LOADING…
Platform  /  Privacy
PRIVACY NOTICE

Your data,handled properly.

How we collect, use and protect personal information through this website - and the rights you have under UK GDPR. We sell assurance for a living; we hold ourselves to the same standard.

Last updated: June 2026

This Privacy Notice explains how E2E Security Consulting Ltd ("E2E SC", "we", "us" or "our") collects, uses, stores, protects and shares personal data in connection with our website, professional security consulting services and the E2ERisk Platform.

E2E SC provides cybersecurity advisory, assurance, governance, risk and compliance services, including operation of the E2ERisk Platform. We are committed to protecting personal data and being transparent about how we use it. This notice should be read alongside our Cookies Policy and, where applicable, any customer agreement, data processing agreement, privacy notices issued by our customers, and platform documentation.

1. Who this notice applies to

This notice applies to individuals whose personal data E2E SC processes as a controller. This may include:

  • website visitors and people who interact with our online content;
  • users of E2E SC services and the E2ERisk Platform where E2E SC determines the purpose and means of processing;
  • customer contacts, prospective customers, leads, event attendees and marketing contacts;
  • supplier, assessor, consultant and third-party contacts invited to use or interact with the E2ERisk Platform;
  • contacts involved in consulting, assurance, penetration testing, governance or risk engagements;
  • support, customer success and account administration contacts;
  • candidates applying for employment, contracting or consultancy roles with E2E SC; and
  • individuals who contact us with enquiries, rights requests, complaints or security matters.

Where E2E SC processes personal data only on the documented instructions of a customer, we usually act as a processor. In those circumstances, the customer is responsible for providing privacy information to relevant individuals, and our processing is governed by the data processing agreement with that customer.

2. About E2E SC and the E2ERisk Platform

E2E SC provides end-to-end cybersecurity assurance, governance, risk and compliance services for organisations, including public sector and regulated environments. Services may include security advisory, assurance frameworks, supplier assurance, penetration testing, risk assessment, secure-by-design support, data protection impact assessment support and cyber governance services.

The E2ERisk Platform is a modular SaaS platform. Customers may purchase and use modules based on their requirements, including Supplier Assurance, Secure by Design, Threat Assessment, Business Impact Assessment, Data Protection / Privacy Impact Assessment, NCSC CAF, Governance Library and Risk Assessment.

Customers decide what information to upload to the E2ERisk Platform, which users to invite, what assessments to perform and how to use outputs. E2E SC processes platform content on behalf of the relevant customer except where we use account, billing, security, support or service-operation data for our own legitimate business purposes.

3. Controller and processor roles

RoleWhen this appliesExamples
ControllerE2E SC determines why and how personal data is processed.Website enquiries, sales and marketing, billing contacts, recruitment, service administration, security monitoring and incident management.
ProcessorE2E SC processes personal data on behalf of a customer under a customer agreement and data processing agreement.Customer-uploaded platform content, supplier questionnaires, assessment records, risk records, DPIA records, CAF evidence and other customer-controlled data.
Independent controllersE2E SC and another organisation each process personal data for their own separate purposes.Customer relationship management, contractual negotiations, complaints, legal claims or regulatory responses.

This notice mainly describes E2E SC controller processing. Where we act as a processor, individuals should refer to the privacy notice of the relevant customer organisation, as that customer determines the purpose, lawful basis, users, retention and content of the processing.

4. Personal data we collect and how we use it

The tables below link the type of personal data we process with the purpose, lawful basis, typical recipients and retention approach. Some processing may fall into more than one category depending on the context.

4.1 Website visitors and enquiries

Data categoriesPurpose and lawful basisRecipientsRetention
IP address, device information, browser information, website usage data, pages visited and cookie preferences.Operate the website, protect security and remember cookie choices. Lawful basis: legitimate interests for essential operation and security; consent for non-essential cookies where required.Website hosting providers, analytics providers where consent has been given, security service providers.Session duration for many technical cookies; cookie consent records usually up to 12 months; analytics retention as described in the Cookies Policy.
Contact form details and enquiry content.Respond to enquiries and manage business communications. Lawful basis: legitimate interests; pre-contractual steps where the enquiry relates to a potential contract.E2E SC staff, CRM or ticketing providers, email service providers.Usually up to 3 years from last interaction unless a longer period is required for a contract, dispute or legal obligation.

4.2 E2ERisk Platform users

Data categoriesPurpose and lawful basisRecipientsRetention
Name, business email address, job title, organisation, role, account identifiers and authentication information.Create and administer user accounts, provide access and manage customer services. Lawful basis: contract performance or legitimate interests in operating the service.E2E SC support, customer success and administration teams; hosting and identity service providers.Duration of account or customer relationship, then retained only as needed for legal, security, audit or contractual purposes.
Usage information, activity logs, access logs, IP addresses, device identifiers, security events and audit trails.Secure the platform, detect misuse, investigate incidents, evidence customer activity and maintain platform integrity. Lawful basis: legitimate interests and, where applicable, legal obligation.E2E SC security operations, infrastructure providers, incident response partners, relevant customer administrators where appropriate.Typically 12 months rolling for operational logs unless required longer for security investigation, audit, legal claim or customer agreement.
Support tickets, platform queries, troubleshooting details and correspondence.Provide support, resolve service issues, improve the platform and maintain service records. Lawful basis: contract performance and legitimate interests.Support and product teams, ticketing providers, service providers involved in support delivery.Usually up to 3 years from closure unless a longer period is required for contract management, legal claims or security investigation.

4.3 Customer-controlled platform content

Data categoriesPurpose and lawful basisRecipientsRetention
Personal data included in customer-uploaded records, questionnaires, assessments, risk records, DPIAs, CAF evidence, assurance records, supplier responses, comments, attachments and reports.Process customer-controlled data to provide the E2ERisk Platform and related services. E2E SC usually acts as processor for this content; the customer determines the purpose, lawful basis and instructions.Authorised customer users and invited users; E2E SC personnel only where required for service, support, security or contractual purposes; approved subprocessors.As instructed by the customer and governed by the customer agreement and data processing agreement.

4.4 Consulting, assurance and testing services

Data categoriesPurpose and lawful basisRecipientsRetention
Business contact details, engagement records, correspondence, meeting notes, evidence provided by customers, vulnerability or assurance records that may contain personal data.Deliver consulting, assurance, penetration testing, governance, risk and compliance services. Lawful basis: contract performance, legitimate interests and, where applicable, legal obligation.E2E SC consultants, authorised customer contacts, approved delivery partners and professional advisers where required.Contract term plus up to 6 years, unless a shorter or longer period is required by contract, law, security investigation or legal claim.

4.5 Sales, marketing and events

Data categoriesPurpose and lawful basisRecipientsRetention
Name, business contact details, role, organisation, sector, communication preferences, event attendance and marketing interaction history.Promote relevant E2E SC services, manage events, respond to interest and develop customer relationships. Lawful basis: legitimate interests or consent where required.Sales and marketing teams, CRM, email marketing, webinar and event providers.Until unsubscribe, opt-out or usually up to 3 years from last meaningful engagement. Suppression records may be kept to respect opt-outs.

4.6 Candidates and recruitment

Data categoriesPurpose and lawful basisRecipientsRetention
Name, contact details, CV, employment history, qualifications, interview notes, right-to-work evidence, references and recruitment correspondence.Assess suitability, manage recruitment and comply with legal obligations. Lawful basis: pre-contractual steps, legitimate interests and legal obligation.Hiring managers, HR, recruitment agencies, background-check providers where applicable.Usually 6 months after decision for unsuccessful candidates; successful candidate data is handled under HR retention rules.

4.7 Finance, contracts and legal compliance

Data categoriesPurpose and lawful basisRecipientsRetention
Billing contacts, invoice details, payment records, contract correspondence, tax records and legal or regulatory correspondence.Administer contracts, issue invoices, meet tax/accounting obligations, manage disputes and comply with law. Lawful basis: contract performance, legal obligation and legitimate interests.Finance team, accountancy providers, banks, insurers, professional advisers, regulators and courts where necessary.Financial records usually 7 years; contract and legal records generally contract term plus up to 6 years, or longer where required.

5. Special category and sensitive personal data

E2E SC does not routinely collect special category personal data for its own controller purposes. Customers may choose to upload personal data or sensitive information to the E2ERisk Platform, for example in DPIA, risk, business impact or governance records. Where that occurs, the customer is responsible for determining the lawful basis, necessity, minimisation, transparency and any additional conditions required by law.

If special category data is incidentally disclosed to E2E SC, we will process it only where necessary and where an appropriate UK GDPR Article 9 condition and Data Protection Act 2018 Schedule 1 condition applies, or where we act on customer instructions as processor.

6. Cookies and similar technologies

Our website uses cookies and similar technologies. Strictly necessary cookies support website and platform operation, authentication, session security and consent management. Non-essential cookies, such as analytics or marketing cookies, are used only where required consent has been obtained. For more information about the cookies we use, their purposes, duration and how to change preferences, please see our Cookies Policy.

7. Sharing personal data

We do not sell personal data. We share personal data only where necessary for the purposes described in this notice, where required by law, or where permitted by the relevant customer agreement or data processing agreement. This may include:

  • E2E SC staff and authorised contractors who need access to perform their role;
  • hosting, infrastructure, identity, security, support, ticketing and software providers;
  • CRM, email, event and marketing automation providers;
  • professional advisers, auditors, insurers, banks and accountancy providers;
  • customers, authorised customer users, invited suppliers or assessors, where relevant to platform workflows;
  • regulators, law enforcement, courts, government bodies or public authorities where required or permitted by law; and
  • third parties involved in a merger, acquisition, restructuring or sale of all or part of our business, subject to appropriate safeguards.

Where we use processors or subprocessors, we require appropriate contractual commitments to protect personal data and process it only as permitted.

8. International data transfers

E2E SC is based in the United Kingdom and aims to use UK or appropriate regional processing locations where practicable. Some service providers may process personal data outside the UK or European Economic Area. Where personal data is transferred internationally, we use appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or other lawful transfer mechanisms where required.

9. Security

We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:

  • encryption in transit and, where appropriate, encryption at rest;
  • multi-factor authentication and role-based access controls;
  • least-privilege access and segregation of duties;
  • logging, monitoring and security event review;
  • secure development, vulnerability management and penetration testing;
  • supplier and subprocessor assurance;
  • staff training and confidentiality obligations; and
  • incident response and breach management procedures.

If a personal data breach is likely to result in a risk to individuals, we will notify the ICO within the required timescale and inform affected individuals where required by law.

10. Retention

We retain personal data only for as long as needed for the purposes described in this notice, to comply with legal obligations, to resolve disputes, to enforce agreements, to maintain security, or as required by customer agreements and data processing agreements.

Record typeTypical retention
Website enquiries and general correspondenceUsually up to 3 years from last meaningful interaction.
E2ERisk Platform account recordsDuration of account or customer relationship, then limited retention for audit, security, legal or contractual purposes.
Security and access logsTypically 12 months rolling, unless needed longer for investigations, legal claims or security assurance.
Customer-controlled platform contentAs instructed by the customer and governed by the customer agreement and data processing agreement.
Marketing and lead recordsUntil opt-out or usually up to 3 years from last meaningful engagement. Suppression records may be retained to respect opt-outs.
Financial and tax recordsUsually 7 years.
Contract and legal recordsContract term plus up to 6 years, or longer where required for legal claims or regulatory purposes.
Candidate recordsUsually 6 months after decision for unsuccessful candidates; successful candidate records are retained under HR retention rules.

When retention periods expire, personal data is deleted, anonymised or isolated from active processing until deletion is practicable, for example where data remains in backup archives for a limited period.

11. AI, analytics and automated decision-making

E2E SC may use analytics and service improvement tools to understand how our website, services and platform are used, to improve reliability, security, usability and customer support.

The E2ERisk Platform may provide templates, dashboards, outputs, scoring, summaries, reports or recommendations to support customer decision-making. These outputs are decision-support materials and customers remain responsible for reviewing outputs and making final governance, risk, security, privacy and business decisions.

E2E SC does not use solely automated decision-making that produces legal or similarly significant effects about individuals for our own controller purposes unless we tell individuals separately and provide the required information and safeguards.

12. Your rights

Under UK data protection law, individuals have rights in relation to their personal data. These rights may depend on the context and lawful basis for processing.

RightWhat it means
Right of accessYou can ask for a copy of personal data we hold about you.
Right to rectificationYou can ask us to correct inaccurate or incomplete personal data.
Right to erasureYou can ask us to delete personal data where there is no continuing lawful reason to keep it.
Right to restrictionYou can ask us to restrict how we use personal data in certain circumstances.
Right to data portabilityWhere processing is based on consent or contract and carried out by automated means, you can request data in a portable format.
Right to objectYou can object to processing based on legitimate interests or to direct marketing.
Right to withdraw consentWhere we rely on consent, you can withdraw it at any time. This does not affect processing before withdrawal.
Rights relating to automated decisionsYou have rights relating to solely automated decisions that have legal or similarly significant effects.

To exercise rights in relation to processing where E2E SC acts as controller, contact privacy@e2esc.co.uk. We usually respond within one calendar month. This may be extended where requests are complex or numerous. Where E2E SC acts as processor for a customer, we may need to refer your request to the relevant customer or assist that customer in responding.

13. Complaints

If you have concerns about how we handle personal data, please contact privacy@e2esc.co.uk in the first instance. We will acknowledge data protection complaints within 30 days and respond without undue delay.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. The ICO can be contacted through ico.org.uk or by telephone on 0303 123 1113.

14. Third-party links

Our website, services and platform may link to third-party websites, services or content. We are not responsible for the privacy practices of those third parties. You should review their privacy notices before providing personal data to them.

15. Changes to this notice

We may update this notice from time to time to reflect changes to our services, platform, suppliers, processing activities or applicable law. The date at the top shows when this notice was last updated. Where changes are material, we will take reasonable steps to bring them to the attention of affected individuals.

16. Contact us

Contact methodDetails
Privacy contactprivacy@e2esc.co.uk
Security contactsecurity@e2esc.co.uk
Websitewww.e2esc.co.uk
Postal addressData Protection, E2E Security Consulting Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Company number16563415 (registered in England & Wales)

This notice applies to the laws of England and Wales: UK GDPR; Data Protection Act 2018; the Privacy and Electronic Communications Regulations (PECR); and the Data (Use and Access) Act 2025.