Privacy notice.
How information submitted to 39Security.co.uk is used and protected.
Who is responsible
39Security is a trading name of Thirty Nine Degrees Ltd, company number 11715128. The ICO registration shown for the business is ZA764888.
Website, assessment and order information
We collect information supplied through contact, assessment and checkout forms, including names, organisations, contact details, business size, assessment answers, selected services and implementation notes. We also retain order references, payment provider, payment status and provider transaction, customer or subscription identifiers where supplied. Card details are entered on Stripe or SumUp hosted checkout and are not stored by this website.
Training-event booking information
When an event is booked, we collect the booking contact’s business and contact details, delegate names, job titles, booking quantity, payment status, event attendance information and any details needed to administer the course. Paid delegates receive transactional confirmation and reminder emails, a protected workbook link and a calendar file. Optional marketing consent is recorded separately and is not required to attend.
Dietary and accessibility information
Dietary or accessibility details can reveal sensitive personal information. They are requested only where needed to support attendance, are restricted to staff and suppliers who need them for event delivery, and should be deleted or anonymised after the event and any reasonable follow-up period unless a longer legal requirement applies. The booking contact should obtain each delegate’s permission before submitting these details.
News and alert subscriptions
When someone signs up for news and alerts, we record their email address, optional name, company, area preferences, selected topics, consent wording and timestamps. A confirmation email is used before the subscription becomes active. Every marketing email should include the individual unsubscribe link, and unsubscribed records are retained only as needed to respect the opt-out and meet compliance requirements.
Policy and resource downloads
When you request a downloadable policy, checklist or other resource, we use the email address you provide to send a transactional secure-link email. The delivery email uses a unique tracking pixel and secure link so we can record email opens, link clicks and actual file downloads. These measurements can be affected by privacy proxies and automated mail-security scanners. The request does not add you to a marketing list. Download links expire and are protected by a random token.
Partner referral attribution
If you arrive through an approved 39Security partner referral link, we may store the partner referral code, landing page and resulting enquiry or booking attribution. This is used to measure the effectiveness of the partnership and does not change your price or require you to buy a 39Security service.
Marketing measurement
Where configured and permitted by the visitor's consent choice, the website can use Google tags, Meta Pixel, LinkedIn Insight Tag and the 39D CRM website tracker. Campaign parameters, UTM values, referrers and advertising click identifiers may be stored so marketing performance can be measured. The CRM uses a pseudonymous visitor reference and, where a visitor arrives through a tracked CRM email and has granted the relevant consent, page views can be associated with the corresponding CRM contact and email/campaign journey.
Windows update and hardware inventory
For managed customers, the protected inventory API can receive business device information such as client name, computer name, manufacturer, model, serial number, Windows edition and build, most recently reported KB, patch date, processor, warranty and replacement dates. This information is available only in the administration area and is used for patch visibility, support planning and hardware lifecycle recommendations.
Why information is used
Information is used to respond to requests, provide assessments, process and administer orders and event bookings, deliver training and contracted services, maintain security, manage device lifecycle, prevent abuse and measure marketing. The applicable lawful basis depends on the activity and may include performance of a contract, legal obligations, consent or legitimate business interests.
Service providers and sharing
Information may be processed by suppliers needed for hosting, email, payment, analytics, advertising, customer relationship management and security delivery. It may also be disclosed where required by law or to protect legitimate rights. Supplier due diligence and contractual safeguards are used where required, including for relevant international transfers.
Retention and security
Records should be retained only for the approved business, contractual, security, accounting and legal periods. Access to the admin area, Stripe and SumUp credentials and the inventory bearer token must be restricted. Hardware data must not be published on the public website.
Your rights and contact
Individuals may request access, correction or other applicable data-protection rights by contacting [email protected]. Concerns may also be raised with the UK Information Commissioner's Office.