How we keep your data safe
The systems we build hold a business's customers, jobs and money. This is how we protect them, in plain words. Everything here is something we do today, and anything you can check for yourself is linked.
- Registered company
- No. 17266711Check it at Companies House (opens in a new tab)
- Registered with the ICO
- No. ZC168993Check it on the ICO register (opens in a new tab)
- If something goes wrong
- You hear within 24 hours
- Where the data is held
- London and Dublin
- Fully insured
- £1m professional indemnityUnderwritten by Hiscox
Your data stays yours, in writing
Our client agreement includes the data protection terms UK law requires when one business handles personal data for another. You decide what is collected and why, and we only use it on your instructions.
The agreement names every company that helps us run your system, and you get fourteen days' notice before that list changes. If something ever goes wrong, we tell you within 24 hours. When the work ends, you choose whether we hand the data back or delete it. We never use your data, or your customers' data, to train AI.
Each customer only sees their own records
Who can see what is enforced by the database itself, not just by the screens. Rules on every table mean a customer only ever reaches their own records, even if someone tries to go around the app.
Every night an automatic check reads those rules on every database we run and alerts us the moment who can see or change something is different from the night before.
Checked the way an intruder would check it
Before any change that touches sign-in, payments or customer data goes live, we look at it as someone trying to get in would: a stranger, a customer, a member of staff, a former member of staff. If any of them could misuse it, it does not ship.
Every week, the past week's changes are reviewed again in the same way.
If you find a security problem in anything we run, please report it to team@ownlydigital.co.uk.
Tested with separate accounts before launch
Every new system is tested with separate test accounts to prove that one customer cannot reach another customer's data, an ordinary user cannot make themselves an admin, and staff you remove lose access straight away. These tests run on test copies, never on your live data.
Protected every day it runs
Public forms and sign-in pages have bot protection and limits on repeated attempts. Live systems report crashes and errors to us as they happen, so a fault reaches us straight away. Every connection is encrypted, and secret keys stay on the server: they are never sent to the browser.
Held in London and Dublin
The databases behind the systems we build and run are held in data centres in London and Dublin. Some services, such as sending email and taking card payments, are provided by companies that process data elsewhere. Every one of them, and where it works, is on our sub-processors list.



