Data protection
Privacy Policy
Your privacy and security are fundamental principles for us. This policy explains who processes your personal data, for what purpose, for how long and how you can exercise your rights.
Controller
Your data will be processed by:
B10SEC CYBERSECURITY AND DATA PROTECTION LIMITED (HQ)
- Company number 14722219
- Staverton Court, Staverton, Cheltenham, Gloucestershire, United Kingdom, GL51 0UX
B10SEC Proteção de Dados e Cibersegurança Ltda.
- CNPJ 38.215.361/0001-28
- São Paulo, SP
- Controller for data subjects in Brazil, under the LGPD (Brazilian General Data Protection Law, Lei 13.709/2018)
BTEENSEC Cibersegurança e Proteção de Dados Lda
- NIF 514.789.484
- Sintra, Portugal
You may contact us and our data protection officer by email at dpo@b10sec.pt or through the following form, data subject rights request.
Collection of personal data
| Source of collection | Purpose | Legal basis | Personal data | Data retention period |
|---|---|---|---|---|
| Website / Email / Social media | Commercial communications | Consent | Full name Telephone | 12 months |
| Email rh@b10sec.pt | Talent management | Consent | Full name Telephone Other information provided in the CV | 12 months |
| Website | Analysis of access statistics | Consent | IP address | 12 months |
| Email / Internal systems | Project delivery | Contract | Full name Telephone Other information required to carry out the project | Term of the contract |
| Email / Internal systems | Project invoicing | Legal obligation | Full name Telephone Other information required by law | During the term of the contract and, after the contract ends, stored for a further 10 years |
| Website / Email | Delivery of the free training | Consent | Name | 12 months |
| Website / Email | Delivery of the Amigo Ciberseguro initiative | Consent | Name | 12 months |
| Website / Email / Social media | IO Leak Data Monitor · Commercial communications | Consent | Name | 12 months |
| Email / Internal systems | IO Leak Data Monitor · Monitoring | Contract | Full name Telephone Other information required to carry out the monitoring | Term of the contract |
Retention period
The period for which your personal data is stored and retained varies according to the purpose for which the data was collected, as set out in the table in the "Collection of personal data" section.
Secure processing and storage
Our obligation is to keep your data secure by applying appropriate cyber security measures to ensure the protection of your personal data and prevent access by unauthorised persons. We apply cyber security and data protection best practices, such as:
- Compliance with cyber security and data protection laws, regulations and best practices
- Enterprise risk management
- Cyber security and privacy maturity management
- Business continuity management
- Digital fraud management
- Secure configuration management
- Patch management
- Vulnerability management
- Cyber and privacy incident management
- IAM (Identity Access Management)
- Secure development management
- Physical security management
- Data management
- Threat monitoring
- Employee awareness programme
- Security & Privacy Supply Chain
- Threat Intelligence
Data lifecycle in the free initiatives
Applies to registrations for the Amigo Ciberseguro initiative and the free training.
Collection
- Source of collection: B10SEC website
- Data collected: Name and email
- Legal basis: Consent
- Purpose: To register for the Amigo Ciberseguro initiative and/or the free training
Storage
Data stored in the Google GCP environment, on servers located in a datacentre in Europe.
Processing
Data is processed and stored securely, applying practices defined by ENISA, NIST, CSF, CERT RMM, ISO 27001:2013 and ISO 27701:2019, among other good practices.
Sharing
Personal data is not shared with third parties, except with the service providers acting on our behalf listed in the "Sharing of personal data" section.
The initiatives' supporters only have access to the names of the participating Organisations.
Deletion
After the 12-month period, the data will be deleted automatically if the data subject does not renew their consent to the processing of the data.
Sharing of personal data
We only send data to third parties without your consent where this is required by law or by a judicial authority.
However, your personal data may be processed by service providers acting on our behalf, namely marketing and digital and social media agencies, accounting services, auditors and lawyers, and external entities such as SaaS platform providers, hosting and maintenance services.
Some of these providers are headquartered outside the EEA, which involves an international transfer of your data. However, we always put in place the necessary safeguards to ensure your data is processed securely, through contracts containing contractual clauses and the application of security controls defined by data protection and cyber security best practices, as described in the "Secure processing and storage" section.
Delivery of website form messages
Messages sent through the forms on this website are delivered to our team by email via Resend (Plus Five Five, Inc., San Francisco, United States), which acts as a processor on our behalf. Resend processes only the data entered in the form (such as name, email, company and message), for the sole purpose of delivering the message, and stores this data in the United States.
This international transfer is protected by the Standard Contractual Clauses approved by the European Commission, the UK Addendum and Resend's participation in the EU-U.S. Data Privacy Framework.
Your rights
As a data subject, you may exercise the following rights, within the limits established by law:
- Right of access to your personal data, to know which data is being processed and the processing operations carried out on your personal data;
- Right to rectification of any of your personal data that is inaccurate or out of date;
- Right to erasure of your personal data;
- Right to object, that is, to request that your personal data not be processed, on grounds relating to your particular situation;
- Right to withdraw your consent at any time, where consent was the legal basis for processing your data;
- Right to request restriction of processing of your personal data in the following cases:
- Where you contest the accuracy of your data, for a period enabling B10SEC to verify its accuracy.
- Where the processing of certain data is unlawful and you oppose the erasure of the data, requesting instead the restriction of its use.
- Where B10SEC no longer needs to process your data, but you require it for the establishment, exercise or defence of a right in legal proceedings.
- Where you have objected to the processing of your data carried out by B10SEC on the basis of legitimate interests, pending verification of whether the legitimate interests invoked override the grounds invoked by the data subject.
- Right to data portability, that is, to receive the personal data you have provided in a structured, commonly used and machine-readable format, and to transmit it to another controller.
To exercise these rights, you may send a written request to the contact details given in the "Controller" section, or use the data subject rights request.
To exercise your rights, you must state in your request your name and the right you are exercising.
Updates to the privacy policy
B10SEC reserves the right to make changes or updates to this Privacy Policy at any time, and such changes will be duly updated on the website https://b10sec.com.
We suggest that you consult it regularly to stay informed of any changes.
Updated on 25 September 2026.