Legal
How SecureDocUK processes personal data under UK GDPR and the Data Protection Act 2018.
Last updated: 6 September 2026
The data controller is Andras Mezofi trading as SecureDocUK (“we”, “us”, “our”).
We sell UK security document templates online and may contact UK corporate businesses about those products.
Email: andras@securedocuk.co.uk Website: https://securedocuk.co.uk Address: 24 Barge House Road, London E16 2NW
Depending on how you use the site or shop, we may process:
| Purpose | Lawful basis |
|---|---|
| Run the website and keep it secure | Legitimate interests |
| Take and fulfil orders; provide downloads and support | Contract |
| Answer enquiries | Legitimate interests or contract |
| Keep accounting and tax records | Legal obligation |
Where we rely on legitimate interests for running and securing the site or answering enquiries, those interests are operating a small online shop and responding to people who contact us.
We do not currently send marketing emails to customers. If that changes, we will update this notice first and only email on a lawful basis under UK GDPR and PECR.
Checkout fields needed to complete a purchase are required. If you do not provide them, we cannot fulfil the order. Other contact details are optional.
We use the following organisations in connection with the site and shop. They do not all act in the same capacity:
| Organisation | How we use them |
|---|---|
| Payhip (Payhip Ltd) | Digital shop and download delivery |
| Etsy | Marketplace listings and orders |
| Vercel | Hosting for securedocuk.co.uk |
| Google (Google Workspace / Gmail) | Business email for andras@securedocuk.co.uk |
Payment card details are processed by the payment methods offered at Payhip/Etsy checkout under those providers’ arrangements. We receive order and payment-status information, not full card numbers.
Some of these organisations may process personal data outside the United Kingdom. Where that happens, we rely on the transfer arrangements in their current privacy notices and data-processing terms. You can ask us for more detail.
| Record type | Retention |
|---|---|
| Customer orders and tax / accounting records | Kept for at least five years after the 31 January submission deadline for the relevant tax year, or longer where legally required |
| General enquiry emails that do not become customers | Deleted after 12 months |
| Website / server logs | Kept only as long as needed for security and operation of the site, then deleted or anonymised |
This section applies when we obtain business contact details from a database or public sources (not from you directly) and email you about SecureDocUK products.
We send cold B2B marketing emails only to contacts at corporate subscribers (for example limited companies, LLPs, and similar organisations where PECR’s electronic-mail consent rule does not apply).
We do not send unsolicited marketing emails to sole traders or ordinary partnerships unless we have valid consent or the PECR soft opt-in applies.
Named employees’ business emails are still personal data under UK GDPR.
| Purpose | Lawful basis |
|---|---|
| B2B sales / marketing emails about SecureDocUK templates (corporate subscribers only) | Legitimate interests |
| Keep a CRM and suppression list so we respect opt-outs | Legitimate interests / duty to honour objections |
Our legitimate interest is promoting relevant UK security documentation products to people in security operations, guarding, or related compliance roles at UK corporate organisations.
Before any cold B2B outreach starts, a written legitimate-interests assessment (LIA) for this processing will be signed and dated. Until then, this notice does not claim that a documented LIA is already maintained.
Where we obtained your data from Apollo or other public / third-party sources, we provide this privacy information at the latest when we first contact you (by linking to this notice in the first email).
Before each outreach campaign we screen the send list against our suppression list so opted-out contacts are not emailed.
| Organisation | How we use them |
|---|---|
| Apollo.io | B2B prospecting / CRM tooling |
| Google (Workspace / Gmail) | Sending email from andras@securedocuk.co.uk |
Apollo and Google may process outreach-related personal data outside the United Kingdom. We rely on the transfer arrangements in their current privacy notices and data-processing terms. You can ask us for more detail.
| Record type | Retention |
|---|---|
| Unresponsive prospects (no meaningful reply) | Deleted after 12 months |
| Opt-out / suppression data | We keep only minimal details needed to make sure we never email you again, for as long as SecureDocUK continues B2B outreach |
You have an absolute right to object to direct marketing. Reply “not for me” or email andras@securedocuk.co.uk and we will stop marketing emails and add you to our suppression list.
Every cold B2B email must:
Under UK GDPR you may have the right to:
Email andras@securedocuk.co.uk. You can also complain to the ICO: https://ico.org.uk/
Essential cookies may be used to run and secure the website.
The site loads Vercel Web Analytics (/_vercel/insights/script.js) for basic traffic measurement. Vercel describes this product as privacy-oriented / cookieless. We do not use advertising cookies or other non-essential marketing trackers.
If we add non-essential analytics cookies in future, we will use them only with consent and update this section first. We will not use legitimate interests as the basis for analytics cookies.
We may update this notice. The “Last updated” date at the top will change when we do. For material changes affecting B2B contacts, we will update this page and, where appropriate, note the change in future emails.
Andras Mezofi trading as SecureDocUK
Email: andras@securedocuk.co.uk
Web: https://securedocuk.co.uk
Address: 24 Barge House Road, London E16 2NW