Effective Date: September 30, 2025
Last Updated: July 14, 2026
This Privacy Policy explains how Negative PID collects, uses, and protects personal data when you visit or interact with our website.
It applies to all users of our website, including visitors, customers, and individuals who submit information through online forms or contact methods.
This policy also explains your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR).
In most website interactions and service enquiries, Negative PID acts as a Data Controller because we determine why and how personal data is processed.
Where we provide services on behalf of a customer that involve processing personal data according to their instructions, we may act as a Data Processor. In such cases, the applicable contractual arrangements will define the responsibilities of each party.
If you have any questions about this policy or how your data is handled, you can contact us using the details provided in Section 13.
We may collect and process the following categories of personal data:
When you request a consultation, quotation, or service proposal, we process the information provided to:
Information provided during an enquiry does not create a customer relationship unless you choose to proceed with our services.
Depending on the service requested, we may collect additional information submitted voluntarily through our online forms, including:
Please avoid submitting unnecessary personal information relating to third parties unless it is required for the provision of the requested service.
When using our website forms, please provide only information necessary for your enquiry or requested service.
You should avoid submitting:
If you provide information relating to another individual, you are responsible for ensuring that you have an appropriate lawful basis for sharing that information with us.
Due to the nature of our services, customers may voluntarily provide information relating to security incidents, suspected fraud, online impersonation, digital assets, websites, systems, or other technical matters.
Customers should only provide information necessary for the requested service and should avoid submitting unnecessary personal information about third parties.
Where information relating to third parties is provided, the customer remains responsible for ensuring they have appropriate authority or lawful basis for sharing that information.
Our services are intended for adults and we do not knowingly collect personal data from children.
If you believe that we have collected personal data relating to a child without appropriate authorisation, please contact us so that we can review and take appropriate action.
We may use contact information provided voluntarily to send information about our services where permitted by applicable law.
You may unsubscribe from marketing communications at any time by following the instructions provided or contacting us directly.
We do not sell or rent personal data for marketing purposes.
When interacting with us as a business customer, supplier, partner, or professional contact, we may process business contact information such as:
This information is processed to manage business relationships, provide services, and communicate regarding contractual matters.
We may use cookies and similar technologies to:
Details of the cookies and tracking technologies used on this website are described in our Cookie Policy and managed through our cookie consent mechanism where required.
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures may include:
While we take reasonable steps to protect personal data, no internet-based service can guarantee absolute security.
We use personal data collected via our website to:
Where you use our GDPR self-assessment tools, questionnaires, or compliance services, we process the information you provide to:
Information submitted through self-assessment forms may include details about your organisation's data processing activities, systems, suppliers, policies, and security practices.
We do not use assessment responses for unrelated purposes, marketing profiling, or sale to third parties.
Where a self-assessment service is provided without account creation or ongoing access, submitted information may only be retained for the period necessary to provide the service and maintain appropriate business records.
Negative PID does not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.
We process personal data collected through our website under one or more of the following legal bases:
We retain personal data collected via the website only for as long as necessary to:
Data collected via contact forms or enquiries is typically retained for a limited period of time unless it leads to a customer or supplier relationship.
| Data type | Retention approach |
|---|---|
| Website enquiries | Until resolved + limited follow-up period |
| Quote requests | According to quotation/business record requirements |
| GDPR assessment submissions | According to the specific service terms and retention notice |
| Customer records | As required for contractual, accounting, and legal obligations |
| Security/investigation case data | According to engagement terms |
Where cookies or similar technologies are used, they may be categorised as:
Where required by law, users will be given the option to accept or reject non-essential cookies.
We may share personal data with trusted service providers that support our operations, including:
All third-party providers are required to handle personal data securely and in accordance with applicable data protection laws.
Negative PID operates from the European Union and uses service providers that may process personal data in different jurisdictions.
Our website hosting infrastructure is provided by a service provider located in Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection under applicable EU data protection legislation.
Other service providers used to support our operations may process personal data in countries outside the European Economic Area (EEA).
Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are implemented, such as:
We regularly review our service providers to ensure they maintain appropriate privacy and security protections.
Some information submitted through GDPR assessment tools may be processed using secure third-party infrastructure providers. We select providers that implement appropriate privacy and security safeguards.
You have the right to:
If you have any questions about this Privacy Notice or wish to exercise your rights, you can contact:
Negative PID SL
Email: privacy@negativepid.com
Website: https://negativepid.com
We may update this Privacy Policy from time to time to reflect changes in website functionality, legal requirements, or business practices.
The most recent version will always be published on this page.
Use this form to provide some basic information about the nature of your request.
By submitting this form you are NOT committing to purchase any services.
If you have any difficulties filling in the form, please contact us at info@negativepid.com.