HOLSTER holstersecurity.com
Legal

Privacy Policy

Last updated: 3 July 2026
Effective: 3 July 2026
Jurisdiction: England and Wales

Summary: Holster Cybersecurity, a Sikaverse Limited company, is the data controller for personal data you provide through this website. We collect only what we need, use it only for the purposes described here, and do not sell it. Your rights under the UK GDPR are set out in Section 8 below.

1. Who we are

Sikaverse Limited (trading as Holster Cybersecurity) is the data controller of the personal data collected through this website. We are registered in England and Wales.

References to "Holster", "we", "us", or "our" in this Privacy Policy refer to Sikaverse Limited t/a Holster Cybersecurity.

If you have any questions about how we use your personal data, please contact us at hello@holstersecurity.com.

We are registered with the Information Commissioner's Office (ICO) as a data controller. Our ICO registration details are available on the ICO Register.

2. The personal data we collect

We collect the following categories of personal data depending on how you interact with us:

CategoryData elementsSource
Contact dataName, work email address, organisation name, job titleContact form, scorecard lead forms, email correspondence
Communication dataContents of messages you send us, enquiry detailsContact form submissions
Scorecard dataResponses to readiness scorecard questions, score, risk tier, category breakdownFree assessment tool submissions (where you choose to provide contact details)
Usage dataIP address, browser type, pages visited, referring URL, time of visitServer logs and analytics (where applicable)

We do not collect any special category personal data (as defined in Article 9 of the UK GDPR) through this website, nor do we collect data relating to criminal convictions or offences.

3. How we collect your personal data

We collect personal data through the following means:

4. Why we use your personal data and our lawful bases

Under the UK GDPR, we must have a lawful basis for processing your personal data. The table below sets out the purposes for which we process your data and the corresponding lawful bases.

PurposeLawful basis (UK GDPR)
Responding to enquiries submitted through our contact formLegitimate interests (Article 6(1)(f)) — responding to prospective client enquiries is necessary for our legitimate business interests
Sending a follow-up report or consultation booking following a scorecard submissionConsent (Article 6(1)(a)) — you provide your contact details specifically to receive this communication
Managing our client relationship and delivering contracted servicesPerformance of a contract (Article 6(1)(b))
Sending relevant service information or updates where you have requested themConsent (Article 6(1)(a)) or Legitimate interests (Article 6(1)(f))
Complying with legal obligations (e.g. tax, accounting, regulatory requirements)Legal obligation (Article 6(1)(c))
Analysing website usage to improve the site and our servicesLegitimate interests (Article 6(1)(f))

Where we rely on legitimate interests as our lawful basis, we have carried out a balancing test and are satisfied that our interests do not override your rights and freedoms. You may object to processing based on legitimate interests at any time (see Section 8).

5. Who we share your personal data with

We do not sell, rent, or trade your personal data to third parties. We may share your personal data with the following categories of recipients in limited circumstances:

Any third parties who process personal data on our behalf are required to do so only on our instructions and are bound by appropriate contractual obligations, including data processing agreements where required.

6. International transfers

Formspree, our form processing provider, may process data on servers located outside the United Kingdom and European Economic Area. Where such transfers occur, they are carried out in reliance on appropriate transfer mechanisms as required by Chapter V of the UK GDPR, including the UK International Data Transfer Agreement (IDTA) or adequacy regulations made by the UK Secretary of State.

If you would like further information about the safeguards applicable to any specific transfer, please contact us at hello@holstersecurity.com.

7. How long we keep your personal data

Data typeRetention periodReason
Contact form enquiries (no subsequent engagement)12 monthsTo follow up on enquiries within a reasonable period
Scorecard submission contact details12 months from submissionTo deliver the requested follow-up and for relationship management
Client engagement records6 years from end of engagementLegal and contractual obligations, tax and accounting requirements
Email correspondence6 years from the date of the emailBusiness records, legal obligations
Server log / usage data90 daysSecurity and performance monitoring

We review and delete personal data when it is no longer required for the purpose for which it was collected or when there is no longer a lawful basis to retain it.

8. Your rights under the UK GDPR

Under the UK GDPR and the Data Protection Act 2018, you have the following rights in respect of your personal data:

To exercise any of the above rights, please contact us at hello@holstersecurity.com. We will respond within one calendar month of receiving your request. We may need to verify your identity before responding.

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

We would, however, appreciate the opportunity to address your concerns before you contact the ICO, and ask that you contact us in the first instance.

9. Cookies

This website uses cookies. Please see our Cookie Policy for detailed information about the cookies we use, why we use them, and how to manage them. We use cookies in accordance with the UK Privacy and Electronic Communications Regulations 2003 (PECR) as amended.

10. Security measures

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:

We will notify the ICO and, where required, affected individuals of any personal data breach in accordance with our obligations under Article 33 and 34 of the UK GDPR.

Please note that no method of transmission over the Internet or electronic storage is completely secure. While we take reasonable steps to protect your personal data, we cannot guarantee absolute security.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Where we make material changes, we will update the "Last updated" date at the top of this page.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal data.

12. How to contact us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact us: