Legal
Privacy Policy
Last updated: 24 September 2026
BoundaryProof Security
Web: https://boundaryproof.co.uk/
Email: enquiries@boundaryproof.co.uk
United Kingdom · Law of England and Wales
1. Who we are
BoundaryProof Security is a UK founder-led practice offering web, external infrastructure, OSINT and firewall assessments. We do not sell Cyber Essentials / CE+ certification, managed SOC, or unrelated product bundles via this site.
For site and enquiry data we are the controller under UK GDPR. For assessment data, controller/processor roles follow the engagement terms.
2. Data we collect
You give us: name, email, company, service interest, timeline, and message (intro-call form, email, or Calendly notes).
Automatic: hosting and security logs via Netlify (IP, user agent, pages, timing) as needed to run and protect the site.
We do not take card payments on the public form. We do not run first-party Google Analytics on the public site today. If analytics or marketing pixels are added later, this policy will be updated before they go live.
3. Why we use it
To reply to enquiries; arrange free intro calls; deliver paid work; operate and secure the site; keep authorised-scope and engagement records; and meet legal duties. We do not sell personal data. We do not run a marketing list from the form today.
4. Lawful bases (UK GDPR)
- Enquiries / intro calls: legitimate interests and/or steps prior to contract
- Paid engagements: contract
- Hosting / security logs: legitimate interests (site integrity)
- Legal / tax records: legal obligation
- Any future marketing email: consent only
5. Retention
- Form leads with no engagement: 12 months after last meaningful contact
- Proposals / engagements / report metadata: up to 6 years after end (limitation / tax), or shorter where law allows
- Assessment artefacts: per statement of work / engagement letter; default delete or return after the retention window on request
- Calendly booking data: per Calendly settings and our need to run intros
- Hosting logs: per Netlify
6. Sharing
We share only as needed with Netlify (hosting and forms), Calendly (booking), the email provider for enquiries@boundaryproof.co.uk, professional advisers if required, and authorities if legally required. Some processing may occur outside the UK under provider contractual safeguards or adequacy mechanisms. We do not sell or rent personal data.
7. Cookies
No first-party analytics cookies in the current public setup. Calendly and Netlify may set essential or operational cookies when those features are used. Cookie details stay on this privacy page. We do not show a separate cookie banner unless non-essential trackers are introduced later.
8. Security and children
We use reasonable technical and organisational measures. Do not send passwords, secrets, or unnecessary personal data via the public form. Services are for businesses; we do not knowingly collect children’s data.
9. Your rights
Under UK GDPR you may have rights of access, rectification, erasure, restriction, objection, and portability (where applicable), and to withdraw consent where used. Email enquiries@boundaryproof.co.uk. You can complain to the ICO: https://ico.org.uk / 0303 123 1113.
10. Assessment work
Personal data encountered during authorised assessments is processed only to deliver the engagement, under the Terms / statement of work / authorisation letter. A free intro is not permission to test and not a free report.