Protection Research

Privacy Policy

Effective Date: 3 August 2026

Contents

  • Introduction
  • Who We Are
  • Scope of this Privacy Policy
  • Personal Data We Collect
  • How We Collect Personal Data
  • Lawful Bases for Processing
  • How We Use Personal Data
  • Sharing Personal Data
  • International Transfers
  • Data Security
  • Data Retention
  • Your Rights
  • Cookies and Similar Technologies
  • Third-Party Websites
  • Children's Privacy
  • Changes to this Privacy Policy
  • Contact Us
  • Complaints

1. Introduction

Protection Research Ltd ("Protection Research", "we", "our" or "us") is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, disclose and otherwise process personal data when you: visit our website; create an account; purchase or use our Services; communicate with us; subscribe to newsletters or marketing communications; engage with our research or publications; or otherwise interact with Protection Research. We process personal data in accordance with: the UK General Data Protection Regulation (UK GDPR); the Data Protection Act 2018; and any other applicable data protection legislation. Please read this Privacy Policy carefully so that you understand how your personal data is handled.

2. Who We Are

Protection Research Ltd is the data controller responsible for personal data processed under this Privacy Policy, except where we act solely as a processor on behalf of our business customers.

Company Name

Protection Research Ltd

Company Number

  • 17366537
  • Registered Office

41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG

Email

support@protectionresearch.com Where we process personal data on behalf of a customer, that processing is governed by our Data Processing Agreement and the instructions of the relevant customer.

3. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed through:

  • our websites
  • customer accounts
  • subscription services
  • customer support
  • email correspondence
  • research publications
  • software applications
  • online portals
  • events and webinars
  • surveys and feedback
  • marketing activities; and

any other services operated by Protection Research. This Privacy Policy does not apply to third-party websites or services that may be linked from our website. Those services operate under their own privacy policies, which you should review separately.

4. Personal Data We Collect

Depending upon how you interact with us, we may collect the following categories of personal data.

Identity Information

  • This may include:
  • name
  • job title
  • employer
  • organisation name

business contact details.

Contact Information

  • Including:
  • business email address
  • telephone number

correspondence address.

Account Information

  • Including:
  • username
  • encrypted password
  • account preferences
  • subscription status

authentication information.

Payment Information

Where applicable, we may receive limited payment information relating to subscriptions. Payment card information is processed directly by our third-party payment providers. Protection Research does not store full payment card details.

Technical Information

Including:

IP address;

  • browser type
  • operating system
  • device identifiers
  • session information
  • diagnostic logs

security logs.

Usage Information

  • Including:
  • pages visited
  • research viewed
  • searches performed
  • downloads
  • feature usage
  • login history

account activity.

Communications

  • Including:
  • emails
  • customer support requests
  • survey responses
  • feedback

correspondence.

Marketing Preferences

Including your communication preferences and subscription choices.

5. How We Collect Personal Data

We collect personal data in several ways.

Information You Provide

  • You may provide personal data when you:
  • register an account
  • purchase a subscription
  • contact support
  • subscribe to communications
  • complete forms
  • provide feedback

participate in surveys or events.

Automatically Collected Information

  • We automatically collect certain technical information through:
  • cookies
  • server logs
  • analytics technologies
  • authentication systems

security monitoring tools. Further information is provided in our Cookie Policy.

Information from Third Parties

  • We may receive information from:
  • payment providers
  • identity verification services
  • analytics providers
  • business partners
  • publicly available business sources

lawful third-party data providers. Where appropriate, we take reasonable steps to ensure such information has been obtained lawfully.

6. Lawful Bases for Processing

Protection Research processes personal data only where we have a lawful basis to do so under the UK General Data Protection Regulation (UK GDPR). Depending on the circumstances, we may rely upon one or more of the following lawful bases.

Performance of a Contract

  • We process personal data where it is necessary to:
  • create and administer customer accounts
  • provide subscription services
  • process payments
  • authenticate users
  • provide customer support
  • deliver research and publications
  • manage renewals and cancellations; and

perform our contractual obligations.

Legitimate Interests

We may process personal data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.

These legitimate interests include:

  • improving our Services
  • protecting our systems from fraud and cyber threats
  • maintaining network and information security
  • understanding how customers use our Services
  • developing new products and features
  • responding to enquiries
  • managing our business operations
  • enforcing our contractual rights; and

defending legal claims.

Legal Obligations

We may process personal data where necessary to comply with legal or regulatory obligations, including obligations relating to taxation, accounting, fraud prevention, law enforcement requests and regulatory compliance.

Consent

Where required by law, we will obtain consent before processing personal data for specific purposes, such as certain marketing communications or the use of non-essential cookies. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

7. How We Use Personal Data

Protection Research uses personal data only for legitimate business purposes.

These purposes include:

  • providing our Services
  • managing customer accounts
  • authenticating users
  • processing subscription payments
  • providing technical support
  • communicating with customers
  • responding to enquiries
  • maintaining system security
  • detecting fraud and abuse
  • monitoring service performance
  • conducting analytics
  • improving our Services
  • complying with legal obligations
  • protecting our legal rights
  • maintaining business records; and

sending service-related communications. Where permitted by Applicable Law, we may also use business contact information to send information about: product updates; new research; service announcements; security notifications; webinars; events; and other business communications relevant to our Services. Recipients may opt out of non-essential marketing communications at any time using the unsubscribe mechanism provided or by contacting us directly.

8. Sharing Personal Data

Protection Research does not sell personal data. We share personal data only where necessary to operate our business, provide the Services or comply with legal obligations.

Recipients may include:

Service Providers

  • Including providers of:
  • cloud hosting
  • payment processing
  • email delivery
  • customer support systems
  • analytics
  • authentication services
  • security monitoring

infrastructure services. All service providers are required to process personal data only on our instructions where applicable and to implement appropriate security measures.

Professional Advisers

  • Including:
  • solicitors
  • accountants
  • auditors
  • insurers; and

other professional advisers where necessary.

Regulators and Public Authorities

We may disclose personal data where required by:

Applicable Law;

  • court order
  • regulatory investigation
  • lawful request from law enforcement; or

other competent public authority.

Business Transactions

  • Where Protection Research is involved in:
  • a merger
  • acquisition
  • investment
  • restructuring; or
  • sale of all or substantially all of its assets,

personal data may be disclosed where reasonably necessary and subject to appropriate confidentiality protections.

9. International Transfers

Protection Research primarily stores and processes personal data within the United Kingdom. Where personal data is transferred outside the UK, we will ensure that appropriate safeguards are implemented in accordance with Applicable Data Protection Law.

Such safeguards may include:

UK International Data Transfer Agreements (IDTAs);

  • the UK Addendum to the European Commission's Standard Contractual Clauses
  • adequacy regulations recognised by the UK Government; or

any other lawful transfer mechanism recognised under Applicable Law. We take reasonable steps to ensure that recipients outside the UK provide an adequate level of protection for personal data.

10. Data Security

Protection Research maintains appropriate technical and organisational measures designed to protect personal data against accidental or unlawful: destruction; loss; alteration; unauthorised disclosure; and unauthorised access. Our security measures may include: encryption in transit where appropriate; encrypted password storage; role-based access controls; multi-factor authentication where implemented; security monitoring; vulnerability management; secure development practices; audit logging; regular software updates; and staff awareness of information security responsibilities. Despite these measures, no method of electronic transmission or storage can be guaranteed to be completely secure. Accordingly, while Protection Research takes reasonable steps to protect personal data, we cannot guarantee absolute security. Where Protection Research becomes aware of a personal data breach, we will respond in accordance with Applicable Data Protection Law, including notifying the relevant supervisory authority and affected individuals where legally required.

11. Data Retention

Protection Research retains personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, regulatory, accounting and contractual obligations. The length of time we retain personal data depends on the nature of the information and the purpose for which it is processed.

Examples include:

account and profile information, which is generally retained for the life of the account and for a reasonable period after closure to allow reactivation, dispute resolution and security investigations; subscription and billing records, which are generally retained for up to six (6) years (or longer where required for tax, accounting or legal purposes); customer support correspondence, which is generally retained for up to two (2) years after the relevant matter is closed unless a longer period is required; security, authentication and diagnostic logs, which are generally retained for shorter operational periods appropriate to security monitoring and incident investigation; and marketing preference records, which are retained until you unsubscribe or otherwise ask us to stop processing them for that purpose, subject to any residual records needed to honour that request. Where retention is no longer necessary, personal data will be securely deleted, anonymised or otherwise disposed of in accordance with our internal data retention procedures. Where required by law, Protection Research may retain certain information for longer periods.

12. Your Rights

Individuals may have various rights under Applicable Data Protection Law, subject to applicable exemptions.

These rights may include the right to:

  • request access to personal data
  • request correction of inaccurate personal data
  • request deletion of personal data in certain circumstances
  • request restriction of processing
  • object to certain processing activities
  • request transfer of personal data where applicable (data portability)
  • withdraw consent where processing is based upon consent; and

not be subject solely to automated decision-making where such rights apply. Protection Research does not routinely make decisions based solely on automated processing that produce legal or similarly significant effects. Requests relating to data protection rights should be submitted using the contact details provided below. We may request additional information to verify the identity of the requester before responding. Protection Research will respond to valid requests within the time limits required by Applicable Data Protection Law. Where a request is manifestly unfounded or excessive, we reserve the right to refuse the request or charge a reasonable administrative fee where permitted by law.

13. Cookies and Similar Technologies

Our websites and Services use cookies and similar technologies to improve functionality, maintain security and better understand how our Services are used.

Cookies may be used to:

  • remember user preferences
  • maintain authenticated sessions
  • improve website performance
  • collect usage analytics
  • protect against fraud and abuse; and

support the operation of our Services. Where required by law, we will obtain consent before placing non-essential cookies on your device. We do not currently display a cookie consent banner. You may manage cookies through your browser settings or other available privacy controls. Further information is available in our separate Cookie Policy.

14. Third-Party Websites

Our website or Services may contain links to third-party websites, products or services. Protection Research does not control those third-party websites and is not responsible for: their privacy practices; their security; their content; or their availability. Users should review the privacy policies of any third-party websites they visit before providing personal data. The inclusion of a third-party link does not constitute an endorsement or recommendation unless expressly stated.

15. Children's Privacy

Protection Research provides business-to-business services intended for organisations and professionals. Our Services are not directed towards children. We do not knowingly collect personal data from children. If we become aware that personal data relating to a child has been collected inadvertently, we will take reasonable steps to delete that information without undue delay unless retention is required by Applicable Law. Parents, guardians or other individuals who believe that a child has provided personal data should contact us using the details provided in this Privacy Policy.

16. Changes to this Privacy Policy

Protection Research may update this Privacy Policy from time to time to reflect: changes in Applicable Law; regulatory guidance; improvements to our Services; changes to our business operations; or developments in information security and privacy practices. The latest version will always be published on our website with the updated Effective Date. Where changes materially affect how we process personal data, we will take reasonable steps to provide appropriate notice where required by Applicable Law. Continued use of our Services after the updated Privacy Policy becomes effective constitutes acknowledgement of the revised Policy.

17. Contact Us

If you have any questions regarding this Privacy Policy or our processing of personal data, please contact:

Protection Research Ltd

Company Number: 17366537

Registered Office: 41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG

Email: support@protectionresearch.com

We will endeavour to respond to privacy-related enquiries promptly and in accordance with Applicable Data Protection Law.

18. Complaints

If you believe that Protection Research has processed your personal data unlawfully or in breach of Applicable Data Protection Law, we encourage you to contact us first so that we have an opportunity to investigate and resolve your concerns. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the United Kingdom's independent supervisory authority for data protection matters. Making a complaint to the ICO does not affect any other legal rights or remedies that may be available to you.

End of Privacy Policy

Effective Date: 3 August 2026

© Protection Research Ltd. All rights reserved.