Privacy Notice
The personal-data controls operated by WESTPORT CYBER LIMITED, trading as Lagan Cyber, set out the way a controls register sets them out: one numbered entry per control, each naming what is required, how it runs, which record proves it, and who answers for it.
How to read an entry
Four fields follow every heading below. Control is the commitment itself. Implementation is how it runs in practice. Evidence kept names the artefact an assessor could ask for. Owner names the role that answers for it. Assessors read a policy by looking for those four things, so they are stated instead of implied — the same shape the product puts around a customer’s own controls.
The tag beside each heading fixes the role. A Controller entry covers data this company decides about, mainly people who read the site, write to us, or sign in. A Processor entry covers what a customer places in the platform, where the customer decides and this company acts on written instruction; there, an individual’s relationship runs through their own employer. An entry tagged both operates identically on either side of that line.
References are to UK GDPR and the Data Protection Act 2018. Entry numbers are stable, so PRV-14 means the same thing in correspondence as it does here.
PRV-01 Identity of the entity behind this register Controller & processor
An assessor’s first question about any register is whose it is. One company operates every entry that follows.
PRV-01
Controller & processor
Control
The entity accountable for personal data reaching this website and the Lagan Cyber platform is named, incorporated, and reachable at an address a person reads.
Implementation
WESTPORT CYBER LIMITED is incorporated in Northern Ireland under company number NI741244 and trades as Lagan Cyber. Its registered office stands against that number on the Companies House register. Anything to do with data protection reaches the Data Protection Lead at hello@lagancyber.co.uk, which is a monitored mailbox rather than a ticket queue.
Evidence kept
The company’s filed record at Companies House; the disclosure carried in the footer of every page here; the mailbox log behind that address.
Owner
Data Protection Lead.
The application to pay the data protection fee and appear on the Commissioner’s register of fee payers sits with the ICO. That number will be written into this entry when it issues. Activity here is run from Northern Ireland, with no establishment elsewhere in Europe; should processing later fall within EU GDPR territorial scope, an Article 27 representative will be appointed and published in this entry before it begins.
PRV-02 Role determination before processing Controller & processor
Most privacy notices published by software companies blur the two roles. This one fixes the role first and lets everything else follow from it.
PRV-02
Controller & processor
Control
Each activity is assigned a role in writing before any data moves: controller where this company sets the purpose, processor where a customer sets it.
Implementation
Readers of the site, senders of email, named users of the platform, supplier contacts and job applicants sit on the controller side, because the purpose there is ours. Tenant configuration readings, evidence records, policy acknowledgements, questionnaire answers and training results sit on the processor side, because a subscribing organisation decides why they exist and this company only executes. The dividing line is authorship of the purpose, not who happens to hold the bytes.
Evidence kept
The role column of the register at PRV-03, and the executed processing terms held for each customer.
Owner
Data Protection Lead.
PRV-03 The processing register itself Controller & processor
Everything the rest of this document says in prose is summarised in one table. Nothing is processed that does not appear as a row here.
| Activity | People | Data | Role | Basis | Clock |
|---|---|---|---|---|---|
| Serving these pages | Readers | IP address, timestamp, path, response code, user agent | Controller | 6(1)(f) | 30 days |
| Correspondence | Enquirers | Name, work address, message content | Controller | 6(1)(f) | 2 years after the last reply |
| Platform accounts | Named users at customers | Name, work address, organisation, platform role, sign-in history | Controller | 6(1)(b) | Closure plus 12 months |
| Configuration reads | A customer’s staff | Account names, role assignments, policy and sharing state | Processor | Customer’s | Customer’s instruction |
| Evidence records | A customer’s staff | Control reference, source, method, result, integrity hash | Processor | Customer’s | Customer’s instruction |
| Training and simulation results | A customer’s staff | Module completion, exercise outcome, date | Processor | Customer’s | Customer’s instruction |
| Supplier administration | Supplier contacts | Name, work contact details, contract papers | Controller | 6(1)(b) | 6 years after the relationship ends |
| Recruitment | Applicants | Application, work history, interview notes | Controller | 6(1)(b) | 6 months after the decision |
| Billing and statutory accounts | Customer contacts | Invoice and payment records | Controller | 6(1)(c) | 6 years after the accounting period closes |
| Security and audit logging | Users and administrators | Actor, action, time, source address | Both | 6(1)(f) | 13 months |
PRV-03
Controller & processor
Control
A single register lists every processing activity with its people, its data, its role, its basis and its clock, and it is the reference copy when the prose and the table disagree.
Implementation
Rows are added before an activity starts, not catalogued afterwards. Any new purpose requires a row, a basis and a clock before a line of code touching it reaches production.
Evidence kept
The table above, dated and versioned with this document.
Owner
Data Protection Lead.
PRV-04 Lawful basis assignment Controller
A basis chosen after the fact is a rationalisation. These are fixed at the point a row enters the register.
PRV-04
Controller
Control
Every controller row carries one lawful basis, selected before collection, and none of them relies on consent as a fallback for something already justified another way.
Implementation
Article 6(1)(b) contract covers account provision, billing arrangements and the pre-contract steps taken with an applicant. Article 6(1)(c) legal obligation covers accounting and tax records that companies legislation requires to exist. Article 6(1)(f) legitimate interests covers keeping this site up, logging security events, replying to business correspondence and administering suppliers; PRV-05 records the reasoning behind each. Consent is reserved for the narrow cases where law demands it, and withdrawing it is as simple as a reply.
Evidence kept
The basis column of PRV-03; one balancing note per legitimate interest; consent records where consent applies.
Owner
Data Protection Lead.
PRV-05 Legitimate interests, written down first Controller
Article 6(1)(f) asks for a test, and a test that was never written cannot be produced later.
PRV-05
Controller
Control
Each reliance on legitimate interests is assessed and recorded before use, naming the interest, why the processing is necessary for it, and what it does to the person on the other side.
Implementation
The interests claimed are deliberately narrow: keeping the service reachable, keeping accounts and connected tenants secure, answering a business message that was sent to us, and running supplier relationships. Each is measured against what somebody dealing with a business-to-business security product would expect to happen. Where a purpose can be met with less data, the smaller option wins, and the note says so.
Evidence kept
A dated balancing note per purpose, reviewed once a year, issued on request.
Owner
Data Protection Lead.
PRV-06 Article 9 and Article 10 exclusion Controller & processor
The strongest control over a sensitive category is a design that never asks for it.
PRV-06
Controller & processor
Control
The register carries no row for Article 9 or Article 10 material, and no field in the product invites it.
Implementation
Nothing in a configuration reading, an evidence record, a questionnaire answer or a training result calls for health, biometric, political, religious, trade-union, sex-life or criminal-conviction information. Recruitment asks no such question either. If free text in an enquiry volunteers something of that kind, it is taken out of the working record and plays no part in any decision.
Evidence kept
The register at PRV-03, whose columns show which categories exist; the fixed question set used in recruitment.
Owner
Data Protection Lead.
PRV-07 Website request handling Controller
These pages are static files. What a visit generates is what a web server needs in order to answer, and no more than that.
PRV-07
Controller
Control
Site delivery collects the minimum a server requires to serve a page, and nothing that would follow a reader from one site to the next.
Implementation
A request produces one log line at the hosting layer holding an IP address, a timestamp, a path, a response code and a user-agent string; those lines keep the service available and make abuse visible. There is no analytics product here, no advertising pixel, no experiment framework and no reader profile, which is checkable from the page source rather than something you have to take on trust. Typefaces are fetched by the browser from Google’s font hosts, so that company observes the request for a font file; CKY-04 in the cookie policy covers what that involves.
Evidence kept
Hosting request logs, held 30 days; the published response headers; the page source itself.
Owner
Engineering.
PRV-08 Correspondence and enquiries Controller
Enquiries run through a mailbox. There is no form on this site, so nothing is captured that a sender did not choose to type.
PRV-08
Controller
Control
A message sent to the published address is used to answer that message, and is not repurposed into marketing.
Implementation
What arrives is a message, the address it came from and whatever the sender included. A person reads it and replies, and the exchange stays in the thread. Addresses collected this way are never sold, rented, loaded into a marketing database, enriched from third-party sources, or used to send anything nobody asked for. A message about an assessment is treated exactly the same way as any other enquiry.
Evidence kept
The mailbox thread, which is the whole record of the exchange.
Owner
Data Protection Lead.
A thread is closed and removed two years after the final reply in it, unless it has become part of a contract file, in which case the supplier or customer clock in PRV-15 governs instead.
PRV-09 Platform account identities Controller
An account belongs to a named person working for a subscribing organisation, and that organisation can see it.
PRV-09
Controller
Control
An account record holds what authentication and audit require, and nothing collected merely because it might prove interesting later.
Implementation
The record carries a name, a work address, an organisation, a role inside the platform and a sign-in history. Authentication secrets are never stored in a form that can be read back. Sign-in events are logged because an unexplained login to a compliance tool is exactly the event that has to be reconstructable afterwards.
Evidence kept
The account record and its audit trail; the user list an administrator can see.
Owner
Engineering.
An administrator at the subscribing organisation sees the accounts, roles and activity of its own people. That visibility is a condition of a tool bought to demonstrate oversight, and it is not something this company can switch off for an individual user.
PRV-10 Tenant configuration reads Processor
A posture check reads how a tenant is set up. It does not read what the people in that tenant wrote.
PRV-10
Processor
Control
Connected authority is read-only and scoped to configuration and metadata, so content created by a customer’s staff stays outside what the platform can reach.
Implementation
Granted scopes carry no write permission, which means a setting cannot be altered, an account cannot be disabled and a message cannot be quarantined from here. Checks look at policy state, role assignment, sharing and guest configuration, forwarding rules and logging state. Documents, mailbox contents, message bodies, chat history and calendar entries lie beyond the authority granted and beyond the product’s purpose. Widening a scope requires the customer to grant the wider permission themselves, after notice.
Evidence kept
The scope list published on the evidence page; the collection-method field carried on every evidence record; the customer’s own tenant audit log, which independently shows each read.
Owner
Engineering.
PRV-11 Records the platform creates Processor
Four kinds of record name individual people, and all four belong to the customer whose tenancy they sit in.
PRV-11
Processor
Control
Records created inside a tenancy are segregated to it, and nothing derived from one customer is reused for another.
Implementation
Evidence records, policy acknowledgements, supplier questionnaire responses and training or simulation outcomes are written with the tenant identifier attached and are retrievable only through that tenancy. Findings are never pooled into a benchmark, a shared model or a comparison across customers. An individual named in one of these records deals with their own employer about it, because the employer decided that the record should exist.
Evidence kept
Tenant identifiers on every stored record; access logs showing which account opened which record and when.
Owner
Engineering.
PRV-12 The instruction chain under Article 28 Processor
Processor work is only lawful if the instruction behind it is documented. That paperwork is executed before a tenant is connected, not afterwards.
PRV-12
Processor
Control
Processing on a customer’s behalf runs on written instruction under terms that bind this company and anyone engaged beneath it.
Implementation
The terms fix subject matter, duration, purpose, data types and categories of people; they impose confidentiality on everyone with access; they require help with rights requests, breach notification and impact assessments; and they require return or destruction when the service ends. An instruction that appears to conflict with data protection law is declined in writing, with the reason, and referred back to the customer to reissue.
Evidence kept
The executed terms per customer; the written record of any instruction declined and why.
Owner
Data Protection Lead.
PRV-13 Sub-processor register Controller & processor
Rows below describe a provider by the job it does. The company currently doing that job is named to anyone who asks.
| Function | Processing location | Transfer route | Identity |
|---|---|---|---|
| Static hosting and DNS for this site | United Kingdom, with edge delivery | UK Addendum where a route leaves the UK | Named on request |
| Application hosting and database | United Kingdom | None required | Named on request |
| Transactional email delivery | United Kingdom or EEA | Adequacy | Named on request |
| Error reporting and uptime monitoring | United Kingdom or EEA | Adequacy | Named on request |
| Accounting and payment handling | United Kingdom | None required | Named on request |
PRV-13
Controller & processor
Control
No third party handles personal data on this company’s behalf without a row in this register and contractual duties no weaker than the ones owed upward to customers.
Implementation
A provider joins the register before anything reaches it. Writing to hello@lagancyber.co.uk produces the current name behind any row. Customers receive email notice at least 30 days before a sub-processor touching their data is added or swapped, and may object inside that window; an unresolved objection entitles the customer to end the affected service.
Evidence kept
This register; the contract file per provider; dated copies of every change notice issued.
Owner
Data Protection Lead.
PRV-14 International transfers Controller & processor
Data sits in the United Kingdom by default. Movement beyond it happens only where an instrument covers the movement.
PRV-14
Controller & processor
Control
Personal data stays in the United Kingdom unless a recorded transfer route covers the destination, and the route is identified before data travels.
Implementation
Adequacy regulations cover recipients in the EEA, Ireland among them, and nothing further is needed for those. Absent adequacy, transfer runs on the International Data Transfer Agreement issued by the ICO, or on the UK Addendum where a provider already operates EU standard contractual clauses. A transfer risk assessment precedes reliance on either instrument, weighing the destination’s legal regime, how sensitive the data is, and the realistic prospect of state access. Where a customer instructs a transfer as controller, that instruction is followed and the customer carries the assessment.
Evidence kept
The signed instrument per provider and the dated assessment behind it, issued on request with commercial terms redacted.
Owner
Data Protection Lead.
PRV-15 Retention clocks Controller & processor
Every record class has a clock, and each clock starts on an event that can be pointed at rather than on a general sense that the data is still useful.
| Record class | Clock starts | Held for | Why that long |
|---|---|---|---|
| Site request logs | The request | 30 days | Long enough to investigate abuse, short enough not to build a history |
| Correspondence threads | The final reply | 2 years | Follow-up questions arrive months later and deserve context |
| Account records | Account closure | 12 months | Covers a dispute about what an account did |
| Security and audit logs | The logged event | 13 months | An intrusion found late still has a full year behind it |
| Processor records | Customer instruction | As instructed; returned or destroyed when the service ends | The customer decides, and its schedule governs |
| Invoices and accounting records | Close of the accounting period | 6 years | Companies and tax legislation require it |
| Recruitment records | The hiring decision | 6 months | Long enough to answer a challenge to the decision |
PRV-15
Controller & processor
Control
Deletion runs to the schedule above rather than to whoever remembers, and a clock set by a customer is never quietly extended.
Implementation
Scheduled jobs enforce each row and write a record when they run. Backups follow a separate cycle that expires within 35 days; a record removed from live systems can persist in a backup until that cycle turns over, during which it is restored only as part of recovering an entire system and is deleted again on the next pass.
Evidence kept
The schedule; the output of each deletion job; the retention field carried on evidence records.
Owner
Engineering.
PRV-16 Deletion of data and account closure Controller & processor
Asking for removal should not require knowing the right word for it. An email saying so is enough.
PRV-16
Controller & processor
Control
A request to close an account and remove what stands behind it is carried out, and whatever legitimately survives is stated here rather than left for someone to discover.
Implementation
An email to hello@lagancyber.co.uk from the address on the account, or from an administrator acting for an organisation, starts the work; live records go inside 30 days and written confirmation follows. Where the request concerns processor records, the customer organisation gives the instruction and this company executes it, so an individual employee starts with their own administrator. Ending a subscription stops billing and is a different act from deletion of data — asking for one does not perform the other.
Evidence kept
The dated request, the deletion job record, and the confirmation issued when it completed.
Owner
Data Protection Lead.
Two classes outlive a closure: accounting records held for their statutory period, and audit log lines until the 13-month clock in PRV-15 runs out. Both are named above, and nothing else is retained against a closed account.
PRV-17 The security control set Controller & processor
A company selling control evidence has to be able to produce its own. This entry is what would be handed over if asked.
PRV-17
Controller & processor
Control
The controls protecting personal data here are mapped to a published framework and evidenced, rather than described in adjectives.
Implementation
Access is granted by role on a least-privilege basis and reviewed quarterly, with standing administrative access avoided. Multi-factor authentication is required on every administrative route. Traffic is encrypted in transit and stored data is encrypted at rest, with tenant credentials held in a managed key service under separate access control. Changes reach production through review. The internal control library maps to ISO/IEC 27001:2022 Annex A and the Cyber Essentials technical controls, with NCSC CAF and NIS2 mapped in part; that mapping is our own control library used to organise the work, and the framework names remain the property of their respective publishers.
Evidence kept
Quarterly access review records, change records, and the mapping itself — the same class of artefact the platform produces for a customer.
Owner
Engineering.
PRV-18 Personal data breach handling Controller & processor
The regulatory clock starts when a company becomes aware of a breach, not when it finishes deciding how bad it was.
PRV-18
Controller & processor
Control
A suspected breach is triaged on the day it is known, and notification duties are assessed against the moment of awareness.
Implementation
A report reaching hello@lagancyber.co.uk is triaged the same working day. Containment comes first, then establishing scope, then notification. As controller, where a breach is likely to put people’s rights at risk, the ICO is told within 72 hours of awareness and individuals are told directly where that risk is high. As processor, the affected customer is told without undue delay so the customer can meet its own deadline, and the customer decides what its regulator and its people are told.
Evidence kept
One incident record per event — what happened, when it became known, what was done, what was decided about notification and the reasoning — retained six years.
Owner
Data Protection Lead.
Anyone reporting a weakness here in good faith is not pursued for having looked. Send the finding to the address above and expect a human answer.
PRV-19 Rights available to individuals Controller
Each right below has the same route: one address, answered by a person who can act on it.
PRV-19
Controller
Control
Every right in Chapter III of the UK GDPR is available in practice, not merely acknowledged in text.
Implementation
- Access, Article 15 — a copy of what is held, together with why it is held and who has seen it.
- Rectification, Article 16 — correction of a record that is wrong or incomplete.
- Erasure, Article 17 — removal where the reason for holding it has fallen away.
- Restriction, Article 18 — processing frozen while an accuracy dispute is worked out.
- Portability, Article 20 — a machine-readable copy where the handling is automated and rests on contract or consent.
- Objection, Article 21 — a halt where the basis is legitimate interests, unless a compelling ground survives the challenge.
- Automated decisions, Article 22 — addressed at PRV-23.
- Withdrawing consent, Article 7(3) — as easy to take back as it was to give.
- Complaint, Article 77 — addressed at PRV-21.
Evidence kept
A rights log holding each request, its date, the decision taken and the date the answer went out.
Owner
Data Protection Lead.
Where a right bites on processor records, the organisation that put the record there is the one that decides. The request is passed to that customer promptly and assistance given, which is what Article 28 requires of a processor.
PRV-20 How a request is handled Controller
The procedure matters as much as the right. This is the whole of it.
PRV-20
Controller
Control
A rights request is answered inside one month, identity is checked in proportion to what is at stake, and the ordinary case attracts no charge.
Implementation
No particular form of words is needed, no article has to be cited, and nobody needs legal help to ask. Enough detail to find the record is what actually matters. Identity is settled by a reply from the address already on file wherever that suffices; more proof is sought only when the material is sensitive or the address does not match. The month runs from receipt, or from the point identity is settled. A complex request, or several at once, can take up to two further months, and notice of that extension goes out within the first month carrying the reason for it.
Evidence kept
The rights log and the dated correspondence behind each entry in it.
Owner
Data Protection Lead.
A charge or a refusal is possible only where a request is excessive or plainly unfounded. In that event the reasoning is given in writing, along with the route to challenge it at PRV-21.
PRV-21 Route to the supervisory authority Controller & processor
The regulator’s address is printed here at the same size as ours, because a complaint route hidden in the last paragraph is not a route.
PRV-21
Controller & processor
Control
Anyone unhappy with how their data was handled can go directly to the supervisory authority, with no obligation to come here first.
Implementation
The UK supervisory authority is the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113. Complaints can be made online through the ICO. Raising the matter here first is welcome and usually quicker, and it is never a precondition of going to the regulator.
Evidence kept
Complaint correspondence, filed alongside the rights log.
Owner
Data Protection Lead.
PRV-22 Children Controller & processor
This is a product bought by organisations for their own security posture. Nothing about it is built for or aimed at a child.
PRV-22
Controller & processor
Control
No control depends on a child’s data, and no part of this site or platform is directed at children.
Implementation
Accounts exist for people acting in a work capacity, and the site is written for the person in an organisation who answers security questionnaires. Where a subscribing employer’s own workforce includes someone under 18 whose training record passes through the platform, that record is handled on the employer’s instruction like every other processor record, with no additional profiling and no special treatment beyond the employer’s own duties.
Evidence kept
The account register, which records organisation and work role for each user.
Owner
Data Protection Lead.
PRV-23 Automated processing and profiling Controller & processor
Checks run automatically. Judgements about people do not.
PRV-23
Controller & processor
Control
No decision producing a legal or similarly significant effect on a person is taken by machine alone, and Article 22 is not engaged by anything the product does.
Implementation
A check evaluates a configuration and returns pass, fail or not applicable against a control reference; the subject of that verdict is a setting, not a person. Training and simulation outcomes describe what happened in an exercise, and what an employer does with them is that employer’s decision as controller of its own workforce data. Nothing here scores individuals, ranks them against colleagues, or feeds an employment consequence automatically. Should that ever change, the change would be described in this entry, with a lawful basis and human review, before it went live.
Evidence kept
The evidence record, which names the check performed, the method used and the result reached.
Owner
Engineering.
PRV-24 Change control for this register Controller & processor
A register nobody can date is not evidence of anything. This one is versioned like the rest of the product.
PRV-24
Controller & processor
Control
Amendments are versioned, dated and notified ahead of taking effect wherever they matter to somebody relying on this document.
Implementation
This is version 2.0, in force 15 August 2026, replacing version 1.0 of 5 August 2026. Where an amendment cuts a protection or materially alters how data is handled, account holders get email notice at least 30 days ahead of the change and the revised text is published here on the same day. Corrections that leave the meaning untouched take effect on publication.
Evidence kept
Superseded versions, retained and issued on request from hello@lagancyber.co.uk, so a reader can see what moved and when.
Owner
Data Protection Lead.