Legal information · Last updated 17 September 2026
Privacy Policy
This policy explains how Secure Chain Technology Group Ltd collects, uses, retains, and safeguards personal data when you use the Threat Centre or request our services.
1. Who we are
Secure Chain Technology Group Ltd is the data controller for personal data covered by this policy. We are registered in England and Wales under company number 12153901. Our registered office is 43 Clocktower Business Centre, Chesterfield, S43 2PE.
Contact our privacy team at privacy@securechaingroup.com.
2. Personal data we collect
We may collect identity and contact data, including your name, work email address, organisation, role, and communications. When you request a Security Review, Vulnerability Assessment, or Threat Exposure Review, we collect the information you submit and records needed to respond.
We may also process limited technical and usage data such as browser type, device information, IP address, security logs, consent choices, and platform interactions. Optional analytics and functional data is used only where you have consented.
3. How and why we use data
- To answer enquiries and take steps requested before entering a contract.
- To deliver agreed services and administer our relationship under a contract.
- To operate, secure, monitor, and improve the platform where necessary for our legitimate interests, balanced against your rights.
- To meet legal, regulatory, fraud-prevention, and security obligations.
- To use optional analytics or functional technologies where you have given consent, which you may withdraw at any time.
4. Sharing and international transfers
We disclose personal data only where necessary to vetted service providers, professional advisers, authorities, or counterparties involved in a corporate transaction. Providers act under written confidentiality and data-protection terms.
If data is transferred outside the UK, we use a lawful safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with supplementary measures where appropriate.
5. Retention and security
Enquiry and assessment-request records are normally retained for up to 24 months after our last meaningful contact, unless an engagement or legal obligation requires longer. Contract, transaction, and compliance records may be retained for up to seven years. Security logs are generally retained for up to 12 months. Consent records are retained for up to 12 months before renewal.
We apply proportionate technical and organisational controls designed to prevent unauthorised access, loss, misuse, alteration, or disclosure. No internet service can guarantee absolute security.
6. Your UK data protection rights
Subject to legal conditions and exemptions, you may ask us to access, correct, erase, restrict, or transfer your personal data; object to processing based on legitimate interests or direct marketing; and withdraw consent without affecting earlier lawful processing. You also have rights relating to solely automated decisions where applicable.
Contact privacy@securechaingroup.com to exercise a right. We may need to verify your identity and normally respond within one month.
7. Complaints and updates
Please contact us first so we can address your concern. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, through ico.org.uk/make-a-complaint or by calling 0303 123 1113.
We may update this policy when our processing or legal obligations change. The latest version and date will remain available on this page.