SecurityDraft — Privacy Policy
1. Who we are
"SecurityDraft" is a trading name of Zebtech Ltd, a company registered in England and Wales, company number 04948022, registered office 2 Longfield Cottages, Danworth Lane, Hurstpierpoint, BN6 9LW ("we", "us", "our"). For the personal data described in this policy, Zebtech Ltd is the data controller. We are registered with the UK Information Commissioner's Office (ICO).
This policy explains, in plain English, what personal data we collect when you use the SecurityDraft website at securitydraft.com or buy a SecurityDraft service, why we hold it, and the rights you have over it. If anything here is unclear, email us — see section 12.
2. The short version
SecurityDraft's website is a simple, static site. We do not run advertising, tracking, profiling, or third-party analytics on it, and we do not sell or share your personal data for anyone else's marketing. We collect personal data in only two ordinary ways: when you email us, and when you buy a service (payment is handled by Stripe). Beyond that, our web server keeps basic technical logs, as almost every website does.
3. The personal data we collect
| What | When / how |
|---|---|
| Your enquiry and its contents — your name, email address, and anything you choose to write to us | When you email enquiries@securitydraft.com or otherwise contact us |
| Order and contact details — name, business name, billing details, email address, order reference | When you buy a service and when we deliver it and support it |
| Content you send us to do the work — the documents and materials you supply so we can prepare your deliverable | When you engage us for a paid service. Please do not send personal data about your own customers or end-users — redact it first; it is not needed (see your service's Terms of Business) |
| Payment data — card/payment details, and the fact and amount of your payment | At checkout. Your card details are entered into and handled by Stripe, not by us — see section 5. We receive confirmation of payment and limited billing details, never your full card number |
| Server logs — IP address, browser/device type, pages requested, date and time | Automatically, when your browser requests pages from our site, kept by our hosting provider for security and to keep the site running |
4. Cookies
The SecurityDraft website is a static site and does not set analytics, advertising, or tracking cookies, and does not use third-party trackers. If a strictly necessary cookie is ever needed for the site to function, or if the checkout provider (Stripe) sets a cookie as part of taking your payment, that is limited to making the service work and is covered by the "strictly necessary" exemption under the Privacy and Electronic Communications Regulations (PECR). We will update this policy before introducing any non-essential or analytics cookies, and would ask for your consent first where the law requires it.
5. Who processes data on our behalf (sub-processors)
We use a small number of trusted providers to run the service. They process personal data only on our instructions, under contract, and only for the purposes below:
| Provider | What they do for us |
|---|---|
| Stripe (Stripe Payments Europe, Ltd / Stripe, Inc.) | Takes and processes your payment and acts as our payments provider / merchant of record. Stripe collects and handles your card and billing data directly under its own privacy policy. We never see or store your full card number. |
| Migadu (email hosting) | Hosts the enquiries@securitydraft.com mailbox through which we send and receive email with you. |
| Cloudflare Pages (Cloudflare, Inc.) | Serves the securitydraft.com website and keeps the technical server logs described in section 3. |
We do not sell your personal data, and we do not share it with anyone else except where you ask us to, or where the law requires it (section 6).
6. Why we hold your data, and our lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| To answer your enquiry and talk to you about our services | Legitimate interests — responding to someone who has contacted us; and, where you are asking about buying, steps at your request before a contract |
| To provide the service you paid for — doing the work, delivering it, supporting it, and handling revisions | Performance of a contract with you (or your business) |
| To take payment and prevent fraud | Performance of a contract; and legitimate interests in preventing fraud (this involves Stripe as described in section 5) |
| To keep our website secure and working (server logs) | Legitimate interests in the security and reliability of our site |
| To meet our legal and tax/accounting duties (e.g. VAT and company records) | Legal obligation |
Where we rely on legitimate interests, we have checked that our interest does not override your rights; you can object at any time (section 9).
7. International transfers
Some of our providers are based outside the UK or process data internationally — for example Stripe operates globally. Where personal data leaves the UK, we rely on the safeguards UK data protection law requires: transfers to countries the UK has judged "adequate", or, where it has not, contractual protections such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so that your data keeps an equivalent level of protection.
8. How long we keep it
- Enquiry emails: kept while we are in contact and for a reasonable period afterwards, then deleted, unless they turn into an order.
- Materials you send us for a paid service: kept only as long as your service's Terms of Business say (for most services this is delivery plus a short support window, then deletion; retention for an optional annual re-issue is opt-in). If you ask us to delete sooner, we will.
- Order, billing and payment records: kept for as long as the law requires us to keep business and tax records (generally six years for UK VAT/accounting purposes).
- Server logs: kept for a short period by our hosting provider for security, then rotated out.
9. Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you (a "subject access request");
- have inaccurate data corrected;
- have your data deleted where there is no good reason for us to keep it;
- restrict or object to how we use it, including objecting to any use we base on legitimate interests;
- ask us to port certain data to you or another provider;
- where we ever rely on your consent, withdraw it at any time.
To exercise any of these, email us (section 12). We will respond within one month. There is normally no charge.
10. Payment data — a note on Stripe
When you pay, you enter your card details directly into Stripe's secure checkout. Stripe processes your payment and, as our payments provider, holds your card data under its own privacy policy and PCI-DSS obligations. We do not receive or store your full card number. Stripe is a sub-processor for taking your payment and, separately, acts as an independent controller for its own fraud-prevention and regulatory purposes.
11. Complaints
If you are unhappy with how we have handled your personal data, please tell us first (section 12) so we can put it right. You also have the right to complain to the UK regulator:
Information Commissioner's Office (ICO) — Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · Helpline 0303 123 1113 · ico.org.uk
12. How to contact us
For anything about this policy or your personal data, email enquiries@securitydraft.com.
13. Changes to this policy
We may update this policy from time to time. The version published here is the current one; if we make a significant change we will note it here. This policy takes effect on the date shown at the top and in the footer once approved.