Skip to content
Red Vault

Legal

Privacy Policy

How Red Vault handles personal data for clients, prospects and website visitors under UK GDPR and the Data Protection Act 2018.

Last updated

Who we are

Red Vault Ltd is the data controller for personal data collected through our services and website. We are registered in England and Wales (company number 17184267) with our registered office at 23 Limeharbour, London E14 9TS.

We are registered with the UK Information Commissioner's Office (ICO) as a data controller. For data protection matters, email contact@redvault.co.uk.

What we collect

  • Contact data - name, email, phone, company.
  • Enquiry data - the message you send us through the contact form, and the IP address it was sent from. We keep the address to tell genuine enquiries from automated spam, and nothing else.
  • Account data - login credentials, role, and permissions.
  • Usage data - pages visited, time on site, referring source.
  • Service data - material we hold or process on your behalf, including any personal data within it.

How we use your data

  • To provide our services under the contract we have with you (UK GDPR Article 6(1)(b)).
  • To respond to enquiries and run our business operations under our legitimate interests (Article 6(1)(f)).
  • To meet legal obligations such as tax, accounting, and regulatory record-keeping (Article 6(1)(c)).
  • To send you marketing communications, with your consent (Article 6(1)(a)).

Who we share data with

  • Sub-processors we contract with to deliver our services. The current list is available on request - email contact@redvault.co.uk.
  • Professional advisers (legal, accounting, insurance) under confidentiality.
  • Regulators or law enforcement where legally required.

We do not sell your personal data.

International transfers

We aim to keep all personal data within the UK and EEA. Where data is transferred outside, we use the UK International Data Transfer Agreement (or the IDTA Addendum to the EU SCCs) and equivalent safeguards.

How long we keep data

We keep personal data only as long as needed for the purpose it was collected, or as required by law.

  • Client and contract records: typically seven years after end of contract for tax and audit purposes.
  • Enquiries sent through the contact form: twelve months, then deleted automatically. Ask us sooner and we will remove one on request.
  • Marketing contacts: until you withdraw consent.
  • Website analytics: aggregated after 26 months.

Your rights under UK GDPR

  • Access - request a copy of the personal data we hold about you.
  • Rectification - ask us to correct inaccurate data.
  • Erasure - request deletion (subject to legal exceptions).
  • Restriction and objection - limit how we use your data.
  • Data portability - receive your data in a structured, machine-readable format.
  • Withdraw consent - for any processing that relies on consent.
  • Lodge a complaint with the Information Commissioner's Office (ico.org.uk).

Security

We protect personal data with appropriate technical and organisational measures. Details of our current security posture and policies are available on request - email contact@redvault.co.uk.

Changes to this policy

We may update this policy. Material changes will be notified to active clients and reflected in the “Last updated” date at the top of this page.

Contact us

For privacy questions or to exercise your rights, email contact@redvault.co.uk.