Security and Data Privacy
How we ensure you and your customers' data is kept safe
Data Protection & GDPR Compliance
Bluelinemedia is fully committed to the UK GDPR law and the protection of personal data. We are registered with the Information Commissioner's Office (Reference: Z1799006), and only store personal data as necessary to manage your account. Our sub-processors (including Clook for hosting and Google for emails) are also GDPR-compliant. Read our privacy policy.
Website & Application Security
We believe that security should be "built-in" by default. Our bespoke development approach provides a higher level of protection than standard off-the-shelf platforms, and is much less likely to be a target. Some features include:
- Encrypted Passwords: Using industry-standard hashing.
- Obfuscated Data Fields: To protect sensitive information within databases.
- IP Restrictions: Limiting backend access to authorised locations.
- Two-Factor Authentication (2FA): Available for administrative access.
- Penetration Testing: Our core software framework has been successfully penetration tested by Deloitte to ensure it meets high-level security standards.
Infrastructure & Hosting
Our hosting environment is designed for resilience and protection. We recommend our secure hosting partner Clook, which provides:
- Mirrored Servers: Ensuring data redundancy and uptime.
- DBS Accredited Staff: High-level vetting for all data centre personnel.
- Physical Security: 24/7 monitoring and restricted access to server hardware.
SSL/HTTPS: We provide and manage secure certificates (SSL) to ensure all data transmitted between users and your website is encrypted and shows the "green padlock" in browsers.
Internal Operational Security
We maintain strict internal protocols to ensure your data never leaves a secure environment.
- Network Security: All local computers and server access details are protected by secure passwords.
- No Offsite Data: We have a strict policy that no personal data (electronic or hard copy) is taken offsite from our registered Cheltenham office.
- Staff Awareness: All staff members undergo regular reviews of our privacy commitments and internal security processes.
Incident Response & Your Rights
In the event of a security concern, we act transparently and quickly.
- Breach Protocol: If a security breach occurs that risks individual rights and freedoms, we will notify the ICO and affected individuals within 72 hours.
- Information Audits: We conduct regular audits to identify data flows and potential risks, refining our processes as the regulatory landscape changes.
- Exercising Your Rights: You have the right to access, rectify, or erase your data. For any data-related requests or complaints, contact us at: privacy@bluelinemedia.co.uk.
Read our privacy policy in full.