Security
How we protect the service and the data in it, and what to do if you find a problem.
This is version 1.0, archived on 26 July 2026. It is kept for reference and is not the current document — read the current version.
- Version
- 1.0
- Effective
- 26 July 2026
- Applies to
- Drentova Group Ltd
- History
- 1 version
How we think about it
We are a small team, and we say what is actually in place rather than what sounds reassuring. Where a control is not yet in place, our Trust Centre says so.
Technical and organisational measures
We take the measures below to protect personal data, as required by Article 32 of the UK GDPR. They are reviewed as the service changes, and we publish the current position in our Trust Centre rather than describing a state we hope to reach.
- Data in transit is encrypted using TLS. Data at rest is encrypted by our hosting and database providers.
- Access to production systems is restricted to the people who need it, protected by multi-factor authentication, and removed when it is no longer needed.
- Administrative access to customer data is limited to what is necessary to operate and support the service.
- Backups are taken by our database provider and restoration is tested.
- Changes to production go through review and automated checks before release.
- Third parties are assessed before they process personal data on our behalf, and are engaged under written terms that meet Article 28.
No service can promise perfect security. If we become aware of a personal data breach we will assess it without undue delay, notify the PLACEHOLDER — ICO registration-registered supervisory authority within 72 hours where the breach is notifiable, and tell affected people directly where the breach is likely to result in a high risk to them.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] before disclosing it anywhere else. We acknowledge reports within 3 working days, keep you updated, and will not pursue legal action against anyone who reports in good faith under our Responsible Disclosure Policy.
If a breach happens
We will investigate without undue delay, notify the Information Commissioner’s Office within 72 hours where the breach is notifiable, notify affected customers where there is a high risk to them, and publish a summary of what happened and what we changed once the immediate risk has passed.
How to contact us
- Security reports
- [email protected]
Change log
- v1.0 · 26 July 2026First published version.