Privacy Notice
About us
Nanorisk Limited (“Nanorisk”, “we”, “us”, or “our”) is a UK-based cyber security consultancy. We are committed to protecting the privacy and security of personal data.
Nanorisk Limited, The Work Place, Aycliffe Business Park, Heighington Lane, Newton Aycliffe, DL5 6AH
Email: info@nanorisk.co.uk
Telephone: 0191 369 2434
Nanorisk acts as a data controller for personal data processed in connection with our business operations and portal administration, and as a data processor when processing personal data on behalf of clients as part of contracted security assessment services.
Scope of this privacy notice
This Privacy Notice applies to clients, client representatives, portal users, and other individuals whose personal data may be processed in connection with Nanorisk’s services or the operation of the Nanorisk Security Portal.
Personal data we process
Nanorisk may process the following categories of personal data, depending on context:
- Client and business contact details (name, job title, organisation, business contact information)
- Portal account and access data (user accounts, authentication data, access logs)
- Engagement-related data (communications, identifiers associated with in-scope systems)
- Technical and security data (IP addresses, audit logs, system identifiers)
Nanorisk does not intentionally collect personal data beyond what is necessary to deliver its services.
Purposes of processing
Personal data is processed for the following purposes:
- Delivering contracted cyber security services
- Managing client relationships and communications
- Operating, securing, and administering the Nanorisk Security Portal
- Producing and delivering assessment reports
- Maintaining audit trails and quality assurance
- Complying with legal, regulatory, and contractual obligations
Lawful bases for processing
Nanorisk processes personal data in accordance with UK GDPR under the following lawful bases:
- Contract — where processing is necessary to deliver agreed services
- Legal obligation — where required to comply with applicable laws
- Legitimate interests — including security monitoring, fraud prevention, and service improvement
Nanorisk does not generally rely on consent as a lawful basis for processing in the context of security assessments.
Data sharing and sub-processors
Nanorisk may share personal data with trusted service providers acting as sub-processors, including hosting, infrastructure, and communication providers, solely where necessary to deliver services. All sub-processors are subject to appropriate contractual safeguards.
Nanorisk does not sell personal data.
International transfers
Personal data is hosted within the UK and/or European Economic Area. Where any international transfers occur, appropriate safeguards will be implemented in accordance with UK GDPR.
Data retention
Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, or as required by law or contract. Retention periods are defined within Nanorisk’s internal data retention policies.
Data security
Nanorisk implements appropriate technical and organisational measures to protect personal data, including access controls, encryption, and audit logging.
Individual rights
Individuals have rights under UK GDPR, including the right to access, rectify, or erase personal data, and the right to restrict or object to processing. Requests may be subject to lawful exemptions, particularly where disclosure could compromise security.
Individuals may exercise their data protection rights by contacting Nanorisk using the details provided in this notice.
Requests are assessed on a case-by-case basis in accordance with applicable data protection law. Where necessary, Nanorisk may request verification of identity before responding.
Requests will be responded to within applicable statutory timeframes. Where a request cannot be fulfilled in full due to legal, contractual, or security obligations, this will be explained to the individual.
Data breaches
Nanorisk maintains procedures to identify, assess, and respond to personal data breaches. Where required, breaches will be reported to the Information Commissioner’s Office and affected parties.
Contact and complaints
Questions regarding this Privacy Notice or the processing of personal data may be directed to info@nanorisk.co.uk. Individuals also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
Review and updates
This Privacy Notice is reviewed periodically and updated as necessary to reflect changes in legal, regulatory, or operational requirements.
Download the signed PDF (NR-3, 178 KB)