Legal
HASC Privacy Policy
How the HASC website handles your personal information — what we collect, why, who it is shared with, and the cookies we set.
Last updated: 03/10/2026
Introduction
At the High Assurance Security Centre (HASC), we are committed to protecting your privacy and ensuring that your personal information is handled in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy explains how we collect, use, store, and protect your information when you use our official website.
Information We Collect
- Personal identifiers and contact details - name, job title, organisation, phone numbers, and email addresses.
- Sign-in data - we use Microsoft Entra for sign-in, which means we hold the identifiers and authentication tokens it issues for your account. We never see or store your password.
- Your organisation’s email domain - this does real work, so it is worth being plain about. Where your organisation holds a HASC membership, we record the domain of your work email address and use it to grant you member access automatically, without anyone having to invite you. It is also how we know which organisation’s membership you belong to.
- Policy Navigator conversations - the questions you ask, the answers returned, and a count of the tokens each exchange consumed, which is how your monthly allowance is measured. Your questions go to Azure OpenAI inside HASC’s own Microsoft Azure subscription, never to a public AI service, and Microsoft does not use them to train its models.
- Engagement and transactional data - attendance at HASC events, training programmes, or other services, including expressions of interest in HAST Academy courses.
- Website interaction data - downloads, video views, and browsing behaviour via cookies and, if you accept them, analytics and advertising tools.
- Areas of professional interest or expertise - to tailor relevant communications and events.
- Communication history - records of interactions such as event bookings, enquiries, and marketing responses.
How We Use Your Information
We use your information for the purposes below. UK GDPR requires us to have a lawful basis for each one, so we have named it against each purpose rather than leaving you to guess.
- Respond to your enquiries and provide requested services — lawful basis: contract, or our legitimate interests where you are enquiring on behalf of an organisation.
- Provide and administer your membership, including sign-in, granting member access from your organisation’s email domain, and measuring your Policy Navigator allowance — lawful basis: contract.
- Send you updates, newsletters, or information about HASC activities — lawful basis: consent, which you can withdraw at any time.
- Understand how the platform is used, in aggregate, so we can improve it — lawful basis: consent for analytics and advertising cookies, and our legitimate interests in operating and improving a secure platform for error reporting and diagnostics.
- Measure which of our adverts lead to enquiries, so we can tell which of them are worth running — lawful basis: consent, which you can withdraw at any time.
- Improve our website and monitor its usage, including keeping it secure — lawful basis: legitimate interests.
- Comply with legal obligations — lawful basis: legal obligation.
Where we rely on legitimate interests, you have the right to object, and we will stop unless we have compelling grounds to continue. Where we rely on consent, withdrawing it is straightforward and costs you nothing else.
Data Security
We take appropriate technical and organisational measures to safeguard your personal data against unauthorised access, loss, or misuse. For an organisation that sells security assurance, “appropriate” ought to mean something specific, so here is what it means:
- Encryption in transit — TLS 1.2 as a minimum, TLS 1.3 preferred. Unencrypted protocols are prohibited.
- Encryption at rest — AES-256, including databases and cloud storage.
- Access control — least privilege and need to know. Shared and generic accounts are prohibited, every account is individually attributed, multi-factor authentication is enforced on all externally accessible systems, and access rights are reviewed regularly and revoked when a member of HASC personnel leaves.
- Independent assurance — we are Cyber Essentials Plus certified, and our controls align to ISO/IEC 27001:2022 and NCSC guidance.
- Incident response — where a breach is likely to risk your rights and freedoms, we notify the ICO within 72 hours of becoming aware of it, and tell affected people as soon as we reasonably can.
Access to your information is restricted to personnel who need it for legitimate business purposes.
How Long We Keep Your Information
We keep personal data only for as long as we need it, and the period depends on why we hold it.
- Account and access information. Held while your account is active, and for a limited period after it closes so that we can complete security and audit checks.
- Membership and commercial records. Held for the duration of your membership, and then for the period we are required to keep business and accounting records, which is normally six years from the end of the relevant financial year.
- Your use of our platform tools and the content you enter into them. Held while your account is active, so that you can return to your previous questions and answers, and so that we can support you and manage fair use of the tools. It is deleted when your account is closed.
- Technical, error and analytics information. Held for short, limited periods by the service providers who process it for us, and then deleted or reduced to aggregate statistics that no longer identify anyone.
HASC maintains an internal Data Retention Schedule setting the retention period for each category of personal data we hold and the basis for that period. If you would like to know how long we hold a particular category of your data, contact us at info@hasc.org.uk.
Your Rights
Under the UK GDPR, you have the following rights:
- Access your personal data held by us
- Request correction or deletion of your data
- Object to or restrict our processing of your data
- Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where that is technically feasible
- Withdraw consent for communications at any time
- Rights relating to automated decision making — we do not make decisions about you by automated means alone, and we do not profile you in a way that has legal or similarly significant effects. Policy Navigator answers your questions; it makes no decisions about your membership, your access or your standing. If that ever changes, we will say so here and you will have the right to human review.
- Lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your rights have been infringed
We respond to requests within one month. If a request is complex we may extend that, and we will tell you why within the first month if we do.
If something has gone wrong, we would rather hear from you first — not to stand between you and the ICO, but because we can usually fix it faster. Contact us using the details below and we will look into it and reply. You are free to go to the ICO at any point, whether or not you raise it with us, and doing so does not affect any other legal remedy.
Data Protection Officer
HASC has assessed whether it is required to appoint a Data Protection Officer under Article 37 of the UK GDPR and has concluded that it is not. The Managing Director holds overall accountability for data protection compliance at HASC. Data protection enquiries can be sent to info@hasc.org.uk.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at:
- Email: info@hasc.org.uk
- Postal Address: High Assurance Security Centre C.I.C., 86-90 Paul Street, London, EC2A 4NE
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page, and where appropriate, notified to you by email. Please check regularly to stay informed.