Effective date: 15 July 2026
How JSsec collects, uses, and protects personal data across our website and dashboard.
JSsec Ltd (company number 15774465), whose registered office is at 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE, is the controller of the personal data described in this policy ("JSsec", "we", "our", "us"). We operate our website at jssec.co.uk and jssec.com (the "Website") and the customer dashboard at dashboard.jssec.co.uk and dashboard.jssec.com (the "dashboard").
You can contact us about this policy at [email protected].
This policy explains how we use personal data as a controller, for visitors to the Website, people who contact us or book a demo, users of the dashboard, and our marketing.
When we detect and act on phishing and brand abuse for a customer, we process personal data as that customer's processor, on their instructions, under the Data Processing Agreement that forms part of our Master Services Agreement. That processing is governed by the DPA, not by this policy.
We do not seek to collect special-category data through the Website or dashboard.
Under the UK GDPR we rely on the following bases:
We use cookies and similar technologies on the Website. Analytics and advertising technologies load only after you accept them. Our Cookie Policy at jssec.co.uk/policies/cookie explains each one and how to manage your choices.
We share personal data with service providers who process it on our behalf, including:
We require these providers to protect personal data and to use it only for the purposes we specify. We may also disclose personal data where the law requires it, or to establish, exercise or defend legal claims. We do not sell your personal data.
The sub-processors that support the customer service (as opposed to this controller processing) are listed in, and governed by, the DPA.
We hold personal data in the United Kingdom. Where a provider processes personal data outside the UK, we rely on UK adequacy regulations or on the UK International Data Transfer Agreement (IDTA) or UK-approved standard contractual clauses.
We keep personal data only for as long as we need it for the purposes set out above, or as the law requires. Indicative periods: enquiry and CRM lead data for up to 24 months after our last contact with you; dashboard account data for the term of your organisation's contract and up to 90 days afterwards; analytics data per our Google Analytics retention setting; marketing data until you opt out.
Under the UK GDPR you have the right to access your personal data; to have it corrected or erased; to restrict or object to our processing; to data portability; and to withdraw consent where we rely on it. To exercise any of these, email [email protected]. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), though we would welcome the chance to resolve your concern first.
We apply appropriate technical and organisational measures to protect personal data, summarised at jssec.co.uk/security. No system can be guaranteed completely secure, but we work to protect your data and to meet our obligations if anything goes wrong.
The Website and our services are provided to businesses and are not directed to children.
We may update this policy from time to time. If we make material changes we will post the updated policy on this page with a new effective date.
JSsec Ltd
3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
Email: [email protected]
For other ways to reach us, see our Contact page at jssec.co.uk/contact.