How we collect, use and protect personal information through this website - and the rights you have under UK GDPR. We sell assurance for a living; we hold ourselves to the same standard.
Last updated: June 2026
This Privacy Notice explains how E2E Security Consulting Ltd ("E2E SC", "we", "us" or "our") collects, uses, stores, protects and shares personal data in connection with our website, professional security consulting services and the E2ERisk Platform.
E2E SC provides cybersecurity advisory, assurance, governance, risk and compliance services, including operation of the E2ERisk Platform. We are committed to protecting personal data and being transparent about how we use it. This notice should be read alongside our Cookies Policy and, where applicable, any customer agreement, data processing agreement, privacy notices issued by our customers, and platform documentation.
This notice applies to individuals whose personal data E2E SC processes as a controller. This may include:
Where E2E SC processes personal data only on the documented instructions of a customer, we usually act as a processor. In those circumstances, the customer is responsible for providing privacy information to relevant individuals, and our processing is governed by the data processing agreement with that customer.
E2E SC provides end-to-end cybersecurity assurance, governance, risk and compliance services for organisations, including public sector and regulated environments. Services may include security advisory, assurance frameworks, supplier assurance, penetration testing, risk assessment, secure-by-design support, data protection impact assessment support and cyber governance services.
The E2ERisk Platform is a modular SaaS platform. Customers may purchase and use modules based on their requirements, including Supplier Assurance, Secure by Design, Threat Assessment, Business Impact Assessment, Data Protection / Privacy Impact Assessment, NCSC CAF, Governance Library and Risk Assessment.
Customers decide what information to upload to the E2ERisk Platform, which users to invite, what assessments to perform and how to use outputs. E2E SC processes platform content on behalf of the relevant customer except where we use account, billing, security, support or service-operation data for our own legitimate business purposes.
| Role | When this applies | Examples |
|---|---|---|
| Controller | E2E SC determines why and how personal data is processed. | Website enquiries, sales and marketing, billing contacts, recruitment, service administration, security monitoring and incident management. |
| Processor | E2E SC processes personal data on behalf of a customer under a customer agreement and data processing agreement. | Customer-uploaded platform content, supplier questionnaires, assessment records, risk records, DPIA records, CAF evidence and other customer-controlled data. |
| Independent controllers | E2E SC and another organisation each process personal data for their own separate purposes. | Customer relationship management, contractual negotiations, complaints, legal claims or regulatory responses. |
This notice mainly describes E2E SC controller processing. Where we act as a processor, individuals should refer to the privacy notice of the relevant customer organisation, as that customer determines the purpose, lawful basis, users, retention and content of the processing.
The tables below link the type of personal data we process with the purpose, lawful basis, typical recipients and retention approach. Some processing may fall into more than one category depending on the context.
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| IP address, device information, browser information, website usage data, pages visited and cookie preferences. | Operate the website, protect security and remember cookie choices. Lawful basis: legitimate interests for essential operation and security; consent for non-essential cookies where required. | Website hosting providers, analytics providers where consent has been given, security service providers. | Session duration for many technical cookies; cookie consent records usually up to 12 months; analytics retention as described in the Cookies Policy. |
| Contact form details and enquiry content. | Respond to enquiries and manage business communications. Lawful basis: legitimate interests; pre-contractual steps where the enquiry relates to a potential contract. | E2E SC staff, CRM or ticketing providers, email service providers. | Usually up to 3 years from last interaction unless a longer period is required for a contract, dispute or legal obligation. |
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| Name, business email address, job title, organisation, role, account identifiers and authentication information. | Create and administer user accounts, provide access and manage customer services. Lawful basis: contract performance or legitimate interests in operating the service. | E2E SC support, customer success and administration teams; hosting and identity service providers. | Duration of account or customer relationship, then retained only as needed for legal, security, audit or contractual purposes. |
| Usage information, activity logs, access logs, IP addresses, device identifiers, security events and audit trails. | Secure the platform, detect misuse, investigate incidents, evidence customer activity and maintain platform integrity. Lawful basis: legitimate interests and, where applicable, legal obligation. | E2E SC security operations, infrastructure providers, incident response partners, relevant customer administrators where appropriate. | Typically 12 months rolling for operational logs unless required longer for security investigation, audit, legal claim or customer agreement. |
| Support tickets, platform queries, troubleshooting details and correspondence. | Provide support, resolve service issues, improve the platform and maintain service records. Lawful basis: contract performance and legitimate interests. | Support and product teams, ticketing providers, service providers involved in support delivery. | Usually up to 3 years from closure unless a longer period is required for contract management, legal claims or security investigation. |
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| Personal data included in customer-uploaded records, questionnaires, assessments, risk records, DPIAs, CAF evidence, assurance records, supplier responses, comments, attachments and reports. | Process customer-controlled data to provide the E2ERisk Platform and related services. E2E SC usually acts as processor for this content; the customer determines the purpose, lawful basis and instructions. | Authorised customer users and invited users; E2E SC personnel only where required for service, support, security or contractual purposes; approved subprocessors. | As instructed by the customer and governed by the customer agreement and data processing agreement. |
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| Business contact details, engagement records, correspondence, meeting notes, evidence provided by customers, vulnerability or assurance records that may contain personal data. | Deliver consulting, assurance, penetration testing, governance, risk and compliance services. Lawful basis: contract performance, legitimate interests and, where applicable, legal obligation. | E2E SC consultants, authorised customer contacts, approved delivery partners and professional advisers where required. | Contract term plus up to 6 years, unless a shorter or longer period is required by contract, law, security investigation or legal claim. |
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| Name, business contact details, role, organisation, sector, communication preferences, event attendance and marketing interaction history. | Promote relevant E2E SC services, manage events, respond to interest and develop customer relationships. Lawful basis: legitimate interests or consent where required. | Sales and marketing teams, CRM, email marketing, webinar and event providers. | Until unsubscribe, opt-out or usually up to 3 years from last meaningful engagement. Suppression records may be kept to respect opt-outs. |
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| Name, contact details, CV, employment history, qualifications, interview notes, right-to-work evidence, references and recruitment correspondence. | Assess suitability, manage recruitment and comply with legal obligations. Lawful basis: pre-contractual steps, legitimate interests and legal obligation. | Hiring managers, HR, recruitment agencies, background-check providers where applicable. | Usually 6 months after decision for unsuccessful candidates; successful candidate data is handled under HR retention rules. |
| Data categories | Purpose and lawful basis | Recipients | Retention |
|---|---|---|---|
| Billing contacts, invoice details, payment records, contract correspondence, tax records and legal or regulatory correspondence. | Administer contracts, issue invoices, meet tax/accounting obligations, manage disputes and comply with law. Lawful basis: contract performance, legal obligation and legitimate interests. | Finance team, accountancy providers, banks, insurers, professional advisers, regulators and courts where necessary. | Financial records usually 7 years; contract and legal records generally contract term plus up to 6 years, or longer where required. |
E2E SC does not routinely collect special category personal data for its own controller purposes. Customers may choose to upload personal data or sensitive information to the E2ERisk Platform, for example in DPIA, risk, business impact or governance records. Where that occurs, the customer is responsible for determining the lawful basis, necessity, minimisation, transparency and any additional conditions required by law.
If special category data is incidentally disclosed to E2E SC, we will process it only where necessary and where an appropriate UK GDPR Article 9 condition and Data Protection Act 2018 Schedule 1 condition applies, or where we act on customer instructions as processor.
Our website uses cookies and similar technologies. Strictly necessary cookies support website and platform operation, authentication, session security and consent management. Non-essential cookies, such as analytics or marketing cookies, are used only where required consent has been obtained. For more information about the cookies we use, their purposes, duration and how to change preferences, please see our Cookies Policy.
We do not sell personal data. We share personal data only where necessary for the purposes described in this notice, where required by law, or where permitted by the relevant customer agreement or data processing agreement. This may include:
Where we use processors or subprocessors, we require appropriate contractual commitments to protect personal data and process it only as permitted.
E2E SC is based in the United Kingdom and aims to use UK or appropriate regional processing locations where practicable. Some service providers may process personal data outside the UK or European Economic Area. Where personal data is transferred internationally, we use appropriate safeguards such as adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or other lawful transfer mechanisms where required.
We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include:
If a personal data breach is likely to result in a risk to individuals, we will notify the ICO within the required timescale and inform affected individuals where required by law.
We retain personal data only for as long as needed for the purposes described in this notice, to comply with legal obligations, to resolve disputes, to enforce agreements, to maintain security, or as required by customer agreements and data processing agreements.
| Record type | Typical retention |
|---|---|
| Website enquiries and general correspondence | Usually up to 3 years from last meaningful interaction. |
| E2ERisk Platform account records | Duration of account or customer relationship, then limited retention for audit, security, legal or contractual purposes. |
| Security and access logs | Typically 12 months rolling, unless needed longer for investigations, legal claims or security assurance. |
| Customer-controlled platform content | As instructed by the customer and governed by the customer agreement and data processing agreement. |
| Marketing and lead records | Until opt-out or usually up to 3 years from last meaningful engagement. Suppression records may be retained to respect opt-outs. |
| Financial and tax records | Usually 7 years. |
| Contract and legal records | Contract term plus up to 6 years, or longer where required for legal claims or regulatory purposes. |
| Candidate records | Usually 6 months after decision for unsuccessful candidates; successful candidate records are retained under HR retention rules. |
When retention periods expire, personal data is deleted, anonymised or isolated from active processing until deletion is practicable, for example where data remains in backup archives for a limited period.
E2E SC may use analytics and service improvement tools to understand how our website, services and platform are used, to improve reliability, security, usability and customer support.
The E2ERisk Platform may provide templates, dashboards, outputs, scoring, summaries, reports or recommendations to support customer decision-making. These outputs are decision-support materials and customers remain responsible for reviewing outputs and making final governance, risk, security, privacy and business decisions.
E2E SC does not use solely automated decision-making that produces legal or similarly significant effects about individuals for our own controller purposes unless we tell individuals separately and provide the required information and safeguards.
Under UK data protection law, individuals have rights in relation to their personal data. These rights may depend on the context and lawful basis for processing.
| Right | What it means |
|---|---|
| Right of access | You can ask for a copy of personal data we hold about you. |
| Right to rectification | You can ask us to correct inaccurate or incomplete personal data. |
| Right to erasure | You can ask us to delete personal data where there is no continuing lawful reason to keep it. |
| Right to restriction | You can ask us to restrict how we use personal data in certain circumstances. |
| Right to data portability | Where processing is based on consent or contract and carried out by automated means, you can request data in a portable format. |
| Right to object | You can object to processing based on legitimate interests or to direct marketing. |
| Right to withdraw consent | Where we rely on consent, you can withdraw it at any time. This does not affect processing before withdrawal. |
| Rights relating to automated decisions | You have rights relating to solely automated decisions that have legal or similarly significant effects. |
To exercise rights in relation to processing where E2E SC acts as controller, contact privacy@e2esc.co.uk. We usually respond within one calendar month. This may be extended where requests are complex or numerous. Where E2E SC acts as processor for a customer, we may need to refer your request to the relevant customer or assist that customer in responding.
If you have concerns about how we handle personal data, please contact privacy@e2esc.co.uk in the first instance. We will acknowledge data protection complaints within 30 days and respond without undue delay.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. The ICO can be contacted through ico.org.uk or by telephone on 0303 123 1113.
Our website, services and platform may link to third-party websites, services or content. We are not responsible for the privacy practices of those third parties. You should review their privacy notices before providing personal data to them.
We may update this notice from time to time to reflect changes to our services, platform, suppliers, processing activities or applicable law. The date at the top shows when this notice was last updated. Where changes are material, we will take reasonable steps to bring them to the attention of affected individuals.
| Contact method | Details |
|---|---|
| Privacy contact | privacy@e2esc.co.uk |
| Security contact | security@e2esc.co.uk |
| Website | www.e2esc.co.uk |
| Postal address | Data Protection, E2E Security Consulting Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom |
| Company number | 16563415 (registered in England & Wales) |
This notice applies to the laws of England and Wales: UK GDPR; Data Protection Act 2018; the Privacy and Electronic Communications Regulations (PECR); and the Data (Use and Access) Act 2025.