Data Protection and Information Security Policy

Our commitment

Digitator Limited is committed to protecting the personal and confidential information entrusted to us by our clients, website users, suppliers and other business contacts.

We handle personal data in accordance with applicable UK data protection law, including the UK General Data Protection Regulation and the Data Protection Act 2018, as amended.

Our approach is based on accountability, data minimisation, appropriate security and respect for the rights of individuals. We collect, access and retain only the information reasonably required for a defined business or contractual purpose.

Responsibility for data protection

Digitator is a director-led business. The Managing Director has overall responsibility for data protection, information security and responding to data protection enquiries.

Client work is undertaken personally by the Managing Director. Access to client systems and information is therefore limited to a single authorised senior consultant unless alternative arrangements have been expressly agreed with the client.

Depending on the circumstances, Digitator may act as:

  • A data controller when deciding why and how personal information is used, such as when managing business contacts and enquiries.
  • A data processor when handling personal information on the documented instructions of a client.

When acting as a processor, we use personal data only for the agreed purposes, follow the client’s documented instructions and comply with the applicable data-processing agreement.

How we protect information

Confidentiality and access control

We restrict access to personal and confidential information according to business need. Our security measures include:

  • Individual, non-shared user accounts.
  • Strong, unique passwords managed securely.
  • Multi-factor authentication wherever it is supported.
  • Device-level authentication and automatic screen locking.
  • Encryption in transit using current secure protocols.
  • Business-grade email and access-controlled cloud storage.
  • Firewall, anti-malware and endpoint-security protection.
  • Timely installation of operating-system, browser, application and security updates.
  • Secure configuration of devices and online services.
  • Secure deletion or confidential disposal of information and equipment when no longer required.

We do not use public or unsecured Wi-Fi to access confidential client information unless access is protected by an appropriate encrypted connection.

We do not disclose client information to another person or organisation unless this has been authorised by the client, is necessary to provide an agreed service, or is required by law.

Integrity, availability and resilience

We take proportionate measures to protect information against accidental loss, unauthorised alteration, destruction or unavailability. These include:

  • Minimising the amount of personal information collected, downloaded and retained.
  • Working within client-approved systems wherever practicable.
  • Avoiding unnecessary local copies of client information.
  • Maintaining version control and change records for material project documents.
  • Using secure, access-controlled systems with appropriate backup arrangements.
  • Testing backup and recovery arrangements periodically.
  • Maintaining suitable replacement equipment and business-continuity arrangements.
  • Documenting project status, decisions, actions and implementation activity.
  • Checking the accuracy and integrity of data used in our work.

Where inaccurate personal information is identified, we will correct it or notify the relevant client promptly.

Data protection by design

We consider privacy and information security when planning projects, selecting systems and deciding how information should be collected, used, shared, retained or deleted.

Our approach includes:

  • Identifying the purpose and lawful basis for processing.
  • Collecting only the information needed for that purpose.
  • Limiting access to authorised individuals.
  • Considering whether information can be anonymised or pseudonymised.
  • Assessing potential risks to individuals.
  • Applying appropriate retention and deletion periods.
  • Undertaking a data protection impact assessment where processing is likely to present a high risk to individuals.

Your data protection rights

Depending on the circumstances, individuals may have rights relating to their personal information, including:

  • The right to receive clear information about how their data is used.
  • The right to access their personal data.
  • The right to have inaccurate or incomplete information corrected.
  • The right to request deletion of personal data where applicable.
  • The right to request that processing be restricted.
  • The right to data portability where applicable.
  • The right to object to certain processing.
  • Rights relating to automated decision-making and profiling where applicable.

When Digitator acts as the controller, we will verify, record and respond to rights requests within the timescales required by law.

When we process information on behalf of a client, requests relating to that information should normally be directed to the client. If we receive a request directly, we will record it, refer it to the relevant client without undue delay and assist the client with its response.

Further information about the personal data we collect and use is available in our Privacy Policy.

Consent

We identify the appropriate lawful basis before processing personal information. We do not rely on consent where another lawful basis is more appropriate.

Where consent is required, we ensure that it is:

  • Freely given, specific, informed and unambiguous.
  • Obtained through a clear affirmative action.
  • Presented separately from unrelated terms where appropriate.
  • Supported by clear information about the proposed processing.
  • Capable of being withdrawn as easily as it was given.

We retain an appropriate audit trail showing who provided consent, when and how it was obtained, what information was presented at the time, and whether consent was subsequently changed or withdrawn.

Service providers and subprocessors

We use selected technology and service providers to support our business and deliver client services. Before using a provider to process personal information, we consider:

  • The nature of the information and processing involved.
  • The provider’s privacy and security arrangements.
  • Where information will be stored or accessed.
  • The provider’s contractual data protection commitments.
  • Data retention and deletion arrangements.
  • Any international transfers of personal information.

Appropriate data-processing terms are put in place where required. Where Digitator acts as a processor, we will comply with the relevant client’s requirements concerning the appointment of subprocessors.

International transfers

Some technology providers may store or access information outside the United Kingdom. We seek to avoid restricted international transfers where reasonably practicable.

Where a restricted transfer is necessary, it will take place only where a valid legal mechanism is available. Depending on the destination and circumstances, this may include:

  • UK adequacy regulations.
  • The UK International Data Transfer Agreement.
  • The UK Addendum to the EU Standard Contractual Clauses.
  • Another legally recognised safeguard or applicable exception.

Where appropriate safeguards are required, we will ensure that an appropriate transfer risk assessment or data protection test is completed and that any necessary supplementary safeguards are applied.

Records of processing

We maintain proportionate records of our personal-data processing activities. These records may include:

  • The categories of personal data and individuals concerned.
  • The purpose and lawful basis for processing.
  • Whether Digitator is acting as a controller or processor.
  • The systems, recipients and service providers involved.
  • Relevant retention and deletion periods.
  • International transfers and the safeguards used.
  • The principal technical and organisational security measures applied.

These records are reviewed and updated when our activities, systems, suppliers or legal obligations change.

Data retention and deletion

We retain personal information only for as long as it is reasonably required for the relevant purpose, to meet contractual obligations or to comply with legal requirements.

When information is no longer required, it is securely deleted, anonymised or returned to the relevant client. At the end of a client engagement, we follow the applicable contractual requirements and the client’s lawful instructions concerning the return or deletion of personal data.

Information security incidents

We maintain a process for identifying, containing, investigating and documenting suspected information security incidents and personal data breaches.

Where an incident affects personal information processed on behalf of a client, we will notify the client without undue delay and provide reasonable assistance with:

  • Investigating and containing the incident.
  • Identifying the information and individuals affected.
  • Assessing potential risks to individuals.
  • Meeting any regulatory or contractual reporting obligations.
  • Communicating with affected individuals where required.
  • Implementing corrective and preventative measures.

Incidents and near misses are recorded, reviewed and used to improve our security arrangements.

Testing and continuous improvement

We review our data protection and information security arrangements regularly and following any material change, identified weakness or security incident.

These reviews include, where relevant:

  • Reviewing access permissions and system configurations.
  • Checking that security updates and endpoint protections are current.
  • Testing backup and recovery arrangements.
  • Reviewing service-provider and international-transfer arrangements.
  • Reviewing processing records and retention requirements.
  • Checking consent records where consent is used.
  • Reviewing incidents, corrective actions and lessons learned.
  • Completing an annual review of relevant policies and procedures.

Any weakness identified is recorded, prioritised and addressed. Follow-up checks are undertaken where appropriate to confirm that the corrective action has been effective.

Contacting us

If you have a question about this page, how Digitator handles personal information or wish to exercise a data protection right, please contact us.

You also have the right to raise a concern with the UK Information Commissioner’s Office. Further information is available on the ICO website.

Last reviewed: 4 September 2026
Next review date: 3 September 2027