BeeSec Limited Privacy Notice


Effective Date: 16 July 2026


BeeSec Limited ("BeeSec", "we", "our", or "us") is committed to protecting your privacy and handling personal information in a transparent and secure manner. This Privacy Notice explains how we collect, use, disclose and protect personal data when you interact with our website, communicate with us, or engage BeeSec to provide professional security services.

This Privacy Notice has been prepared in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and other applicable data protection legislation.


1. Who We Are


BeeSec Limited is a cyber security consultancy specialising in penetration testing and security advisory services.



Data Controller

BeeSec Limited

Email: [email protected]

Website: https://www.beesec.co.uk


2. Personal Information We Collect


Depending on how you interact with us, we may collect the following categories of personal information.


Website Visitors

  • Name
  • Email address
  • Telephone number
  • Company name
  • Information submitted through contact forms
  • IP address
  • Browser type
  • Device information
  • Website usage information
  • Cookies and similar technologies


Customers and Prospective Customers

  • Contact details
  • Job title
  • Company information
  • Business correspondence
  • Meeting notes
  • Purchase and billing information
  • Technical information necessary to deliver our services


Suppliers

  • Contact information
  • Contractual information
  • Payment details
  • Business communications


Recruitment

Where you apply for a role with BeeSec we may collect:

  • CV
  • Employment history
  • Qualifications
  • References
  • Interview notes


3. How We Use Personal Information


We process personal information to:

  • Respond to enquiries
  • Deliver penetration testing and security consultancy services
  • Manage customer relationships
  • Prepare proposals and contracts
  • Provide technical support
  • Manage invoices and payments
  • Improve our website
  • Meet legal and regulatory obligations
  • Protect BeeSec, our staff and our customers from fraud and cyber threats


We do not sell personal information.


4. Lawful Basis for Processing


Under the UK GDPR we rely upon one or more of the following lawful bases:

  • Contract
  • Legitimate Interests
  • Legal Obligation
  • Consent (where required)
  • Vital Interests (where applicable)


Where consent is used, it may be withdrawn at any time.


5. Marketing Communications


Where you have requested information from us or have consented to receive marketing communications, we may contact you with information relating to BeeSec's services.

You may unsubscribe from marketing communications at any time.

We do not send unsolicited marketing where consent is required by law.


6. Cookies


Our website may use cookies and similar technologies to:

  • Maintain website functionality
  • Analyse website usage
  • Improve website performance

You can manage cookies through your browser settings.


7. Sharing Personal Information


We may share personal information with trusted service providers where necessary to operate our business, including providers of:

  • Microsoft 365
  • Microsoft Azure
  • Website hosting
  • Accounting services
  • Payment processing
  • Professional advisers
  • Legal services


These providers process information only where necessary and under appropriate contractual safeguards.

We may also disclose information where required by law or regulatory obligation.


8. International Transfers


BeeSec seeks to process personal information within the United Kingdom wherever practicable.

Where information is transferred outside the UK, appropriate safeguards will be implemented in accordance with UK GDPR requirements, including adequacy regulations or approved contractual safeguards where applicable.


9. Information Security


BeeSec applies appropriate technical and organisational measures to protect personal information, including:

  • Microsoft Entra ID authentication
  • Multi-Factor Authentication (MFA)
  • Full disk encryption (BitLocker and LUKS)
  • Secure cloud infrastructure
  • Role-based access controls
  • Principle of least privilege
  • Security monitoring
  • Vulnerability management
  • Secure software development practices
  • Staff security awareness training


No system connected to the Internet can be guaranteed to be completely secure; however, BeeSec continually reviews and improves its security controls.


10. Data Retention


BeeSec retains personal information only for as long as necessary to fulfil the purposes for which it was collected or to meet legal, regulatory or contractual obligations.

Customer engagement information is normally retained for five years following completion of an engagement unless otherwise agreed or required by law.

Information exceeding the applicable retention period is securely deleted or anonymised.


11. Your Rights


Subject to applicable law, you may have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Request deletion
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent where processing relies upon consent


Requests should be submitted to:

[email protected]


12. Complaints


If you are unhappy with how BeeSec handles your personal information, please contact us in the first instance.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):

https://ico.org.uk/


13. Third-Party Websites


Our website may contain links to third-party websites.

BeeSec is not responsible for the privacy practices of external websites and recommends reviewing their privacy notices.


14. Changes to this Privacy Notice


BeeSec may update this Privacy Notice periodically to reflect changes in legislation, our services or our processing activities.

The latest version will always be published on our website.


15. Contact


If you have any questions regarding this Privacy Notice or wish to exercise your data protection rights, please contact:

BeeSec Limited

Email: [email protected]

Website: https://www.beesec.co.uk