Legal
Data Security
Last updated: 12 July 2026
1. Our approach
Security is built into how we work, not added on afterwards. This page describes the measures and the architecture we use to protect client data and the systems we supply and support. We describe what our practices support and how we configure things; we do not claim ISO, SOC, or other formal certifications for our company, and we do not claim to have completed external security audits we do not hold.
2. Least-data principle
We collect and hold only the data we need to respond to you and to supply and support your products and services. We do not gather personal data we have no clear use for, and we do not ask for sensitive personal data through this website. Keeping the amount of data we hold small is the simplest way to reduce risk.
3. Secure email and records
Inquiries, correspondence, quotations, and project records are kept in our business systems and accessed only by the people who need them to do their work. We access these records for the purpose they were provided for — responding to you, preparing quotations, and fulfilling and supporting orders — and not for any other purpose.
4. Vetted service providers
We rely on a small number of established service providers for functions such as email and website hosting. We choose providers with a solid security track record, and they process data only as needed to provide their service to us. We share client data with manufacturers and authorised distributors only where it is necessary to fulfil and support an order.
5. Server and hosting infrastructure
The server and hosting infrastructure we use for our own systems, and which underpins our Servers line, is EU-based, GDPR-compliant, and runs on 100% green electricity. Locating this infrastructure in the EU means it operates under a mature data-protection framework, and the green-powered data centres reduce the environmental footprint of the systems we run.
6. Access control on our systems
On our own systems we apply least-privilege access: people get only the access their role requires. We use individual accounts rather than shared logins, keep administrative access limited to those who need it, and remove access when it is no longer needed.
7. Incident handling and responsible disclosure
If we become aware of a security incident affecting data we hold, we act to contain it, assess the impact, and take appropriate steps in line with our obligations. If you believe you have found a security vulnerability or a data-handling concern relating to our website or a system we supply, please report it to [email protected]. Give us enough detail to reproduce and assess the issue, and allow us reasonable time to investigate and respond before disclosing it publicly. We appreciate reports made in good faith.
8. Your shared responsibility
Security is a shared responsibility. On the client side, we ask that you maintain good password hygiene, keep user accounts and permissions up to date, remove access when staff leave, keep the products and software supplied updated as advised, and follow the access practices we set up together. Strong day-to-day habits by your team are an essential part of keeping systems secure.
9. Related
For how we handle personal data collected through this website, see our Privacy Policy.
10. Contact
Questions about data security? Contact us at [email protected].