Privacy Policy

This Privacy Policy governs the manner in which 4ARMED Limited collects, uses, maintains and discloses personally identifiable information collected from data subjects in the course of its business.

Who are we?

4ARMED provides professional services to help businesses build, deploy and manage more secure, resilient and compliant applications in cloud environments. Additionally, we provide training services to individuals looking to improve their security testing capabilities.

Our Data Protection Officer can be contacted directly at:

+44 203 475 2443

privacy@4armed.com

Scope

This privacy policy applies to the Site ('https://www.4armed.com/') and all products and services offered by 4ARMED Limited. 4ARMED Limited is a company registered in the United Kingdom.

Data Collection

We collect personal data from you for one or more of the following purposes:

  1. To provide you with information you have requested.
  2. To create and fulfil a contract for services that you, or the business you represent, have purchased from us.
  3. To keep you up to date about services that you have explicitly asked for updates on by subscribing to a mailing list.
  4. To ensure the security of our websites and infrastructure.

We may also collect non-personal data, referred to as "technical information" about data subjects whenever they interact with our Site. Non-personal identification information may include the browser name, the type of computer and technical information about Users means of connection to our Site, such as the operating system and the Internet service providers utilised and other similar information. This information is used to improve the way our Site performs.

PurposeData collectedSourcePurposeLawful basisShared?Retention period
Provide information Name, company name, address, email address Website contact form, email, telephone To respond to your enquiries about our services. Contract performance Internal only Maximum 8 years
Contract fulfilment Name, company name, address, email address Email, telephone To create and fulfil a contract for delivery of our services to you. Contract performance Internal and appointed subcontractors if applicable Maximum 8 years
Service updates Name, email address Mailing list subscription To provide updates on services for which you have explicitly requested this. Legitimate interest Internal only Until consent withdrawn or legal limits apply
Security Technical information (see above) Application logs, third-party analytics tools To ensure the safe running of our systems. Legitimate interest Internal only Maximum 8 years

Data Processing

From time-to-time, 4ARMED Limited may for a limited time period, be exposed to personal data for which its clients are the data controller. For example, during a penetration test, an identified vulnerability may provide access to personal data. In this instance 4ARMED is temporarily a data processor and this privacy policy applies in its entirety until such access to the data is removed. Personal data accessed in this manner is never stored by 4ARMED.

Personal Data Storage

4ARMED is a company whose primary offices are in the UK.

  • Our Site is hosted in Amazon Web Services in their EU Ireland and London regions. Some connections may be routed through other geographic regions due to the use of CloudFront for content distribution.
  • We utilise a number of public cloud service providers in the delivery of our services. These are all located within either the US, the EU or Switzerland. Where non-EU, all participate in the EU - US Privacy Shield Framework.

Cookies

We use cookies on our Site to improve its performance. These are purely optional and not required for it to function. Specifically we utilise the following:

NameServicePurpose
_hssc HubSpot CRM Tracking and Analytics relating to our Customer Relationship Management system.
_hssrc HubSpot CRM Tracking and Analytics relating to our Customer Relationship Management system.
_hstc HubSpot CRM Tracking and Analytics relating to our Customer Relationship Management system.
hubspotuk HubSpot CRM Tracking and Analytics relating to our Customer Relationship Management system.
_hs_opt_out HubSpot CRM Indicates cookie consent.
_ga Google Analytics Tracking and Analytics. Used to distinguish users.
_gid Google Analytics Tracking and Analytics. Used to distinguish users.
wooTracker Woopra Website user analytics.
driftt_* Drift Website chat functionality.

Security

As you might imagine, we take our own data security very seriously. We believe we have effective controls in place to limit data storage and protect it where it is stored. Our information security management system is certified to ISO27001 and we are certified to Cyber Essentials PLUS. More on our security can be found at https://www.4armed.com/security/.

Your rights as a data subject

At any point while we are in possession of or processing your personal data, you, the data subject, have the following rights:

  • Right of access – you have the right to request a copy of the information that we hold about you. Such requests may be refused under exceptional circumstances. If responding to requests may incur unreasonable expense, you may have to meet this in order for us to fulfil the request.
  • Right of rectification – you have a right to correct data that we hold about you that is inaccurate or incomplete.
  • Right to be forgotten – in certain circumstances you can ask for the data we hold about you to be erased from our records.
  • Right to restriction of processing – where certain conditions apply to have a right to restrict the processing.
  • Right of portability – you have the right to have the data we hold about you transferred to another organisation.
  • Right to object – you have the right to object to certain types of processing such as direct marketing.
  • Right to object to automated processing, including profiling – you also have the right to be subject to the legal effects of automated processing or profiling.
  • Right to judicial review: in the event that 4ARMED refuses your request under rights of access, we will provide you with a reason as to why. You have the right to complain as outlined below.

Complaints

In the event that you wish to make a complaint about how your personal data is being processed by 4ARMED (or third parties as described above), or how your complaint has been handled, you have the right to lodge a complaint directly with the supervisory authority and 4ARMED’s Data Protection Officer.

The supervisory authority for the UK, where 4ARMED are based, is the Information Commissioner's Office.

Changes to this privacy policy

4ARMED Limited has the discretion to update this privacy policy at any time. When we do, we will revise the updated date at the bottom of this page. We encourage data subjects to frequently check this page for any changes to stay informed about how we are helping to protect the personal information we collect.

Consent

By consenting to this privacy policy you are giving us permission to process your personal data specifically for the purposes identified.

This document was last updated on May 24, 2018.