Privacy Policy

Keeping Your Data Safe

How we use and protect your information

Understand your Privacy Rights
You might also want to read...

 

Effective Date: September 30, 2025
Last Updated: July 14, 2026

This Privacy Policy explains how Negative PID collects, uses, and protects personal data when you visit or interact with our website.

It applies to all users of our website, including visitors, customers, and individuals who submit information through online forms or contact methods.

This policy also explains your rights under applicable data protection laws, including the General Data Protection Regulation (GDPR).

In most website interactions and service enquiries, Negative PID acts as a Data Controller because we determine why and how personal data is processed.

Where we provide services on behalf of a customer that involve processing personal data according to their instructions, we may act as a Data Processor. In such cases, the applicable contractual arrangements will define the responsibilities of each party.

If you have any questions about this policy or how your data is handled, you can contact us using the details provided in Section 13.

We may collect and process the following categories of personal data:

3.1 - Information you provide directly
  • Name and contact details (e.g. email address, phone number)
  • Information submitted via contact forms or enquiry forms
  • Messages or communications sent through the website
  • Any additional information you voluntarily provide
3.1.1 - Consultation and quote requests

When you request a consultation, quotation, or service proposal, we process the information provided to:

  • understand your requirements;
  • determine the appropriate service scope;
  • assess whether we can provide the requested assistance;
  • prepare quotations, proposals, or agreements;
  • communicate with you before and after service delivery.

Information provided during an enquiry does not create a customer relationship unless you choose to proceed with our services.

3.1.2 - Information submitted through forms or online assessments

Depending on the service requested, we may collect additional information submitted voluntarily through our online forms, including:

  • business name and organisation details;
  • job title or professional role;
  • information about your organisation's activities, systems, processes, and compliance requirements;
  • details relating to cybersecurity concerns, suspected fraud, digital investigations, or other requested services;
  • responses provided through GDPR self-assessment questionnaires and readiness assessments;
  • information required to prepare quotations, proposals, or service agreements.

Please avoid submitting unnecessary personal information relating to third parties unless it is required for the provision of the requested service.

3.1.2.1 Information you should not submit

When using our website forms, please provide only information necessary for your enquiry or requested service.

You should avoid submitting:

  • unnecessary personal information about other individuals;
  • passwords or authentication credentials;
  • confidential information unrelated to your request;
  • sensitive personal data unless specifically requested and necessary for the service.

If you provide information relating to another individual, you are responsible for ensuring that you have an appropriate lawful basis for sharing that information with us.

3.1.3 - Information provided for investigations or security consultations

Due to the nature of our services, customers may voluntarily provide information relating to security incidents, suspected fraud, online impersonation, digital assets, websites, systems, or other technical matters.

Customers should only provide information necessary for the requested service and should avoid submitting unnecessary personal information about third parties.

Where information relating to third parties is provided, the customer remains responsible for ensuring they have appropriate authority or lawful basis for sharing that information.

3.2 - Children's data

Our services are intended for adults and we do not knowingly collect personal data from children.

If you believe that we have collected personal data relating to a child without appropriate authorisation, please contact us so that we can review and take appropriate action.

3.3 - Marketing communications

We may use contact information provided voluntarily to send information about our services where permitted by applicable law.

You may unsubscribe from marketing communications at any time by following the instructions provided or contacting us directly.

We do not sell or rent personal data for marketing purposes.

3.4 - Business and professional information

When interacting with us as a business customer, supplier, partner, or professional contact, we may process business contact information such as:

  • name;
  • job title;
  • organisation;
  • business email address;
  • professional communications.

This information is processed to manage business relationships, provide services, and communicate regarding contractual matters.

3.5 - Technical Information
  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Pages visited and time spent on the website
  • Referring website or source
3.6 - Cookies and Similar Technologies

We may use cookies and similar technologies to:

  • Ensure the website functions correctly;
  • Analyse website usage;
  • Improve user experience.

Details of the cookies and tracking technologies used on this website are described in our Cookie Policy and managed through our cookie consent mechanism where required.

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

These measures may include:

  • access controls and authentication measures;
  • secure communication channels;
  • secure cloud services;
  • software updates and security monitoring;
  • data minimisation practices;
  • confidentiality obligations for persons with access to personal data.

While we take reasonable steps to protect personal data, no internet-based service can guarantee absolute security.

We use personal data collected via our website to:

  • Respond to enquiries and requests;
  • Provide information about our services;
  • Manage customer or business relationships;
  • Improve website performance and user experience;
  • Monitor website security and prevent misuse;
  • Comply with legal obligations.
5.1 - GDPR self-assessment and compliance services

Where you use our GDPR self-assessment tools, questionnaires, or compliance services, we process the information you provide to:

  • generate assessment results;
  • identify potential compliance gaps;
  • prepare recommendations;
  • provide requested consultancy services;
  • communicate with you regarding your assessment.

Information submitted through self-assessment forms may include details about your organisation's data processing activities, systems, suppliers, policies, and security practices.

We do not use assessment responses for unrelated purposes, marketing profiling, or sale to third parties.

Where a self-assessment service is provided without account creation or ongoing access, submitted information may only be retained for the period necessary to provide the service and maintain appropriate business records.

5.2 - Automated decision-making and profiling

Negative PID does not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.

We process personal data collected through our website under one or more of the following legal bases:

  • Legitimate interests – to operate, secure, and improve our website and services;
  • Contractual necessity – where processing is required to respond to enquiries or take steps prior to entering into a contract;
  • Legal obligation – where required by applicable law;
  • Consent – where cookies or specific tracking technologies require consent.

We retain personal data collected via the website only for as long as necessary to:

  • Respond to enquiries;
  • Manage ongoing communication;
  • Meet legal, accounting, or operational requirements.

Data collected via contact forms or enquiries is typically retained for a limited period of time unless it leads to a customer or supplier relationship.

Data typeRetention approach
Website enquiriesUntil resolved + limited follow-up period
Quote requestsAccording to quotation/business record requirements
GDPR assessment submissionsAccording to the specific service terms and retention notice
Customer recordsAs required for contractual, accounting, and legal obligations
Security/investigation case dataAccording to engagement terms

Where cookies or similar technologies are used, they may be categorised as:

  • Strictly necessary cookies – required for website functionality;
  • Analytics cookies – used to understand how visitors use the website;
  • Functional cookies – used to improve user experience.

Where required by law, users will be given the option to accept or reject non-essential cookies.

We may share personal data with trusted service providers that support our operations, including:

  • website hosting and infrastructure providers;
  • secure email and communication providers;
  • payment processors;
  • accounting and invoicing providers;
  • electronic signature providers;
  • cloud storage providers;
  • cybersecurity and website security providers.

All third-party providers are required to handle personal data securely and in accordance with applicable data protection laws.

Negative PID operates from the European Union and uses service providers that may process personal data in different jurisdictions.

Our website hosting infrastructure is provided by a service provider located in Switzerland. Switzerland is recognised by the European Commission as providing an adequate level of data protection under applicable EU data protection legislation.

Other service providers used to support our operations may process personal data in countries outside the European Economic Area (EEA).

Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are implemented, such as:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses approved by the European Commission;
  • other legally recognised transfer mechanisms where applicable.

We regularly review our service providers to ensure they maintain appropriate privacy and security protections.

Some information submitted through GDPR assessment tools may be processed using secure third-party infrastructure providers. We select providers that implement appropriate privacy and security safeguards.

You have the right to:

  • Access your personal data;
  • Request correction of inaccurate data;
  • Request deletion of your data (where applicable);
  • Restrict or object to processing;
  • Withdraw consent where applicable;
  • Request data portability;
  • Lodge a complaint with a supervisory authority.

If you have any questions about this Privacy Notice or wish to exercise your rights, you can contact:

Negative PID SL
Email: privacy@negativepid.com
Website: https://negativepid.com

We may update this Privacy Policy from time to time to reflect changes in website functionality, legal requirements, or business practices.

The most recent version will always be published on this page.

Secret Link

Request a quote or consultation

Use this form to provide some basic information about the nature of your request.

By submitting this form you are NOT committing to purchase any services. 

If you have any difficulties filling in the form, please contact us at info@negativepid.com.


Negative PID
Privacy Overview

Please refer to our Privacy Policy.