Skip to main content

Legal

HASC Privacy Policy

How the HASC website handles your personal information — what we collect, why, who it is shared with, and the cookies we set.

Last updated: 03/10/2026

Introduction

At the High Assurance Security Centre (HASC), we are committed to protecting your privacy and ensuring that your personal information is handled in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy explains how we collect, use, store, and protect your information when you use our official website.

Information We Collect

  • Personal identifiers and contact details - name, job title, organisation, phone numbers, and email addresses.
  • Sign-in data - we use Microsoft Entra for sign-in, which means we hold the identifiers and authentication tokens it issues for your account. We never see or store your password.
  • Your organisation’s email domain - this does real work, so it is worth being plain about. Where your organisation holds a HASC membership, we record the domain of your work email address and use it to grant you member access automatically, without anyone having to invite you. It is also how we know which organisation’s membership you belong to.
  • Policy Navigator conversations - the questions you ask, the answers returned, and a count of the tokens each exchange consumed, which is how your monthly allowance is measured. Your questions go to Azure OpenAI inside HASC’s own Microsoft Azure subscription, never to a public AI service, and Microsoft does not use them to train its models.
  • Engagement and transactional data - attendance at HASC events, training programmes, or other services, including expressions of interest in HAST Academy courses.
  • Website interaction data - downloads, video views, and browsing behaviour via cookies and, if you accept them, analytics and advertising tools.
  • Areas of professional interest or expertise - to tailor relevant communications and events.
  • Communication history - records of interactions such as event bookings, enquiries, and marketing responses.

How We Use Your Information

We use your information for the purposes below. UK GDPR requires us to have a lawful basis for each one, so we have named it against each purpose rather than leaving you to guess.

  • Respond to your enquiries and provide requested services — lawful basis: contract, or our legitimate interests where you are enquiring on behalf of an organisation.
  • Provide and administer your membership, including sign-in, granting member access from your organisation’s email domain, and measuring your Policy Navigator allowance — lawful basis: contract.
  • Send you updates, newsletters, or information about HASC activities — lawful basis: consent, which you can withdraw at any time.
  • Understand how the platform is used, in aggregate, so we can improve it — lawful basis: consent for analytics and advertising cookies, and our legitimate interests in operating and improving a secure platform for error reporting and diagnostics.
  • Measure which of our adverts lead to enquiries, so we can tell which of them are worth running — lawful basis: consent, which you can withdraw at any time.
  • Improve our website and monitor its usage, including keeping it secure — lawful basis: legitimate interests.
  • Comply with legal obligations — lawful basis: legal obligation.

Where we rely on legitimate interests, you have the right to object, and we will stop unless we have compelling grounds to continue. Where we rely on consent, withdrawing it is straightforward and costs you nothing else.

Sharing Your Information

We do not sell your personal information.

The platform runs in HASC's own Microsoft Azure subscription. Microsoft processes your information on our behalf as our hosting, database, file storage, email and sign-in provider, and may only use it to deliver those services to us. Questions you put to Policy Navigator, and documents processed for it, are sent to Azure OpenAI running inside that same subscription — they are not sent to a public AI service, and Microsoft does not use them to train its foundation models.

We also use Sentry to collect error reports from the website so we can diagnose faults. These contain technical details such as the page address, browser and error trace, and are processed in the EU.

Where your data goes outside the UK. Our own platform data stays in the UK — HASC’s Azure subscription runs in the UK South region. Three of the providers above involve transfers, and UK GDPR requires us to name the mechanism that protects them, so:

  • Sentry processes error reports in the European Union, which is covered by the UK’s adequacy regulations for the EEA. No further safeguard is required while that adequacy finding stands.
  • Microsoft may transfer data outside the UK in the course of providing Azure, Microsoft 365 and Clarity. Those transfers rely on the UK Addendum to the EU Standard Contractual Clauses, incorporated through Microsoft’s Data Protection Addendum, together with the EU–US Data Privacy Framework and its UK extension where the recipient is certified under it.
  • Google may transfer data outside the UK, including to the United States, when the Google Ads tag runs. Those transfers rely on the Standard Contractual Clauses incorporated through Google’s Ads controller data protection terms, which apply to that data because Google is an independent controller of it.

If you book or enquire about a course, the details you provide are sent to High Assurance Security Training Limited (HAST, trading as HAST Academy), a company registered in England and Wales under company number 16865309, whose registered office is at 66 Paul Street, London, EC2A 4NA, so they can deliver the training. HAST uses that information to run the course you have asked about.

Beyond this, we share information with service providers only where necessary to operate the site or deliver a service you have asked for, always under confidentiality agreements. We may also disclose information where required by law or to protect the rights, property, or safety of HASC and its users.

Cookies and Similar Technologies

Cookies and browser storage let a website keep small amounts of information on your device. We only place things that are strictly necessary to run the site until you tell us otherwise. Analytics and advertising stay switched off unless you accept them.

Under the Privacy and Electronic Communications Regulations we need your consent before setting anything that is not strictly necessary. You are asked on your first visit, and you can change your answer at any time:

Your choice covers both analytics and advertising and is stored for six months, after which we ask again. If you close the banner without choosing, nothing non-essential is set and we ask again next time.

Strictly necessary — always on

These deliver the site itself, so they do not require consent. Blocking them in your browser will break sign-in.

WhatSet byPurposeHow long it lasts
Microsoft Entra / MSAL sign-in entries (browser storage)HASC (Microsoft library)Keeps you signed in and holds the tokens that authorise your requests.Until you sign out, or after 4 hours of inactivity.
Session activity and sign-out entriesHASCEnds an idle session and signs you out of every open tab at once.Until you sign out, or after 4 hours of inactivity.
hasc-cookie-consentHASCRemembers the cookie choice you made, so you are not asked again.About 6 months, then we ask again.

Functional — set when you use the feature

Stored on your device only, never sent to us as a profile. They exist to deliver something you asked for, such as saving an article or remembering where you were.

WhatSet byPurposeHow long it lasts
Saved and read security news itemsHASCKeeps your saved items and marks what you have already seen.Until you clear your browser data.
Onboarding progress and sector selectionHASCRemembers where you reached in setup and which sector you chose.Until you clear your browser data.
Cached profile and tool preferencesHASCAvoids re-fetching your profile on every page and keeps tool settings.Until you clear your browser data.

Analytics — only with your consent

On www.hasc.org.uk we use Microsoft Clarity to understand how the site is used. Clarity records how visitors interact with pages — clicks, scrolling and page navigation — and can replay those sessions so we can see where the site is confusing or broken. It records your IP address, browser and device. Microsoft may use what it collects through Clarity for its own purposes as well as ours, so it is not acting solely on our instructions. That makes Microsoft an independent controller of that data in its own right, alongside us — not merely a processor following our instructions, which is what most analytics providers are. What Microsoft does with it is governed by its own privacy statement, not by this policy, and we cannot control or undo it on your behalf. Clarity runs only on our public website, and none of it loads unless you accept.

CookieSet byPurposeHow long it lasts
_clckMicrosoft Clarity (hasc.org.uk)Keeps a Clarity identifier for the browser so repeat visits are linked.Roughly a year.
_clskMicrosoft Clarity (hasc.org.uk)Groups the pages you view into a single session.Within a day.
CLIDMicrosoft (clarity.ms)Identifies the browser to Clarity’s own service.Up to a year. Set by Microsoft, not us.
MUID, ANONCHK, SMMicrosoftMicrosoft’s own identifiers, used across its services for analytics and, in Microsoft’s hands, advertising.Set by Microsoft and outside our control, so we do not state a figure we cannot stand behind — ANONCHK is short-lived, SM lasts the session, and MUID persists for months. Microsoft’s own statement is authoritative.

If you reject, or later withdraw consent, we stop Clarity from loading and clear the Clarity entries we can reach from this site. The cookies Microsoft sets on its own domains can only be removed through your browser or Microsoft's own privacy controls.

Advertising — only with your consent

On www.hasc.org.uk we use Google Ads conversion measurement to measure which of our adverts lead to enquiries. If you accept, a Google tag loads and tells Google which page you viewed — the address only, never anything after a ? or # — and may set the cookies below. Google receives your IP address, browser and device details and can link them to what it already holds about you, including a Google account if you are signed in to one. Google may use what it collects for its own purposes as well as ours, so it is not acting solely on our instructions. That makes Google an independent controller of that data in its own right, alongside us. What Google does with it is governed by its own privacy policy, not by this policy, and we cannot control or undo it on your behalf. Nothing is requested from Google unless you accept, and the tag runs only on our public website.

CookieSet byPurposeHow long it lasts
_gcl_au, _gcl_awGoogle Ads (hasc.org.uk)Lets Google Ads tell whether someone who clicked one of our adverts later made an enquiry. Holds an identifier for the browser and, for _gcl_aw, the advert click.About 90 days.
_gac_*Google Ads (hasc.org.uk)Holds the advert click details Google Ads needs to credit an enquiry to the advert behind it.About 90 days.
Cookies on google.com and doubleclick.netGoogleGoogle’s own identifiers, which it may set when the tag loads and which it uses across its services, including to show and measure adverts.Set by Google and outside our control, so we do not state a figure we cannot stand behind. Google’s own statement is authoritative.

If you reject, or later withdraw consent, we tell Google consent is denied, stop the Google tag sending anything further and clear the Google entries we can reach from this site. The cookies Google sets on its own domains can only be removed through your browser or Google's own privacy controls.

Rejecting analytics and advertising costs you nothing: every part of the platform works exactly the same either way.

We do not sell your data. Sentry, which we use for error reports, sets no cookies and stores nothing on your device.

You can also block or delete cookies in your browser settings. Blocking the strictly necessary ones will stop you from signing in.

Data Security

We take appropriate technical and organisational measures to safeguard your personal data against unauthorised access, loss, or misuse. For an organisation that sells security assurance, “appropriate” ought to mean something specific, so here is what it means:

  • Encryption in transit — TLS 1.2 as a minimum, TLS 1.3 preferred. Unencrypted protocols are prohibited.
  • Encryption at rest — AES-256, including databases and cloud storage.
  • Access control — least privilege and need to know. Shared and generic accounts are prohibited, every account is individually attributed, multi-factor authentication is enforced on all externally accessible systems, and access rights are reviewed regularly and revoked when a member of HASC personnel leaves.
  • Independent assurance — we are Cyber Essentials Plus certified, and our controls align to ISO/IEC 27001:2022 and NCSC guidance.
  • Incident response — where a breach is likely to risk your rights and freedoms, we notify the ICO within 72 hours of becoming aware of it, and tell affected people as soon as we reasonably can.

Access to your information is restricted to personnel who need it for legitimate business purposes.

How Long We Keep Your Information

We keep personal data only for as long as we need it, and the period depends on why we hold it.

  • Account and access information. Held while your account is active, and for a limited period after it closes so that we can complete security and audit checks.
  • Membership and commercial records. Held for the duration of your membership, and then for the period we are required to keep business and accounting records, which is normally six years from the end of the relevant financial year.
  • Your use of our platform tools and the content you enter into them. Held while your account is active, so that you can return to your previous questions and answers, and so that we can support you and manage fair use of the tools. It is deleted when your account is closed.
  • Technical, error and analytics information. Held for short, limited periods by the service providers who process it for us, and then deleted or reduced to aggregate statistics that no longer identify anyone.

HASC maintains an internal Data Retention Schedule setting the retention period for each category of personal data we hold and the basis for that period. If you would like to know how long we hold a particular category of your data, contact us at info@hasc.org.uk.

Your Rights

Under the UK GDPR, you have the following rights:

  • Access your personal data held by us
  • Request correction or deletion of your data
  • Object to or restrict our processing of your data
  • Data portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where that is technically feasible
  • Withdraw consent for communications at any time
  • Rights relating to automated decision making — we do not make decisions about you by automated means alone, and we do not profile you in a way that has legal or similarly significant effects. Policy Navigator answers your questions; it makes no decisions about your membership, your access or your standing. If that ever changes, we will say so here and you will have the right to human review.
  • Lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your rights have been infringed

We respond to requests within one month. If a request is complex we may extend that, and we will tell you why within the first month if we do.

If something has gone wrong, we would rather hear from you first — not to stand between you and the ICO, but because we can usually fix it faster. Contact us using the details below and we will look into it and reply. You are free to go to the ICO at any point, whether or not you raise it with us, and doing so does not affect any other legal remedy.

Data Protection Officer

HASC has assessed whether it is required to appoint a Data Protection Officer under Article 37 of the UK GDPR and has concluded that it is not. The Managing Director holds overall accountability for data protection compliance at HASC. Data protection enquiries can be sent to info@hasc.org.uk.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at:

  • Email: info@hasc.org.uk
  • Postal Address: High Assurance Security Centre C.I.C., 86-90 Paul Street, London, EC2A 4NE

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page, and where appropriate, notified to you by email. Please check regularly to stay informed.