This is a comprehensive UK and EU-oriented website template, not a substitute for advice from a solicitor or data-protection professional. Replace every highlighted field with the company’s real legal name, company number, registered office, privacy email and service-specific information before launch.
Who we are
SecureFlowGroup provides website protection, vulnerability monitoring, malware detection, security alerts and incident-response services. For personal information used to operate this website, market our services, manage accounts and bill customers, the SecureFlowGroup legal entity identified above acts as the controller.
Where customers submit or connect personal information from their own websites to the protection platform, the customer will normally act as controller and SecureFlowGroup will normally act as processor. Those activities are also governed by the Data Processing Addendum.
Scope of this policy
This policy applies to visitors, prospective customers, customers, authorised account users, job applicants, partners and people who contact us. It covers the SecureFlowGroup website, account area, support channels, sales activity and website-protection platform.
It is written with the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, the EU GDPR where it applies, and the UK Privacy and Electronic Communications Regulations in mind. Local laws may provide additional rights.
Information we collect
Account and identity
Name, business contact details, employer, role, account identifiers, authentication records and multi-factor authentication settings.
Commercial and billing
Plan, subscription, invoices, transaction references, billing address and limited payment information received from payment providers.
Device and usage
IP address, browser, device type, approximate region, pages viewed, session times, feature use, audit logs and support interactions.
Communications
Emails, support tickets, call notes, survey answers, product feedback and marketing preferences.
We ask customers not to send special-category information, criminal-offence information or unnecessary personal information through support channels or scan notes.
Website security data
When a customer authorises protection or assessment, we may process domain names, DNS records, IP addresses, certificates, headers, URLs, application responses, script metadata, plugin or framework identifiers, request patterns, authentication events, bot signals, vulnerability evidence, malware indicators and incident records.
Security data may sometimes contain personal information, such as an IP address, account identifier, email address in a log, or information entered into a compromised form. We limit collection to what is reasonably necessary for the authorised security purpose and apply customer-configurable retention where available.
Where information comes from
- Directly from you when you create an account, request a demo, contact support or apply for a role.
- From your organisation, an authorised administrator or an integration you choose to connect.
- Automatically from your device, browser and use of the website or platform.
- From authorised scans, security sensors, public internet records and threat-intelligence sources.
- From service providers, payment processors, identity providers, partners and lawful public sources.
How and why we use information
| Purpose | Typical lawful basis |
|---|---|
| Provide accounts, scans, monitoring, alerts, support and contracted services | Performance of a contract and steps requested before entering a contract |
| Protect SecureFlowGroup, customers and users; investigate abuse, fraud and security incidents | Legitimate interests, legal obligation and, where necessary, substantial public-interest or legal-claims conditions |
| Manage billing, accounting, tax and corporate records | Contract and legal obligation |
| Improve product reliability, detection quality and user experience | Legitimate interests, using aggregated or de-identified information where practical |
| Send requested service messages and security notices | Contract, legal obligation and legitimate interests |
| Send optional marketing | Consent or permitted legitimate-interest/soft-opt-in rules, with an unsubscribe option |
| Handle job applications | Pre-contract steps, legitimate interests and employment-law obligations |
Where we rely on legitimate interests, we consider necessity, proportionality and the effect on individuals. We do not use customer security data to train general-purpose public AI models unless a customer gives explicit written permission.
International transfers
Services may involve processing in the United Kingdom, European Economic Area and other countries. When a restricted transfer is made, we use an approved mechanism such as an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with a transfer-risk assessment and supplementary measures where required.
Regional hosting options and the current subprocessor list should be confirmed in the customer order form or trust centre before launch.
How long information is kept
We keep personal information only for as long as needed for the purpose described, including service delivery, account security, dispute resolution, legal claims, tax and regulatory duties. Typical periods should be confirmed before publication:
Account records
For the account term and a limited period afterwards to support reactivation, security and legal obligations.
Security events
According to the customer plan and configuration, with shorter retention for raw request data where practical.
Billing records
For the period required by tax, accounting and anti-fraud rules.
Marketing records
Until consent is withdrawn or the information is no longer relevant, while retaining a suppression record where needed.
Backups are protected and removed through scheduled lifecycle processes. Information may be retained longer where a legal hold, active dispute or security investigation requires it.
How information is protected
Controls include encryption in transit, encryption at rest where appropriate, least-privilege access, strong authentication, role-based permissions, audit logging, vulnerability management, secure development, supplier review, employee confidentiality duties, incident response and tested backup procedures.
No service can promise absolute security. Customers must secure their credentials, use multi-factor authentication where available, maintain accurate authorised-user lists and tell us promptly about suspected compromise.
Your privacy rights
Depending on the law that applies, you may ask for access, correction, deletion, restriction, portability or objection. You may withdraw consent at any time without affecting earlier lawful processing. You may also object to direct marketing at any time.
Requests can be made through the contact page or the privacy email listed above. We may need to verify identity and authority. We will respond within the period required by applicable law and explain any lawful limitation or extension.
SecureFlowGroup does not currently make decisions producing legal or similarly significant effects solely through automated processing. Security scoring and prioritisation support human or customer decisions and can be reviewed.
Complaints and regulators
You may complain directly to SecureFlowGroup using the contact route above. We will acknowledge a UK data-protection complaint within the legally required period and respond without undue delay.
People in the United Kingdom may also complain to the Information Commissioner’s Office. People in the EEA may complain to the supervisory authority in the country where they live, work or believe an infringement occurred. We would appreciate the opportunity to address the concern first.
Children
SecureFlowGroup is designed for organisations and authorised adult users, not children. We do not knowingly create accounts for children or intentionally collect their personal information. If the service is ever directed to, or likely to be accessed by, children, a separate assessment and age-appropriate protections must be implemented before launch.
Changes and contact
We may update this policy when services, suppliers or laws change. Material changes will be highlighted through the website, account area or email where appropriate. The date at the top shows the latest version.
Privacy questions, rights requests and complaints should be sent to [PRIVACY EMAIL] or by post to [REGISTERED OFFICE].