How we protect your data
We agree the security controls your website or web application needs before we build it. Hosting, access, backups, testing and ongoing updates are documented in your project and support agreements.
Built in, from day one. Controls agreed for your project and hosting arrangement
Data protection. How we meet UK GDPR
Niletech Ltd is registered with the ICO under C1385586. When we process personal data on your behalf, we agree responsibilities and sign a data processing agreement.
- Data processing agreement on every project
- Records of processing kept up to date
- Incident reporting and notification times agreed in your contract
- Data returned or deleted at the end of a contract
- No use of your data to train public AI models
Standards we work to. Recognised standards and guidance we build against
Security questions
Where is our data hosted?
In UK or EU data centres from established providers, chosen to match your policies. The provider and location are named in your agreement.
Can we run a penetration test?
Yes. You can commission your own penetration test at any time, and we will help plan it and fix anything it finds. We can also arrange an independent test for you, at extra cost.
Do you sign a data processing agreement?
Yes. When we handle personal data on your behalf, UK GDPR requires a written contract between us. We sign a data processing agreement on every project.
How do you report a vulnerability?
Email hello@niletech.co.uk. We acknowledge reports within one working day.
Are you Cyber Essentials certified?
Niletech is currently working towards Cyber Essentials certification, the UK government-backed scheme that helps organisations protect themselves against common cyber threats. Certification is pending, and our security practices are being reviewed as part of the assessment process.
Need our security documents?
We’ll send policies and completed questionnaires within two working days.