering into a contract | Pre contractual steps |
| Providing and managing consultations requested by you | Contract or pre contractual steps |
| Managing client and business communications | Legitimate interests and/or contract |
| Website security and technical operation | Legitimate interests |
| Website analytics and non essential cookies | Consent where required |
| Compliance with legal obligations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests and/or legal obligation |
Depending on the circumstances, we rely on one or more of the following lawful bases under the UK GDPR:
7. Squarespace and website analytics
Our website is built and hosted using Squarespace.
We use Squarespace Analytics to understand how visitors interact with our website and to help us improve website content, performance and user experience.
Squarespace Analytics may provide information such as:
pages viewed;
number of visits;
unique visitors;
traffic sources;
referring websites;
device and browser information;
approximate geographical information; and
information about how visitors interact with website content.
Squarespace states that certain analytics and performance cookies may be used to provide analytics information, including information about visitors, visits and traffic sources.
Where applicable law requires consent for non essential cookies or other storage and access technologies, we will seek that consent before using them. The ICO's current guidance confirms that PECR can apply to cookies and other technologies that store information on, or access information from, a user's device.
You can manage your cookie preferences using the cookie controls provided on our website where available.
8. Cookies and similar technologies
Our website uses cookies and similar technologies.
Some are necessary for the website to operate correctly, maintain security or provide functionality requested by visitors.
Other cookies or similar technologies may be used for analytics, performance or other purposes.
Where consent is required, non essential cookies will not be used until you provide the appropriate consent.
The ICO's current guidance requires organisations to provide appropriate information about storage and access technologies and, where an exception does not apply, obtain prior consent.
For detailed information about the cookies and similar technologies used on our website, please see our Cookie Notice and the cookie settings provided on the website.
9. Calendly and consultation bookings
We use Calendly to allow visitors to schedule consultations and meetings with us.
When you use our Calendly booking facility, Calendly may process information such as your name, email address, telephone number, booking information and any other information you choose to provide through the booking process.
Calendly states that customer data submitted through its services is processed on behalf of its customers in accordance with the customer's instructions and applicable contractual arrangements.
Calendly currently states that its data is hosted in United States based data centres operated using Google Cloud Services and Amazon Web Services. Its current Data Processing Addendum provides contractual safeguards for UK personal data transfers, including the UK Addendum to the Standard Contractual Clauses where applicable.
By using our consultation booking facility, you should also review Calendly's own privacy information.
Calendly Privacy Notice:
https://calendly.com/legal/privacy-notice
10. Website hosting and third party services
Our website is provided using Squarespace.
We may also use third party service providers to provide functions such as:
website hosting and infrastructure;
website analytics;
consultation scheduling;
email and communications;
website security;
information technology support;
professional services; and
other services required to operate our business.
Third party providers may process personal data on our behalf where necessary to provide their services.
We seek to ensure that appropriate contractual and data protection safeguards are in place where third parties process personal data on our behalf.
11. Who we share personal data with
We may share personal data where necessary with:
authorised members of our organisation;
Squarespace and associated service providers;
Calendly for consultation and appointment scheduling;
email and communications providers;
website developers or technical support providers;
cyber security, IT or managed service providers where required;
professional advisers, such as legal or accountancy advisers;
insurers where necessary;
regulators and public authorities where legally required;
courts, law enforcement agencies or other competent authorities where required by law; and
third parties where necessary to establish, exercise or defend legal rights.
We do not sell personal data.
We will only disclose personal data where there is a lawful basis for doing so and only to the extent reasonably necessary for the relevant purpose.
12. International transfers
Some of the service providers we use may process personal data outside the United Kingdom.
Where personal data is transferred outside the UK, we will take appropriate steps to ensure that the transfer is lawful and that suitable safeguards are in place where required.
These safeguards may include:
UK adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to the EU Standard Contractual Clauses;
applicable certification or recognised transfer mechanisms; or
another lawful transfer mechanism permitted by UK data protection law.
For example, Calendly currently states that its services process customer data in the United States and that contractual safeguards are used for relevant UK data transfers.
13. How long we keep personal data
We do not keep personal data for longer than is reasonably necessary for the purposes for which it was collected.
Our retention periods will depend on the nature of the information and why we need it.
Our legitimate interests may include operating and securing our website, responding to genuine business enquiries, developing and managing business relationships, improving our services, preventing misuse and protecting our legal rights.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
| Data type | Typical retention approach |
|---|---|
| Website contact and enquiry information | Normally retained for up to 18 months from the enquiry or last relevant communication, subject to periodic review. |
| Consultation and Calendly booking information | Normally retained for as long as reasonably necessary to manage the enquiry or business relationship and for appropriate business records. |
| Related email correspondence | Normally retained for up to 18 months after the last relevant communication, unless a longer period is justified. |
| Website analytics information | Retained in accordance with the relevant Squarespace settings and applicable service configuration. |
| Technical and security information | Retained only for as long as reasonably necessary for security, troubleshooting, administration or legal purposes. |
| Information required for legal, contractual or regulatory purposes | Retained for as long as necessary for the relevant purpose. |
The UK GDPR does not prescribe a single universal retention period. Organisations must consider and justify how long personal data is retained and regularly review whether it is still required.
We may retain information for longer where reasonably necessary because of an ongoing enquiry, client relationship, contract, complaint, dispute, legal claim, regulatory matter, debt recovery matter, audit requirement or other legitimate business or legal purpose.
14. Contact form retention and deletion
Website contact form submissions and related correspondence are normally retained for up to 18 months from the date of the enquiry or the last relevant communication, subject to periodic review.
We may retain information for longer where there is a valid documented reason, including:
an ongoing enquiry;
an existing client relationship;
an ongoing contract;
a complaint;
a legal claim;
a regulatory matter;
debt recovery;
an audit requirement; or
another legitimate legal or business requirement.
We periodically review retained enquiry information and will delete or anonymise personal data that is no longer required.
15. Security
We take appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
These measures may include:
access controls;
account security measures;
strong passwords and authentication controls;
restricting access to authorised persons;
secure website hosting arrangements;
appropriate use of security software and controls;
secure handling of exported or downloaded information;
periodic review and deletion of retained information; and
limiting the personal information collected through the website to information reasonably necessary for the relevant purpose.
However, no transmission or storage system can be guaranteed to be completely secure.
16. Special category and criminal offence data
Our website is not intended to collect special category personal data or criminal offence data.
Special category data may include information concerning health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, sex life or sexual orientation.
Criminal offence data relates to criminal convictions and offences and related security measures.
Please do not provide this type of information through our website unless it is genuinely necessary for your enquiry.
Where such information is provided, we will only process it where there is an appropriate legal basis and where the processing is permitted by applicable data protection law.
17. Children
Our website and services are primarily intended for businesses, organisations and adults.
We do not knowingly seek to collect personal data from children through the website.
If you believe that a child has provided personal data to us unnecessarily, please contact us so that we can review and, where appropriate, delete the information.
18. Automated decision making
We do not use personal data collected through this website to make solely automated decisions that have legal or similarly significant effects on individuals.
We do not use website enquiries, Calendly bookings or Squarespace Analytics to make automated decisions about whether an individual is entitled to receive our services.
19. Your data protection rights
Depending on the circumstances, you may have rights under applicable UK data protection law, including the right to:
request access to your personal data;
request correction of inaccurate or incomplete personal data;
request deletion of your personal data;
object to processing based on legitimate interests;
request restriction of processing;
request data portability where applicable;
withdraw consent where processing is based on consent; and
complain to the Information Commissioner's Office.
These rights are subject to certain legal conditions and exemptions. For example, we may need to retain certain information where we have a legal obligation or a legitimate need to establish, exercise or defend legal claims.
20. How to exercise your rights
To exercise your data protection rights or ask a question about how we process personal data, please contact us using the details below:
Email: info@debosecure.co.uk
Postal address: 61 Bridge Street, Kington. HR5 3DJ
We may need to ask for additional information to verify your identity before responding to a data protection request.
21. Complaints
If you have concerns about the way we handle your personal data, please contact us first so that we have an opportunity to investigate and resolve the matter.
You also have the right to complain to the Information Commissioner's Office (ICO), which is the UK's independent supervisory authority for data protection.
Information Commissioner's Office
Website: https://ico.org.uk/
The ICO's guidance recognises the right of individuals to complain to the supervisory authority where they believe their personal data has not been handled in accordance with applicable data protection law.
22. Changes to this Privacy Notice
We may update this Website Privacy Notice from time to time to reflect changes to our website, services, third party providers, legal requirements or data processing activities.
The latest version will be published on this page together with the date it was last updated.
We recommend checking this page periodically for the latest version.
23. Contact us
For questions about this Privacy Notice, our website or how we handle personal data, please contact:
DeboSecure Limited
Website: https://www.debosecure.co.uk/
Email: info@debosecure.co.uk
Address: 61 Bridge Street, Kington. HR5 3DJ