Table of Contents
- Introduction
- Who are we?
- Personal data we process
- How we collect personal data
- Lawful basis for processing
- How we use personal data
- Data sharing
- International transfer
- Data retention
- Your rights
- Security of personal data
- Data breaches
- Cookies and similar technologies
- Third-party links
- Updates to this policy
- Contact us and complaints
Document Control
| Version No. | Date Updated | Summary of Updates | Updated by: |
| V1 | 16/05/2018 | Creation of policy. | Isabelle
Bearn/Matt Norris |
| V.2 | 25/09/2019 | Branding update. | Isabelle Bearn |
| V.2.1 | 16/02/2023 | Document Template update. | Matt Norris |
| V.3 | 22/04/2026 | Updated for compliance with UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data
(Use and Access) Act 2025 |
Natalie du toit |
Copyright (c) 2026 JUMPSEC Ltd | All Rights Reserved
The content of this document is part of the JUMPSEC Business Management System and is public. The document or any part of it should not be duplicated or the contents transmitted to any third party without the express approval of the document owner. For the latest and current version of this document contact JUMPSEC LTD.
1. Introduction
JUMPSEC Limited (“Jumpsec”, “we”, “us” or “our”) is committed to protecting your privacy and personal data.
We process personal data fairly, lawfully and transparently, and only for specified and legitimate purposes.
This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website, engage with us, attend events, or interact with us in the course of our business activities.
This policy is provided in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
If you have any queries regarding this policy and / or your data privacy, please contact us using any of the following:
Email: [email protected] / Phone: 03339398080 / Address: JUMPSEC Limited, 3E&F Westpoint, 33-34 Warple Way, Acton, W3 0RG
https://www.jumpsec.com/privacy–policy/
2. Who are we?
JUMPSEC Limited is a private limited company established in 2012 and registered in England and Wales (Company No. 08327063).
Registered office:
2 Printer’s Yard, 90a The Broadway, London, SW19 1RD
JUMPSEC is the data controller for personal data processed in connection with this website and our business activities.
3. Personal data we process
“Personal data” means any information relating to an identified or identifiable individual.
We may process the following categories of personal data:
- Contact details (such as name, job title, company, email address, telephone number)
- Business communications and correspondence
- Event registrations and attendance details
- Client, supplier and partner information
- Technical and usage data associated with our website (see Cookies Policy)
- Recruitment or enquiry information provided voluntarily
We do not intentionally collect special category data via our website.
4. How we collect personal data
We collect personal data when you:
- Visit or interact with our website
- Contact us via email, forms or telephone
- Request information about our services
- Attend events, webinars or meetings
- Engage with us as a client, supplier, contractor or partner
- Apply for a role or submit an enquiry
5. Lawful basis for processing
We process personal data only where a lawful basis under Article 6 UK GDPR applies. Depending on the context, this may include:
- Consent – where you have explicitly agreed (e.g. marketing communications)
- Contract – where processing is necessary to perform or prepare a contract
- Legal obligation – where required to comply with applicable law
- Legitimate interests – where processing is necessary for our legitimate business interests, and those interests are not overridden by your rights (e.g. responding to enquiries, managing business relationships, improving services)
Where we rely on legitimate interests, we assess and balance those interests against your rights and expectations.
6. How we use personal data
We use personal data for the following purposes:
- Responding to enquiries and requests about our products and services
- Providing and managing our services
- Managing client, supplier and partner relationships
- Improving our website, services and communications
- Sending relevant business communications where permitted
- Maintaining internal records and accounts
- Meeting legal, regulatory and security obligations
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
7. Data sharing
We may share personal data where necessary with:
- Trusted service providers and suppliers acting as processors
- Professional advisers (such as legal or accounting advisers)
- Regulators, law enforcement or public authorities, where required by law
We do not sell personal data and do not share it for unrelated third-party marketing purposes.
All processors are required to handle personal data securely and in accordance with applicable data protection law.
8. International transfer
Some of our service providers may process personal data outside the UK.
Where personal data is transferred internationally, we ensure appropriate safeguards are in place, such as:
- UK adequacy regulations
- Standard Contractual Clauses or other approved safeguards
9. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including:
- Enquiries: typically up to 24 months
- Client and supplier records: for the duration of the relationship and in line with legal or contractual requirements
- Marketing preferences: until withdrawn
- Legal, financial or compliance records: in accordance with statutory retention periods
Retention periods may vary depending on the nature of the data and our legal obligations.
10. Your rights
Under the UK GDPR, you have the right to:
- Be informed about how your personal data is used
- Access your personal data
- Request correction of inaccurate or incomplete data
- Request erasure of personal data (where applicable)
- Request restriction of processing
- Data portability (where applicable)
- Object to processing based on legitimate interests or direct marketing
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with the Information Commissioner’s Office (ICO)
Requests can be made by contacting us at [email protected]. We may need to verify your identity before responding.
11. Security of personal data
We take appropriate technical and organisational measures to protect personal data, including access controls, security monitoring and staff training.
Personal data is treated as confidential and protected against unauthorised access, alteration or disclosure.
12. Data breaches
In the event of a personal data breach, we have procedures in place to assess and respond appropriately.
Where required, we will notify the ICO within 72 hours of becoming aware of the breach and, where there is a high risk to individuals’ rights and freedoms, we will inform affected individuals without undue delay.
13. Cookies and similar technologies
Our website uses cookies and similar technologies. Full details, including your choices and consent options, are provided in our Cookie Policy, which forms part of this Privacy Policy.
14. Third-party links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. Please review their privacy policies separately.
15. Updates to this policy
We may update this Privacy Policy from time to time. The latest version will always be available on our website.
16. Contact us and complaints
If you have any questions, concerns or requests relating to this Privacy Policy or how we handle personal data, please contact:
Email: [email protected]
Company: JUMPSEC Limited
If you are not satisfied with our response, you have the right to raise a complaint with the Information Commissioner’s Office (ICO).
