UK-based · penetration testing & red team operations
[email protected]Last updated: 12 September 2026
This policy explains how Forefront IT Security Services Ltd ("Forefront", "we", "us") collects, uses and protects personal data when you visit forefrontitsecurityservices.co.uk or engage our services. We are the data controller for the personal data described here and are committed to handling it lawfully, fairly and transparently under the UK GDPR and the Data Protection Act 2018.
Forefront IT Security Services Ltd is registered in England and Wales, company number 13646289, and is based in Gloucester, United Kingdom. If you have any questions about this policy or how we handle your data, contact us at [email protected].
Company details and registered officeInformation you give us: when you complete our contact form, request a quote, or otherwise correspond with us, we collect your name, email address, telephone number, organisation and job role where provided, and the content of your enquiry, including your selected services, scope, budget and timing.
Information collected automatically: like most websites, our hosting and content-delivery providers process limited technical data, such as IP address, browser type and pages visited, for security, abuse prevention and to keep the site running. We use Cloudflare Turnstile to distinguish genuine users from bots on our forms.
We do not knowingly collect special category data through this website, and we ask that you do not include sensitive information in free-text form fields.
To respond to your enquiry, prepare a quote or proposal, and provide the services you request.
Our quote form calculates an indicative estimate and a lead-priority category from your selections to help us review enquiries. These are not a confirmed offer or a decision to accept or refuse an engagement; scope and pricing are confirmed in a written proposal.
To manage our relationship with you, including scoping, delivery and support of security engagements.
To protect our website and services against fraud, spam and abuse.
To comply with our legal and regulatory obligations, and to establish, exercise or defend legal claims.
We rely on the following lawful bases under the UK GDPR: (a) our legitimate interests in responding to enquiries, marketing our services to businesses and securing our systems, balanced against your rights; (b) the performance of a contract with you, or steps taken at your request before entering a contract; and (c) compliance with legal obligations. Where we rely on consent, you may withdraw it at any time.
Our Cookie Policy describes browser storage, caching, form-security checks and external resources used by the public website. External resources can receive technical information such as your IP address even when they do not set a cookie. Public website browsing and authenticated AETOS or Security Front Door sessions are different processing contexts.
Cookie PolicyWe do not sell your personal data. Providers supporting our website, hosting, security and correspondence process relevant data to deliver those services. These include Cloudflare for delivery and form protection, and our email and email-delivery providers. Their roles depend on the service and applicable terms; not every external provider acts only on our instructions.
Some pages load Google-hosted fonts or assets and certification resources from Accredible and BlockMark. Loading them sends a request from your browser to the provider, which can include your IP address, browser details and referring-page information. Their own privacy notices also apply.
We may disclose data where required by law, regulation, court order, or to protect our rights, property or safety.
Some of our providers may process data outside the UK. Where that happens, we rely on adequacy regulations or appropriate safeguards (such as the International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses) to ensure your data remains protected.
We keep enquiry and engagement data for as long as necessary to fulfil the purposes above, to manage our commercial relationship, and to meet legal, accounting and regulatory requirements. When data is no longer needed, we securely delete or anonymise it.
As a security company, protecting information is core to what we do. We apply appropriate technical and organisational measures, including encryption in transit, access controls and the principle of least privilege, to safeguard personal data against unauthorised access, loss or disclosure.
Under UK data protection law you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent where processing is based on it. To exercise any of these rights, contact us at [email protected].
These rights depend on the circumstances and applicable legal exceptions. We respond without undue delay, normally within one calendar month. Where the law permits, necessary identity checks or clarification can affect the deadline. For complex or multiple requests, an extension of up to two further months may apply; we will explain the reason within the initial response period.
You can complain to the Information Commissioner's Office (ICO), whether or not you contact us first. The ICO helpline is 0303 123 1113. Its postal address is Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Make a complaint to the ICOWe may update this policy from time to time. The current version is always available on this page, and the date at the top shows when it was last revised.
For any privacy question or request, email [email protected].
For any questions about this document, contact [email protected].