// LEGAL
Privacy Policy
Last updated: 15 September 2026.
Who we are
Acta Security ("we", "us") is the data controller for personal data processed through this website and our client services. Contact: hello@actasecurity.eu or via our contact form.
What we collect
- Contact form: your email, any name, organisation or subject you provide, your message, and technical data needed to prevent spam and abuse (including your IP address).
- Booking: if you book an assessment or discovery call, the appointment is handled by meetergo; the details you enter there (name, email, chosen time) are processed by them on our behalf.
- Client portal: your email, name, organisation, phone number, country, timezone and VAT number; engagement details and intake answers you submit; payment reference data (we receive only a payment reference and your email from our payment provider: card data is processed by them directly); files you upload; and reports we deliver to you.
- SMS notifications: if you provide a phone number in your portal profile, we may send transactional messages (for example engagement updates). Your number is passed to our SMS provider only for that purpose.
- Live support chat: if you use the live chat widget, the conversation (including your name, email and message content) is processed on infrastructure we operate in the EU.
- File uploads: files you attach to engagements or support tickets are scanned for malware on our EU infrastructure. Do not upload documents containing highly sensitive personal data unless necessary for your engagement.
- Accounting: when your onboarding is approved, your name, email, company name and purchase details are passed to our accounting provider for your client record and invoice.
- Incident response: only what you choose to send us via our secure contact channels.
- Traffic logs: IP address, browser type, request path and response status, used to operate and protect the site and portal, and retained for up to 90 days.
We do not use advertising, profiling or third-party analytics/tracking.
Why we process it (legal bases)
- Consent: when you contact us, request a booking, or opt to provide a phone number for SMS alerts.
- Contract: to scope, deliver, and invoice engagements you order through the portal.
- Legitimate interests: to secure the website and portal against abuse, prevent spam, and respond to enquiries.
- Legal obligation: where we are required to retain or disclose data by law.
Who processes data for us
We work with EU/EEA-resident providers wherever possible:
- OVHcloud (EU): hosting and related services.
- Gcore Luxembourg S.A. (Luxembourg, EU): content delivery and protection of public traffic (IP address and request metadata).
- Zoho Corporation B.V. (Netherlands, EU): email.
- Mollie B.V. (Netherlands, EU): payment processing. Mollie is an independent controller for card data; we receive only the payment reference and your email.
- Bird B.V. (Netherlands, EU): transactional SMS, only when a message is sent to you.
- meetergo GmbH (Germany, EU): appointment booking.
- Sage Group plc (United Kingdom, adequacy decision): accounting and invoicing.
Bot protection on our forms runs on our own EU servers; no data is sent to a third party for that step. Live chat also runs on our EU infrastructure. We never sell personal data. Where a provider may process data outside the EEA, it is done under appropriate safeguards (Standard Contractual Clauses or an adequacy decision).
How long we keep it
- Contact form enquiries: retained only as long as needed to respond, then deleted.
- Security and traffic logs: automatically purged after 90 days.
- Engagement records and reports: retained for as long as necessary for the purposes described above and any applicable legal or contractual obligations, then securely deleted.
- Portal accounts: kept until you request closure. On closure, personal data is deleted within 30 days.
Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent at any time. To exercise these rights, contact privacy@actasecurity.eu. You also have the right to lodge a complaint with your local EU supervisory authority.
How we protect it
Our systems are operated in the EU. We use encryption in transit and at rest, access controls, monitoring, and regular backups. See our Cookie Policy for cookie details.
Changes & contact
We may update this policy; the "last updated" date will change. Questions: privacy@actasecurity.eu or the contact form.