UltraSecure

LEGAL

Privacy Policy

Last updated: June 2026

1. Introduction

UltraSecure ('we', 'us', 'our') is committed to protecting the personal data of our clients, website visitors, and partners. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website at theultrasecure.com or engage our services.

We are committed to compliance with the General Data Protection Regulation (GDPR), the UK GDPR, and applicable data protection laws in Pakistan, the UAE, and the Kingdom of Saudi Arabia.

If you have any questions about this policy, please contact us at privacy@theultrasecure.com.

2. Data We Collect

We collect only the data necessary to provide our services and operate our business. This includes:

Contact and identity information: Full name, company name, job title, work email address, and phone number provided when you contact us or submit a form on our website.

Engagement data: Information you provide during scoping calls, statement of work discussions, and service engagements, including organizational details, technical environment information, and scope definitions.

Website usage data: IP address, browser type, pages visited, and time spent on our website, collected via cookies and server logs for analytics purposes.

Communications: Records of email correspondence and enquiries submitted through our contact forms.

3. How We Use Your Data

We process your personal data for the following purposes:

Service delivery: To scope, plan, and execute security engagements you have contracted us to perform.

Communications: To respond to enquiries, provide quotes, and send engagement-related communications.

Legal compliance: To meet our obligations under applicable law, including record-keeping requirements.

Improving our services: To analyse aggregated, anonymized website usage data and improve our content and user experience.

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

4. Data Security

We apply technical and organisational measures appropriate to the sensitivity of the data we hold. Our security practices include:

Encryption of data in transit using TLS 1.2 or higher for all web communications and client data transfers.

Access controls limiting data access to personnel with a legitimate need on a least-privilege basis.

Secure destruction of client data at engagement close in accordance with agreed data handling procedures.

Regular internal security assessments and team training on data protection practices.

As a security firm, we hold ourselves to the highest standard. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

5. Third-Party Services

We use a limited number of third-party services to operate our website and business. These may include:

Hosting and infrastructure providers for our website and internal systems.

Email delivery services for transactional communications.

Analytics tools for aggregated, anonymized website usage statistics.

All third-party processors are selected based on their data protection practices and are bound by data processing agreements where required under GDPR.

6. Your Rights

Under GDPR and applicable data protection law, you have the following rights:

Right of access: You may request a copy of the personal data we hold about you.

Right to rectification: You may request correction of inaccurate or incomplete data.

Right to erasure: You may request deletion of your data where there is no legitimate basis for continued processing.

Right to restrict processing: You may request that we limit how we use your data in certain circumstances.

Right to data portability: You may request your data in a structured, machine-readable format.

Right to object: You may object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@theultrasecure.com. We will respond within 30 days.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.

Engagement data including reports and correspondence is retained for 7 years following engagement close to meet legal and regulatory record-keeping requirements.

Contact form enquiries where no engagement results are retained for 12 months.

Website analytics data is retained in anonymized, aggregated form indefinitely.

On request at engagement close, we will securely destroy client data and provide written confirmation.

8. Contact

For all data protection enquiries, rights requests, or concerns, contact us at:

Email: privacy@theultrasecure.com

Website: theultrasecure.com/contact

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.