UK Cybersecurity SpecialistsTransport·Logistics·Haulage·Warehousing SMEs
Legal

Privacy Policy

This policy explains how DefendVista collects, uses, stores and protects personal data when you use defendvista.com or engage us for cybersecurity consultancy services. It also sets out your rights under the UK GDPR and the Data Protection Act 2018.

Last updated: 17 June 2026.

Who we are

DefendVista is a UK cybersecurity consultancy. For the purposes of UK data protection law, DefendVista is the data controller for personal data collected through this website and during our client engagements.

General contact: defendvista.com/contact.

What we collect

We only collect what we need to respond to you and run our services:

  • Contact form / consultation requests: name, business email, company, phone (optional), and the message you send us.
  • Cyber-readiness assessment: the answers you provide and the contact details you submit to receive your report.
  • Client engagement records: information needed to deliver the engagement, including invoicing details and project correspondence.
  • Technical / analytics data: IP address, user agent, pages visited and aggregate behaviour, collected via Google Analytics 4 and Microsoft Clarity. Form fields are masked in session replays.
  • Email infrastructure logs: delivery, bounce and complaint metadata for emails we send to you.

We do not knowingly collect special-category data through this website.

Lawful basis

  • Legitimate interests: responding to your enquiry, providing the assessment you requested, securing our site and detecting abuse.
  • Contract: delivering services you have engaged us for.
  • Legal obligation: keeping financial records and meeting regulatory requirements.
  • Consent: non-essential analytics and any marketing communications you opt in to; you can withdraw consent at any time.

How we use your data

  • Reply to your enquiry and arrange a consultation.
  • Deliver the cyber-readiness report you asked for.
  • Provide and improve our consultancy services.
  • Protect the site against fraud, abuse and security threats.
  • Meet legal, accounting and regulatory obligations.

We do not sell personal data and we do not use it for automated decision-making that produces legal or similarly significant effects.

Sharing and sub-processors

We share personal data only with vetted sub-processors that help us run the business, under written terms requiring confidentiality and appropriate security:

  • Cloud hosting and database (Supabase, EU region).
  • Edge network and WAF (Cloudflare).
  • Email infrastructure (Microsoft 365 and our transactional email provider).
  • Analytics (Google Analytics 4, Microsoft Clarity).
  • Accounting and payments providers where relevant.

Where data is transferred outside the UK, we rely on UK adequacy regulations, the UK International Data Transfer Addendum or Standard Contractual Clauses, with additional safeguards as appropriate.

Retention

  • Web enquiries and consultation requests: up to 24 months from last contact.
  • Assessment submissions: up to 24 months unless you become a client.
  • Client engagement records: 6 years after engagement end (UK accounting / limitation).
  • Analytics data: retained per the provider's default, typically up to 14 months.
  • Email delivery logs: 90 days.

Your rights

Under UK GDPR you can ask us to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Erase data where there is no overriding legal basis to keep it.
  • Restrict or object to processing.
  • Receive a portable copy of data you provided.
  • Withdraw consent where consent is the lawful basis.

To exercise any of these rights, contact us via the contact page. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).

Cookies and analytics

We use a small number of strictly necessary cookies for the site to function, plus analytics from Google Analytics 4 and Microsoft Clarity to understand how the site is used. Form fields are masked in session recordings so we do not capture the content you type. You can block non-essential cookies in your browser or via your cookie preferences.

How we protect your data

DefendVista applies the same baseline controls we recommend to clients: TLS-everywhere with HSTS, a content security policy, edge WAF and bot protection, rate limiting on contact endpoints, MFA on administrative accounts, row-level security on our database, encrypted backups and documented incident response.

No system is perfectly secure. If you believe your data may have been affected by an incident, contact us immediately so we can investigate.

Security contact (vulnerability reports only)

If you are a security researcher and have identified a vulnerability affecting defendvista.com or any DefendVista-operated service, please report it via our coordinated disclosure channel rather than the general contact form:

security@defendvista.com is monitored for vulnerability reports only. Please do not use it for sales, recruitment, support, data subject requests or general enquiries: those will be redirected and may be delayed. For everything else, use the contact page.

We commit to acknowledging good-faith reports within 1 UK working day and provide safe-harbour protections to researchers who follow the disclosure policy.

Changes to this policy

We may update this policy as our services or legal obligations change. Material changes will be reflected in the "Last updated" date at the top of this page.

Readiness ScoreBook Consultation