Privacy Policy
How Granite Intel & Protection collects, uses and safeguards your personal information.
Granite Intel & Protection Ltd (“Granite Intel & Protection”, “we”, “us” or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, store and protect data when you interact with our website and services.
Effective date: 4 June 2026
Last updated: 4 June 2026
1. Information We Collect
We collect personal information that you voluntarily provide to us when you engage with our services or use our website. This includes:
1.1 Information Provided Through Our Contact Form
- Full name — to identify you and personalise our communications.
- Email address — to respond to your enquiry and provide requested information.
- Telephone number — to contact you regarding time-sensitive matters or at your request.
- Organisation name — to understand the context of your enquiry and tailor our response appropriately.
- Message content — the details of your enquiry or request.
1.2 Information Collected Automatically
When you visit our website, we may automatically collect certain technical data, including:
- IP address and approximate geographic location
- Browser type and version
- Operating system
- Pages visited, time spent on pages and navigation paths
- Referring website or source
1.3 Information From Client Engagements
In the course of providing our professional services, we may collect additional personal information as necessary for the specific engagement. The collection and processing of such data is governed by individual client agreements and is subject to the strictest confidentiality obligations.
2. How We Use Your Information
We use the personal information we collect for the following purposes:
- Responding to enquiries — processing and replying to contact form submissions and service requests.
- Service delivery — providing intelligence, protection and investigative services as contracted.
- Client relationship management — maintaining records of communications and engagements to ensure continuity of service.
- Legal compliance — meeting our obligations under applicable laws, regulations and professional standards.
- Website improvement — analysing usage patterns to enhance site functionality, content and user experience.
- Security — detecting and preventing fraud, unauthorised access or other malicious activity on our website and systems.
We will never sell, rent or trade your personal information to third parties for marketing purposes.
3. Data Protection & Security
As a firm operating within the intelligence and security sector, data protection is not merely a regulatory obligation — it is central to our professional identity and operational culture. We implement robust technical and organisational measures to protect your personal data, including:
- Encryption — all data transmitted between your browser and our servers is protected using TLS (Transport Layer Security) encryption.
- Access controls — personal data is accessible only to authorised personnel on a strict need-to-know basis, in accordance with our internal security protocols.
- Secure storage — electronic records are stored on encrypted, access-controlled systems. Physical documents containing personal data are secured in restricted-access facilities.
- Data minimisation — we collect only the information necessary for the stated purpose and retain it only for as long as required.
- Staff vetting — all personnel who handle personal data are security-vetted and trained in data protection procedures.
- Incident response — we maintain a documented data breach response plan and will notify affected individuals and the Information Commissioner’s Office (ICO) in accordance with legal requirements should a breach occur.
4. Your Rights
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights in relation to your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may request correction of inaccurate or incomplete personal data.
- Right to erasure — you may request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to restrict processing — you may request that we limit how we use your data in certain circumstances.
- Right to data portability — you may request transfer of your data to another organisation in a structured, commonly used format.
- Right to object — you may object to processing of your personal data where we are relying on a legitimate interest.
- Rights related to automated decision-making — you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, please contact us using the details provided in Section 7 below. We will respond to all legitimate requests within one calendar month.
5. Cookies
Our website uses cookies and similar technologies to enhance your browsing experience. Cookies are small text files placed on your device that allow us to recognise your browser and capture certain information.
5.1 Types of Cookies We Use
- Strictly necessary cookies — essential for the website to function correctly. These cannot be disabled.
- Analytical/performance cookies — allow us to recognise and count visitors and understand how visitors navigate the site. All data collected is aggregated and anonymous.
- Functionality cookies — used to recognise you when you return to the website and to personalise content for you.
5.2 Managing Cookies
You can control and manage cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website. For more information about cookies and how to manage them, visit www.allaboutcookies.org.
6. Third Parties
We may share your personal information with third parties only in the following limited circumstances:
- Service providers — trusted third-party providers who assist us in operating our website, conducting business or servicing you, provided they agree to keep your information confidential. This may include hosting providers, email service providers and analytics platforms.
- Legal obligations — where we are required to disclose personal data by law, regulation, legal process or enforceable governmental request.
- Professional advisers — including lawyers, auditors and insurers, where necessary for the establishment, exercise or defence of legal claims or for the purposes of obtaining professional advice.
- Business transfers — in connection with any merger, acquisition or sale of company assets, your personal data may be transferred as part of that transaction, subject to the same privacy protections described in this policy.
We do not permit third parties to use your personal data for their own marketing purposes. All third-party processors are bound by contractual obligations to process personal data only on our instructions and in compliance with applicable data protection legislation.
6.1 International Transfers
Where we transfer personal data outside the United Kingdom, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the Information Commissioner’s Office, adequacy decisions or other lawful transfer mechanisms under UK GDPR.
7. Contact for Data Enquiries
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how your personal information is being processed, please contact us:
- Data Protection Officer
Granite Intel & Protection Ltd - Email: privacy@granite-intelprotection.co.uk
- Telephone: +44-1224 049204
- Post: Granite Intel & Protection, 2 Union Terrace, Aberdeen, Scotland AB10 1NJ
If you are not satisfied with our response or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting or reporting requirements. Retention periods are determined based on:
- The nature and sensitivity of the data
- The potential risk of harm from unauthorised use or disclosure
- The purposes for which we process the data
- Applicable legal and regulatory requirements
Contact form submissions are retained for a maximum of 24 months unless a formal client engagement is initiated. Client engagement records are retained in accordance with our professional obligations and applicable statutes of limitation.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or operational needs. Any material changes will be posted on this page with an updated “Last updated” date. We encourage you to review this policy periodically.
Continued use of our website or services after any modifications to this Privacy Policy constitutes your acknowledgement of the changes and your consent to abide by the updated terms.