SecurityDraft — Privacy Policy

Version 1.0 · In force from 31 July 2026 (approved by CEO, decision D-030; external DPO review waived — CEO risk acceptance) · plain English on purpose

1. Who we are

"SecurityDraft" is a trading name of Zebtech Ltd, a company registered in England and Wales, company number 04948022, registered office 2 Longfield Cottages, Danworth Lane, Hurstpierpoint, BN6 9LW ("we", "us", "our"). For the personal data described in this policy, Zebtech Ltd is the data controller. We are registered with the UK Information Commissioner's Office (ICO).

This policy explains, in plain English, what personal data we collect when you use the SecurityDraft website at securitydraft.com or buy a SecurityDraft service, why we hold it, and the rights you have over it. If anything here is unclear, email us — see section 12.

2. The short version

SecurityDraft's website is a simple, static site. We do not run advertising, tracking, profiling, or third-party analytics on it, and we do not sell or share your personal data for anyone else's marketing. We collect personal data in only two ordinary ways: when you email us, and when you buy a service (payment is handled by Stripe). Beyond that, our web server keeps basic technical logs, as almost every website does.

3. The personal data we collect

WhatWhen / how
Your enquiry and its contents — your name, email address, and anything you choose to write to us When you email enquiries@securitydraft.com or otherwise contact us
Order and contact details — name, business name, billing details, email address, order reference When you buy a service and when we deliver it and support it
Content you send us to do the work — the documents and materials you supply so we can prepare your deliverable When you engage us for a paid service. Please do not send personal data about your own customers or end-users — redact it first; it is not needed (see your service's Terms of Business)
Payment data — card/payment details, and the fact and amount of your payment At checkout. Your card details are entered into and handled by Stripe, not by us — see section 5. We receive confirmation of payment and limited billing details, never your full card number
Server logs — IP address, browser/device type, pages requested, date and time Automatically, when your browser requests pages from our site, kept by our hosting provider for security and to keep the site running

4. Cookies

The SecurityDraft website is a static site and does not set analytics, advertising, or tracking cookies, and does not use third-party trackers. If a strictly necessary cookie is ever needed for the site to function, or if the checkout provider (Stripe) sets a cookie as part of taking your payment, that is limited to making the service work and is covered by the "strictly necessary" exemption under the Privacy and Electronic Communications Regulations (PECR). We will update this policy before introducing any non-essential or analytics cookies, and would ask for your consent first where the law requires it.

5. Who processes data on our behalf (sub-processors)

We use a small number of trusted providers to run the service. They process personal data only on our instructions, under contract, and only for the purposes below:

ProviderWhat they do for us
Stripe (Stripe Payments Europe, Ltd / Stripe, Inc.) Takes and processes your payment and acts as our payments provider / merchant of record. Stripe collects and handles your card and billing data directly under its own privacy policy. We never see or store your full card number.
Migadu (email hosting) Hosts the enquiries@securitydraft.com mailbox through which we send and receive email with you.
Cloudflare Pages (Cloudflare, Inc.) Serves the securitydraft.com website and keeps the technical server logs described in section 3.

We do not sell your personal data, and we do not share it with anyone else except where you ask us to, or where the law requires it (section 6).

6. Why we hold your data, and our lawful bases

PurposeLawful basis (UK GDPR)
To answer your enquiry and talk to you about our services Legitimate interests — responding to someone who has contacted us; and, where you are asking about buying, steps at your request before a contract
To provide the service you paid for — doing the work, delivering it, supporting it, and handling revisions Performance of a contract with you (or your business)
To take payment and prevent fraud Performance of a contract; and legitimate interests in preventing fraud (this involves Stripe as described in section 5)
To keep our website secure and working (server logs) Legitimate interests in the security and reliability of our site
To meet our legal and tax/accounting duties (e.g. VAT and company records) Legal obligation

Where we rely on legitimate interests, we have checked that our interest does not override your rights; you can object at any time (section 9).

7. International transfers

Some of our providers are based outside the UK or process data internationally — for example Stripe operates globally. Where personal data leaves the UK, we rely on the safeguards UK data protection law requires: transfers to countries the UK has judged "adequate", or, where it has not, contractual protections such as the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, so that your data keeps an equivalent level of protection.

8. How long we keep it

9. Your rights

Under UK data protection law you have the right to:

To exercise any of these, email us (section 12). We will respond within one month. There is normally no charge.

10. Payment data — a note on Stripe

When you pay, you enter your card details directly into Stripe's secure checkout. Stripe processes your payment and, as our payments provider, holds your card data under its own privacy policy and PCI-DSS obligations. We do not receive or store your full card number. Stripe is a sub-processor for taking your payment and, separately, acts as an independent controller for its own fraud-prevention and regulatory purposes.

11. Complaints

If you are unhappy with how we have handled your personal data, please tell us first (section 12) so we can put it right. You also have the right to complain to the UK regulator:

Information Commissioner's Office (ICO) — Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF · Helpline 0303 123 1113 · ico.org.uk

12. How to contact us

For anything about this policy or your personal data, email enquiries@securitydraft.com.

13. Changes to this policy

We may update this policy from time to time. The version published here is the current one; if we make a significant change we will note it here. This policy takes effect on the date shown at the top and in the footer once approved.