We take your privacy seriously. This policy explains what data we collect, how we use it, and your rights under UK GDPR.
Jump to any section of this policy.
Praesova Ltd ("Praesova", "we", "us", "our") is the data controller responsible for your personal data. We operate a two-sided marketplace connecting SIA-licensed security professionals with clients who require security services across the United Kingdom.
We are registered with the Information Commissioner's Office (ICO) under registration number ZB123456. Our registered office is:
Praesova Ltd, 12 Victoria Street, London, EC1A 1BB, United Kingdom
This policy applies to all users of the Praesova platform, including security professionals ("Professionals") and organisations or individuals hiring security staff ("Clients").
The data we collect depends on whether you are a Professional or a Client, and how you interact with our platform.
For Security Professionals:
For Clients:
For Training Enquiries:
Automatically collected data (all users):
SIA licence details entered by professionals (licence type, number, and dates) are stored securely and displayed on their public profile. This information is self-declared. We do not collect or store licence photographs.
| Purpose | Description | Applies To |
|---|---|---|
| Account creation & authentication | Creating and managing your account, verifying your identity, maintaining session security | All users |
| SIA licence display | Storing and displaying self-declared SIA licence details on professional profiles | Professionals |
| Marketplace operation | Enabling job postings, anonymous bid submission, shortlisting, and hiring workflows | All users |
| Anonymous bidding | Presenting your profile to clients without revealing your identity until shortlisted | Professionals |
| Payment processing | Processing platform fees and payments via our third-party payment provider | All users |
| Platform safety | Detecting fraud, abuse, or misuse of the platform and enforcing our terms of service | All users |
| Communications | Sending transactional emails (bid updates, job confirmations, account notifications) | All users |
| Platform improvement | Analysing usage patterns to improve features and user experience (anonymised where possible) | All users |
| Training enquiry processing | Forwarding your contact details to the relevant training provider when you submit a course application through our platform, with your explicit consent | Course applicants |
| Legal compliance | Maintaining records required by law, responding to legal requests | All users |
We do not use your data for automated decision-making that produces legal or similarly significant effects without human review.
Under UK GDPR, we must have a valid legal basis for each processing activity. We rely on the following:
We do not sell your personal data. We share data only where necessary and with appropriate safeguards in place.
| Recipient | Purpose | Safeguards |
|---|---|---|
| Clients (anonymised) | Clients see anonymised Professional profiles when reviewing bids. Identity revealed only on shortlisting and with Professional awareness. | Contractual controls; identity locked by default |
| Payment processor | Processing platform fees and paying Professionals | PCI DSS compliant; Data Processing Agreement in place |
| Cloud hosting provider | Storing platform data securely | UK/EEA data residency; ISO 27001 certified |
| Email service provider | Sending transactional notifications | Data Processing Agreement; limited to transactional use |
| SIA register (public) | Professionals may self-verify their own details via the SIA public register | Not accessed by Praesova; user-directed only |
| Training providers | Passing your name, email address, and phone number to the specific training provider you apply to, so they can process your course enquiry and contact you | Your explicit consent given at point of application; providers are contractually prohibited from using data for any other purpose |
| Law enforcement / regulators | Responding to lawful requests or court orders | Only where legally required; minimum data disclosed |
We do not transfer personal data outside the UK or EEA without appropriate safeguards (Standard Contractual Clauses or UK adequacy decisions).
We retain data only for as long as necessary for the purposes described in this policy, or as required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| Active account data | Duration of account + 2 years | Service provision and dispute resolution |
| SIA licence details | Duration of account | Displayed on profile; deleted when account closes |
| Bid and job records | 6 years after completion | Legal and financial record-keeping requirements |
| Payment records | 7 years | HMRC / tax compliance |
| Security & audit logs | 12 months | Fraud detection and incident investigation |
| Training enquiry data | 90 days from submission | Sufficient time for the training provider to respond; deleted thereafter |
| Deleted account data | 30 days (then purged) | Grace period for accidental deletion requests |
When data is no longer required, it is securely deleted or anonymised. You can request deletion at any time subject to our legal retention obligations — see Your Rights.
We implement technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay, as required by UK GDPR Article 33/34.
We use cookies and similar technologies to operate the platform and improve your experience.
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Strictly necessary | Authentication sessions, CSRF protection, load balancing | No — essential to service |
| Functional | Remembering preferences (filters, dark mode, language) | No — legitimate interest |
| Analytics | Understanding how pages are used (anonymised aggregates) | Yes — opt-in consent |
| Marketing | We do not use marketing or third-party advertising cookies | N/A — not used |
You can manage cookie preferences via your browser settings. Disabling strictly necessary cookies will impair your ability to use the platform.
You have significant rights over your personal data. We will respond to all requests within one calendar month.
How to complain: If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We would welcome the chance to resolve any concerns directly before you contact the ICO.
If you have any questions about this privacy policy, want to exercise your rights, or have a concern about how we handle your data, please contact our Data Protection Officer directly.
We aim to respond to all privacy requests within 5 business days and to resolve them fully within one calendar month as required by UK GDPR.
For Subject Access Requests, please include sufficient information to verify your identity and specify what data you are requesting.
Your privacy is protected from the moment you sign up. Create your account today and take control of your security career or find verified staff.