Privacy Policy
Last Updated: July 14, 2026
1. Introduction and Scope
Ovate ("we," "us," or "our") is a UK-registered cybersecurity firm specializing in Managed Detection & Response , Penetration Testing, Red Teaming, Digital Risk Protection , and Attack Surface Management.
We recognize that for our clients including Global Managed Service Providers (MSPs) and financial institutions data privacy is intrinsically linked to operational security. This Privacy Policy outlines our practices regarding the collection, processing, and protection of personal and operational data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. Our Role Under UK GDPR
To provide clarity on our data processing responsibilities:
- Data Controller: We act as a Data Controller concerning the contact and administrative information of our website visitors and business prospects.
- Data Processor: We act as a Data Processor when ingesting, analyzing, or interacting with operational telemetry, network logs, and infrastructure data on behalf of our clients during active service engagements.
3. Information We Collect
We practice strict data minimization, collecting only the information strictly necessary for business operations and service delivery.
3.1. Identity & Contact Data
When you interact with our website, request a consultation, or enter into a business agreement, we collect:
- Personal information such as name, email address, and phone number when voluntarily submitted.
- Basic website analytics to monitor site performance.
3.2. Operational & Telemetry Data
To execute our core cybersecurity services, we may process specific technical data:
- MDR & Attack Surface Management: We ingest network logs, endpoint telemetry, and infrastructure configurations to facilitate threat detection and triage.
- Penetration Testing & Red Teaming: We may temporarily process application data, network responses, and vulnerability metrics during active engagements.
- Note: Our Digital Risk Protection services generally rely on external threat intelligence and do not require the ingestion of internal client telemetry.
4. How We Use Your Information
We do not sell, rent, or broker your personal or operational data. All data is utilized under a strict "human-in-the-loop" framework to ensure accuracy and accountability. We process data for the following purposes:
- Service Delivery: To actively monitor, test, and protect client infrastructure against cyber threats.
- Threat Triage: To analyze security alerts and telemetry, distinguishing false positives from critical vulnerabilities.
- Communication: To deliver sensitive security reports, administrative updates, and respond to business inquiries.
- Legal Compliance: To satisfy regulatory obligations and defend against legal claims.
5. Third-Party Sub-Processors
We partner with specialized, vetted third-party cybersecurity vendors to enhance our threat detection and analysis capabilities.
- Scope of Processing: These external tools are utilized strictly for processing anonymized machine telemetry, threat intelligence, and security logs.
- Data Isolation: Our third-party sub-processors do not have access to, nor do they store, our clients' personal contact information or identity data.
6. Security & Confidentiality
As a cybersecurity provider, we hold ourselves to the highest standards of data protection. While no environment is entirely immune to risk, we safeguard your data using enterprise-grade security controls, including:
- Encryption: Data is encrypted both in transit and at rest
- Access Controls: We enforce strict Role-Based Access Control (RBAC) and the principle of least privilege. Only authorized analysts assigned to your engagement can access your operational data.
- Infrastructure Security: Our systems are hardened against unauthorized access, continually monitored, and isolated to prevent data leakage.
7. Data Retention & Permanent Destruction
Our data retention policy reflects our commitment to zero-trust principles and minimizing client risk.
- Project Reports & Telemetry: Upon the completion of a project or the termination of a service contract, all client project data, operational telemetry, and final reports are permanently and securely destroyed. We do not retain copies of penetration test reports or security findings after they have been successfully handed over to the client.
- Administrative Data: B2B contact information and billing records are retained only for the duration of the active business relationship and for the minimum period legally required for UK tax and accounting compliance.
8. International Data Transfers
Given our global client base, administrative data may be processed outside the UK. When transferring data internationally, we ensure it is protected by appropriate legal safeguards, such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs), ensuring your data receives equivalent protection regardless of where it is processed.
9. Contact Us
For questions regarding this Privacy Policy, our data destruction protocols, or vendor risk assessments, please reach out to us at:
- Email : contact@ovatesecurity.com
- Address : 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ