Security and Data Handling Statement
Ignite Drive handles personal and business data on behalf of our clients and the audiences we engage for them. This statement sets out how we keep that data secure and handle it responsibly. Our controls are aligned with recognised good practice, including the principles of Cyber Essentials and ISO 27001, and with our obligations under UK GDPR and the Data Protection Act 2018.
Our security controls
- Least-privilege access. Access to systems and data is limited to what each task requires, protected by strong authentication, and reviewed and revoked promptly when no longer needed.
- Encryption. Data is encrypted in transit using TLS, and sensitive credentials, such as connected account access tokens, are encrypted at rest.
- Trusted providers. We use reputable, GDPR-compliant providers for hosting, database, email delivery, and AI processing, each engaged under their data-protection terms.
- Email authentication. Sending domains are protected with SPF, DKIM, and DMARC to prevent spoofing and safeguard deliverability and recipient trust.
- Secure systems and change control. Changes follow disciplined practices, including version control, testing, staged deployment, dependency scanning, and periodic security review before going live.
- Data minimisation and retention. We collect only the data we need, keep it only as long as necessary, and delete or return it on request or at the end of an engagement.
- Confidentiality and agreements. Client work is covered by confidentiality terms, and where we process data on a client's behalf we do so under a written data-processing agreement.
- Monitoring and incident response. We monitor for issues, and in the event of a personal-data breach we contain and assess it and notify affected clients and the ICO without undue delay, within 72 hours where required.
Data we handle and why
We process business contact and professional details for outreach and marketing, website enquiry data, and client and billing records. We act as a data controller for our own website, marketing, and prospect data, and as a data processor when we run outreach or email marketing on a client's instructions. Full detail is set out in our Privacy Policy.
Sub-processors. A current list of the third-party providers that may process data on our behalf is available to clients on request, and key providers are named in our Privacy Policy.
Review. This statement and the controls behind it are reviewed at least every 6 months as part of our management review, and whenever a significant change to our tools or processes occurs.