Skip to Content

Privacy Policy

1. Who we are


ALLSAFELY IT SERVICES LTD, registered in England and Wales, company number 17227414. Registered office: Office 9843, 321-323 High Road, Chadwell Heath, Essex, RM6 6AX, UK.

We are the data controller for the processing described here. Contact us about privacy at [email protected].

We are registered with the Information Commissioner's Office (ICO), registration number [in progress]. We have assessed that we are not required to appoint a Data Protection Officer; the address above reaches the person responsible for data protection.

2. When this policy applies


It applies when we decide how and why personal data is used, that is, for:
- visitors to `allsafely.io`;
- people and organisations we contact about our services;
- our clients' and suppliers' contact and billing people.

It does not apply to personal data inside a client's own systems. The client owns and hosts those systems; we work inside them on the client's instructions and do not copy that data onto allSafely's own systems. For that data we act as a processor under the client agreement, and the client's own privacy notice governs it.

Where we host a service for a client, personal data in that service is held only for the period agreed in the engagement (180 days by default for on-premise or allSafely-hosted setups) and used only to deliver the service. It remains processor data under the client agreement.

3. What we collect, why, and our lawful basis

a. Website visitors
Pages viewed, approximate location, device and browser type, and the site you arrived from. Privacy-friendly analytics (Plausible) runs without cookies and without collecting personal data. Google Analytics 4 runs only if you accept analytics cookies as described under the Cookies page.

Our legitimate interest in running and improving the site; consent for non-essential cookies.

b. Enquiries and live chat
Your name, email, company, and whatever you type into a form or the chat widget.
Our legitimate interest in responding, and taking steps toward a possible engagement at your request.

c. Prospective clients (our outbound contact)
The organisation's name, a named contact's role and business email address, and publicly available company information. We source this from public business directories and websites (including via the service Outscraper) and organise it in Baserow.

Our legitimate interest in business-to-business marketing. Every message identifies allSafely clearly and gives you a one-click way to opt out. We keep prospect records for up to 12 months from the date a contact is added, unless you engage us or ask us to stop sooner. When you opt out we remove the record and keep only a minimal suppression entry so we don't contact you again.

d. Clients and suppliers
Contact details for your team, engagement records, timesheets, correspondence, and billing details. Card payments are handled by Stripe and banking by Wise; we do not store full card numbers. Keeping this data is a legal obligation for accounting and tax records.

e. Security and audit logs

On the systems we manage for a client we switch on audit logging (sign-ins, administrative changes). Those logs stay inside the client's own systems and are not exported to allSafely. Where we host a service for a client, its logs are kept for the period agreed in the engagement (section 2). In both cases we act as a processor for the client.

4. AI tools


We use AI assistants (Anthropic's Claude, and OpenRouter restricted to zero-data-retention models) for internal drafting and analysis. Training on our inputs is disabled. We do not enter client personal data into AI tools unless the client has agreed to it in writing.

5. Who we share data with


We do not sell personal data. We use a small set of service providers who process data for us under contract:

  • Hosting and infrastructure: Hetzner (Germany).
  • Business platforms: Odoo (CRM, invoicing, website and live chat), Baserow (prospect database), Proton (email and calendar).
  • Payments and banking: Stripe, Wise.
  • Website analytics: Plausible; Google Analytics 4 and Search Console (analytics subject to your cookie choice).
  • AI: Anthropic; OpenRouter (zero-data-retention models only).


The current list is maintained on our Trust Center at `allsafely.io/trust`. We also disclose personal data where the law requires it, or to protect our rights.

6. Where your data is held

allSafely is a UK-registered company and operates remotely, including from outside the UK and the European Economic Area. Our service providers are located in the UK, the European Economic Area, Switzerland and the United States. Where personal data is transferred outside the UK we rely on UK adequacy regulations, the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.

7. How long we keep data

  • Website analytics: aggregated; Google Analytics 4 retention is set to 13 months.
  • Enquiries that don't lead to an engagement: up to 12 months.
  • Prospect records: up to 12 months from the date added, then removed (minimal suppression record kept).
  • Our engagement working files (project notes, assessments, research and design documents, correspondence, and your team's contact details): 1 year after the engagement ends, then deleted. This is the 1-year period in section 5 of our Terms of Service.
  • A service we host for a client (for example a hosted Wazuh server): its security and audit logs for the period agreed in the engagement, 180 days by default; backups of the hosted server for up to 1 year. Deleted after that. We hold this as a processor (section 2).
  • Invoicing, accounting and tax records: 6 years, as UK law requires.

8. Your rights

You can ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; provide it in a portable format; and, where we rely on consent, withdraw that consent. You can object to direct marketing at any time and we will always stop.

To exercise any of these, email [email protected]. We respond within one month. There is no charge unless the request is excessive or repetitive.

If you are unhappy with how we handle your data you can complain to the ICO at `ico.org.uk` or 0303 123 1113. Depending on where you are located, your local data protection authority may also be able to help.

9. Children

Our services are for businesses. We do not knowingly collect personal data about children.

10. Changes to this policy

We may update this policy. For material changes we give clients at least 30 days' notice by email and publish the new version here with a new effective date. Past versions stay available at their own dated links. 

11. Version history

 This is the first version of the privacy policy. 


By engaging us, or paying an invoice that links to this page, you accept these terms.