Last updated: 3 August 2026

This policy explains what we do with your personal data, in plain English. It covers hiltdigital.co.uk, hiltcloud.co.uk, score.hiltdigital.uk and securityaudituk.co.uk, all of which are operated by Hilt Digital Solutions Ltd.

Who we are

Hilt Digital Solutions Ltd is the data controller for the personal data described in this policy. Security Audit UK is a trading style of Hilt Digital Solutions Ltd.

You can reach us on 0151 452 3060, or through the contact page. If you want to raise something about your data specifically, say so and it will be handled by a person rather than a form.

What we collect, and when

When you fill something in

Our sites include contact forms, quote requests and a number of self-assessment tools (scorecards). If you complete one, we collect what you type into it. Depending on the tool, that is some combination of:

  • Your name
  • Your email address
  • Your company name
  • Your phone number, if you give us one
  • Your answers to the questions the tool asks, for example how many servers you run or what your renewal date is
  • Your company’s internet domain name, if the tool you used asks for one

We do not ask for, and do not want, passwords, card details or any credentials. If you are ever asked for those by something claiming to be us, it is not us.

When you just visit

We collect information about how the site is used, so we can work out which pages are useful and which are not. This includes your approximate location (country and region, from your IP address), the device and browser you are using, which pages you looked at, how far down them you scrolled, and where you clicked.

You should know that one of the tools we use, Microsoft Clarity, records a playback of the visit itself: mouse movement, scrolling, taps and clicks. It is used to understand where pages confuse people. It masks text you type into form fields, and we do not use it to identify individuals.

Cookies and third-party tools

We use the following, and nothing else that tracks you:

If you would rather none of that happened, you can block cookies in your browser settings, or use your browser’s private mode. The sites work fine without them.

Why we are allowed to hold it

Under UK GDPR we have to have a lawful basis for processing your data. Ours are:

  • Consent, where you have filled in a form asking us to send you something, or ticked a box to hear from us. You can withdraw it at any time.
  • Legitimate interests, for running and improving our own websites, and for replying to an enquiry you started.
  • Contract, where you become a customer and we need your details to actually deliver the work.
  • Legal obligation, for things we are required to keep, such as records behind an invoice.

What we do with it

If you complete one of our tools, we send you the result and the explanation that goes with it. We may then send a small number of follow-up emails on the same subject. Every one of them has an unsubscribe link, that link works immediately, and using it does not stop you getting the thing you actually asked for.

If you ask for a quote or a call, we use your details to have that conversation.

We do not sell your data. We do not share it with, or rent it to, any third party for their own marketing. The only third parties who touch it are the technical suppliers listed in this policy, who process it on our instructions in order to run the service.

Where it lives, and for how long

Form submissions are stored in our own database, on infrastructure we control, hosted in the United Kingdom. Email is sent over our own mail server.

The analytics and advertising suppliers listed above are US-based and may process data outside the UK. Those transfers rely on the safeguards in their own terms, including the UK extension to the EU-US Data Privacy Framework and standard contractual clauses.

We keep enquiry and marketing data for 24 months from your last interaction with us, and then delete it. Customer and financial records are kept for six years after the end of the relationship, because we are required to. If you ask us to delete you sooner, we will, subject to anything we are legally obliged to retain.

Your rights

Under UK GDPR you can ask us to:

  • Tell you what we hold about you, and give you a copy
  • Correct anything that is wrong
  • Delete it
  • Stop or restrict what we do with it
  • Send it to you, or to someone else, in a portable format
  • Stop using it for marketing, which we will action immediately and without argument

Ask through the contact page or on 0151 452 3060. We will respond within one month, and there is no charge.

If you are not happy with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, or on 0303 123 1113. We would rather you came to us first, but it is your right either way.

Children

Our services are sold to businesses. We do not knowingly collect data from anyone under 18. If you believe we have, tell us and we will delete it.

Changes to this policy

If we change how we use personal data, we will update this page and change the date at the top.