Request Demo →

Legal

Data Protection Notice

How SteelCortex approaches client data, service data and information processed during security engagements.

Data protection in SteelCortex services

Cybersecurity work may involve information about systems, users, incidents, logs, identities and business operations. SteelCortex aims to minimise the data collected, restrict access to authorised personnel and process information only for the agreed purpose.

Controller and processor roles

The legal role of SteelCortex depends on the activity. For its own business administration, website and client relationship records, SteelCortex may act as a controller. Where SteelCortex processes personal data solely on a client’s documented instructions as part of a service, the contractual arrangements may define SteelCortex as a processor.

Data minimisation

  • Collect only information reasonably required for the agreed service.
  • Avoid unnecessary copying of sensitive data.
  • Use least-privilege access wherever practical.
  • Separate client information and restrict access by role.
  • Remove or anonymise information when it is no longer needed where appropriate.

Security information and logs

Security assessments and investigations may require log data, account identifiers, IP addresses, system information or evidence of user activity. The scope, access method and expected retention should be agreed before collection wherever practical.

Subprocessors and service providers

Hosting, communications, ticketing, analytics or other infrastructure providers may process limited information on behalf of SteelCortex. Material subprocessors used for contracted processing should be governed by suitable contractual and security arrangements.

Incident handling

If SteelCortex becomes aware of a security incident affecting client data under its control, it will follow the applicable contractual and legal notification process and cooperate with the client as required.

Retention and deletion

Retention depends on the nature of the engagement, evidential requirements, contractual commitments and legal obligations. Client-specific retention or deletion instructions should be documented where required.

Data subject rights

Requests relating to personal data will be handled according to the applicable legal role and relevant data-protection law. Where SteelCortex acts only as a processor, requests may need to be referred to the client organisation acting as controller.

Contact

Questions about data protection can be sent to hello@steelcortex.com.