Version 1.0
Effective date: 28 September 2026
1. Purpose and scope
This policy describes how VYSEBROWN LTD, a private company limited by shares incorporated in England and Wales with company number 17325096 and registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom WC2H 9JQ (the “Company”), protects the information it holds. The Company is a UK technology consultancy and provides consultancy, advisory and technology delivery services through its founders and a network of associates. This policy applies to all information the Company handles, including client information, associate information, personal data, confidential information and business records, and to founders, directors, employees (if any), associates, service providers and anyone else who accesses Company systems (meaning the Company’s IT infrastructure, cloud services, software applications, email, CRM, document management and other platforms used to conduct Company business) or client information on the Company’s behalf.
2. Definitions
In this policy:
“associate” means a self-employed consultant, Founding Associate or independent professional engaged by the Company, whether directly or through their own company, to deliver services;
“confidential information” means any non-public information belonging to the Company or a client, including commercial, technical, financial and project information;
“personal data” has the meaning given in the UK GDPR;
“security incident” means any suspected or actual event that compromises, or may compromise, the confidentiality, integrity or availability of Company systems, client information, confidential information or personal data;
“Company systems” has the meaning given in the Purpose and scope section; and
“UK GDPR” means the UK General Data Protection Regulation and the Data Protection Act 2018.
3. Approach
The Company holds most of its information electronically and works mainly in the cloud. Security depends on proportionate, practical controls that are applied consistently across the Company’s own systems and, where applicable, client environments. The Company structures its controls around recognised good-practice themes, including the government’s Cyber Essentials scheme as a baseline reference, but does not claim certification unless and until certification is obtained. The founders and management are responsible for approving this policy, maintaining appropriate procedures, monitoring compliance and ensuring that associates understand the obligations that apply to their work. Non-compliance with this policy may result in termination of engagement, suspension of access or other appropriate measures, including, in the case of employees, disciplinary action.
4. Access and accounts
Access to the Company’s systems, client information and project records is granted on a need-to-know basis and limited to the founders, employees (if any), associates and service providers who need that access for an authorised business purpose. Access for associates is project-specific, including access to the relevant project folder, and associates must not be given broad access to the Company’s CRM or other central business systems unless expressly approved by management for a defined purpose. Accounts on Company systems must be protected by strong, unique passwords and multi-factor authentication. Credentials must be stored in the Company’s approved password manager and not in browsers, documents or spreadsheets. Where credentials are issued to or shared with an associate, they must be shared via the password manager and not by email or messaging. Access must not be shared and must be removed promptly, and in any event within two business days, of a project ending, a role changing, or access no longer being required.
5. Devices
Devices used to access Company systems or client information must be kept secure, up to date and protected by a password, biometric control or other secure log-in method. Supported software and operating systems must be used and updated promptly so that security fixes are applied. Anti-malware protection must be enabled on all devices used to access Company systems or client information, devices must lock when unattended, and confidential or personal data must not be stored locally unless there is a clear business need and suitable safeguards are in place.
6. Secure configuration and email
The Company uses reputable, supported software and services, including enterprise-grade productivity and email platforms, and relies on appropriate security features built into them. Founders, employees (if any) and associates must be alert to phishing, social engineering and fraudulent messages, must treat with care any request involving payment details, credentials, confidential information or personal data, and must verify unusual or high-risk requests through an appropriate independent channel before acting on them. When accessing a client’s systems or information, they must also comply with the client’s applicable security rules, acceptable use requirements and incident reporting procedures.
7. Data storage and backups
Information is stored in the Company’s cloud environment, which provides resilience and backup. UK-based storage is the Company’s standard approach. International transfers of personal data or confidential client information may take place only where appropriate UK GDPR safeguards are in place, such as an applicable adequacy arrangement, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism recognised under applicable data protection law. Client and associate records must be organised by client, project or engagement so that access can be controlled and records can be located, returned, deleted or access-disabled at project completion. The Company does not keep unnecessary copies of personal data or confidential information on local devices.
Where the Company processes personal data on behalf of a client, it will do so under appropriate written data processing terms (such as a data processing agreement or addendum) that reflect the parties’ respective roles as controller and processor and set out the required UK GDPR obligations, including in relation to security, sub-processing, international transfers and the return or deletion of personal data at the end of the engagement. The Company will assess, at the engagement scoping or contracting stage and before any processing begins, whether it is acting as a processor in respect of a given engagement and, where it is, will ensure that appropriate data processing terms are in place before processing begins.
8. Incident response
If a suspected or actual security incident, confidentiality breach or personal data breach occurs, it must be reported to the founders or management as soon as reasonably practicable and in any event within twenty four hours of discovery, or sooner where required by an applicable client contract or engagement-specific security requirement. Associates must escalate incidents immediately and must not investigate, delete evidence or communicate externally unless authorised. The Company responds in the following way:
identify, escalate and contain the incident as quickly as possible, for example by changing passwords, revoking access, isolating an affected device or notifying a client contact where client systems or information may be affected (and, where the Company is acting as a processor, notifying the relevant client controller without undue delay as required by UK GDPR and within any shorter period required by the applicable client contract);
assess what information is involved and what the likely impact is;
where the Company is acting as controller and a personal data breach is likely to result in a risk to individuals, notify the Information Commissioner’s Office without undue delay and, where required, within seventy-two hours of the Company becoming aware of it, and where the Company is acting as processor, notify the relevant client controller without undue delay after becoming aware of it and within any shorter period required by the applicable client contract;
where the breach is likely to result in a high risk to individuals, inform the individuals affected; and
record what happened and what was done, including decisions on client notifications, regulatory notifications and remedial actions, and take any steps needed to prevent it happening again.
9. Confidentiality and data handling
The Company handles information according to its sensitivity and business purpose. Client confidential information, personal data, credentials, commercial information, technical materials and project deliverables must be accessed, used and shared only for authorised purposes and only with people who need the information for the relevant engagement. Associates must comply with their confidentiality, data protection and information security obligations to the Company and to the relevant client. Information from one client environment must not be used in, disclosed to, or stored with another client environment unless authorised by the relevant client and permitted by law. At project completion, or earlier if access is no longer required, associates must return or delete Company and client information in their possession as instructed within five business days, and the Company will remove their access to project folders and systems promptly thereafter, and in any event within two business days of such return or deletion being confirmed.
10. Roles and responsibilities
Overall accountability for information security rests with the founders and management. Jacob Brown is the Company’s information security lead responsible for the day-to-day operation of this policy, maintaining supporting procedures and acting as the primary contact for security and data protection matters. Every person to whom this policy applies is responsible for reading and understanding it, complying with it, protecting the information and systems they access, and promptly reporting any suspected security incident or weakness. Managers and project leads are responsible for ensuring that associates working on their engagements understand and comply with the obligations relevant to their work.
11. Acceptable use
Company systems, client information and equipment must be used only for authorised business purposes and in a lawful, professional and secure manner. Users must not install unauthorised software, disable or circumvent security controls, connect unauthorised devices, or use Company systems to store, send or access material that is unlawful, offensive or unrelated to the Company’s business. Limited incidental personal use of Company email and systems is permitted provided it is reasonable, does not interfere with work, does not create security or legal risk, and does not breach this policy. Users must not use unauthorised applications, cloud services or file-sharing tools to process Company or client information.
12. Training and awareness
All founders, employees (if any) and associates must complete information security and data protection awareness guidance at the start of their engagement and at appropriate intervals thereafter, including guidance on recognising phishing, social engineering and fraudulent requests. The Company will provide or signpost proportionate training and will issue reminders and updates following significant incidents or material changes to this policy or the threat environment.
13. Third-party and supplier management
Before engaging a service provider, sub-processor or other third party that will access, host or process Company systems, client information, confidential information or personal data, the Company will carry out proportionate due diligence on that party’s security arrangements and put in place written terms imposing appropriate confidentiality, security and data protection obligations, including, where personal data is involved, terms that satisfy the UK GDPR requirements for processors and sub-processors. The Company will maintain a record of third parties that have such access and will review their continued suitability at least annually and following any significant security incident involving such a third party. Where the Company acts as a processor for a client, it will not engage a sub-processor without the authorisation required under the applicable data processing terms.
14. Data retention and secure disposal
Information is retained only for as long as necessary for the business, legal, regulatory or contractual purpose for which it is held, after which it is securely deleted or destroyed. Client and associate information is retained and disposed of in accordance with the relevant engagement terms and any applicable data processing terms, and returned, deleted or access-disabled at project completion as set out in this policy. Confidential information and personal data in physical form must be disposed of securely, and hardware and storage media must be securely wiped or destroyed before disposal, reuse or return so that no recoverable data remains.
15. Encryption
Confidential information and personal data must be protected by encryption in transit and at rest, using the encryption features provided by the Company’s supported software and cloud services; where the platform does not support encryption at rest, appropriate alternative safeguards must be applied. Devices used to access Company systems or client information, and any removable media used to store confidential information or personal data, must be encrypted where the platform supports it. Encryption keys, passwords and recovery credentials must be protected and must not be shared other than as authorised.
16. Logging, monitoring and audit
The Company relies on the logging and monitoring capabilities of its supported systems and cloud services to help detect, investigate and respond to security incidents and unauthorised access. To the extent permitted by law, the Company may monitor and audit the use of its systems and access to Company and client information for security, compliance and investigation purposes. Any such monitoring will be carried out proportionately and in accordance with applicable law, and users should be aware that they will have a limited expectation of privacy in their business use of Company systems. Access and activity records will be reviewed periodically and following any suspected security incident.
17. Remote and home working
When working remotely, users must take the same care to protect Company systems, client information, confidential information and personal data as they would in an office. Users must connect only via secure, trusted networks, must not use unsecured public Wi-Fi to access confidential information or personal data without appropriate protection, must keep devices and paper records physically secure and out of sight of others, must ensure screens are not overlooked in public or shared spaces, and must lock devices when unattended.
18. Business continuity and backup
For business continuity purposes, the Company relies on the availability and recovery features of its cloud services to protect against data loss and service disruption. The Company will take proportionate steps to ensure that critical information can be recovered following an incident, outage or loss of access, will maintain awareness of and periodically verify the recovery arrangements provided by its key service providers, and will respond to significant disruption in a way that prioritises the protection and restoration of client information and personal data.
19. Use of artificial intelligence tools
Confidential information, client information, credentials or personal data must not be entered into, uploaded to, or processed by third-party artificial intelligence or generative AI tools unless the tool has been approved by management for that purpose, appropriate contractual and data protection safeguards are in place, and any applicable client restrictions permit it. Users remain responsible for the accuracy, confidentiality and lawful handling of any output, and must comply with any client requirements or restrictions on the use of AI tools in connection with an engagement.
20. Data subject rights
The Company will handle requests from individuals to exercise their rights under the UK GDPR, including rights of access, rectification, erasure, restriction, objection and portability, in accordance with applicable law and within the required timescales. Where the Company processes personal data as a processor on behalf of a client, it will not respond to such requests directly unless authorised, but will promptly notify the relevant client controller and provide reasonable assistance in responding, as required by the applicable data processing terms. Any request or complaint relating to personal data must be escalated to the information security lead or management without delay.
21. Removable media and personal devices
The use of removable media (such as USB drives and external storage) to store or transfer confidential information or personal data should be avoided in favour of the Company’s secure cloud services and, where unavoidable, such media must be encrypted, kept secure and securely wiped or destroyed when no longer required. Where personal devices are used to access Company systems or client information, they must meet the security requirements set out in the Devices section of this policy, must not be used to store confidential information or personal data locally except where authorised with suitable safeguards, and must have Company and client information removed on request or at the end of the engagement.
22. Review
The founders and management review this policy at least once a year and after any significant incident, material change in the Company’s systems, material change in client or associate working arrangements, relevant legal or regulatory development, or significant change to the cyber threat landscape. Any material changes to this policy will be communicated to associates and other relevant personnel.
