Legal information
Our policies and terms.
Read how we use personal data, manage cookies and work with clients. You will also find our website terms and guidance for reporting a security concern.
Legal hub · updated 11 September 2026 · version 1.6
Privacy policy
How we use personal data, why we use it, who receives it, how long we keep it and your rights.
1 · Who we are
Controller: Musketeers Security Ltd, Company No. 16892937 (England & Wales). Registered office: 44 Grand Parade, Brighton BN2 9QA. Privacy and data-protection contact: jalil@musketeers-security.com.
2 · What we collect, why, and on what basis
- Enquiries & incident-response calls
- name, contact details, what you tell us. Lawful basis: legitimate interest in responding.
- Expert intro requests
- name, work email, organisation and the information you provide through our website form. We contact you to agree a time; submitting the form does not book a meeting. Lawful basis: contract / pre-contract steps.
- HealthCheck scores
- you can answer the questions and see your score without providing contact details. Your answers and score are sent to us only if you request a detailed report.
- HealthCheck report requests
- name, business email, phone number, answers and score. With your consent, we use these details to prepare your report and contact you about it by email or phone. Our founder will contact you within 24 hours with your detailed report. Requesting a report does not subscribe you to the Cyber Hub briefing. Lawful basis: consent. The consent box starts unticked, and you can withdraw consent at any time by contacting jalil@musketeers-security.com.
- Cyber Hub briefing
- name, business email and organisation. With your separate consent, we send the briefing by email. The box starts unticked, and you can unsubscribe using the link in each email or by contacting us. Lawful basis: consent.
- Optional website tracking
- with your consent, Google Analytics (and Plausible, where enabled) records visits and activity such as page views, scrolling, link clicks, downloads, form interactions and supported video activity. This includes browser and device information and approximate location. We use this to understand how the site is used and improve it. We do not send names, email addresses or form answers in these analytics events. You can withdraw consent through Cookie preferences. Visitor-identification tools (Apollo) run only if you allow them separately.
Where did you get my data?
Existing imported contacts: The contacts in our existing imported business-outreach list came from Apollo.io. The third-party contact notice below applies to that list.
New website leads: If you submit an enquiry, request an expert intro or HealthCheck report, or subscribe to the Cyber Hub Briefing, we receive the information directly from you through that form. We do not describe those new website leads as Apollo-sourced contacts.
To ask about the source of your own record, email jalil@musketeers-security.com. To stop marketing emails, use the unsubscribe link in any email.
2a · Business contacts we obtain from third parties (UK GDPR Article 14 notice)
Musketeers Security Ltd carries out business-to-business outreach to people in cyber-security, IT, risk and technology leadership roles at incorporated organisations. Where we have not obtained your details directly from you, this is the information we are required to give you:
- Where the data comes from
- Apollo.io, for the existing imported business-outreach list. New website leads provide their information directly through our forms.
- What we hold
- first name, last name, job title, employer, work email address and, where published, business phone number, city and country. We hold nothing beyond professional contact identifiers.
- Why, and on what lawful basis
- to introduce our coordinated cyber-security programme to the professionals responsible for their organisation's security posture. Lawful basis: legitimate interests, UK GDPR Article 6(1)(f), supported by a documented Legitimate Interest Assessment (available on request). Electronic marketing to corporate subscribers is conducted in line with the Privacy and Electronic Communications Regulations (PECR).
- Who we will not contact this way
- sole traders, partnerships and other unincorporated businesses; anyone using a personal (non-corporate) email address; and contacts in Germany or Austria, where national rules require prior opt-in consent. Such records are removed before any outreach.
- Where it is kept
- in our CRM and email platform (Wix, EU/UK data-hosting terms apply). Personal data is never sold.
- How to stop it
- every email carries a one-click unsubscribe. You may also object at any time by emailing jalil@musketeers-security.com. Either route permanently suppresses your record from all outreach within 48 business hours, and you will receive confirmation of the source of your data on request.
3 · Who receives it
Website and enquiry services include content delivery and hosting (Wix), Microsoft 365, and our CRM, website-form and email platform (Wix). Cloudflare delivers the Cyber Hub’s public article feed and receives connection information, such as IP addresses, to deliver and protect that service. The feed request does not include enquiry details or analytics cookies. Google Analytics processes website usage information when you accept optional analytics. Google may process this information outside the UK. See Google’s privacy policy. The existing imported business-contact list described in section 2a was obtained from Apollo.io. New website leads provide their details directly to us. Each operates under appropriate contractual terms. Personal data is never sold. Member firms receive engagement data only under the NDA and contract governing your engagement.
4 · How long we keep it
- Enquiry correspondence: only while needed to respond and manage the relationship.
- HealthCheck report requests, contact details, answers and scores: only while needed to prepare the report and handle the requested follow-up, or until you withdraw consent, unless a legal obligation requires retention.
- Cyber Hub briefing subscriptions: while you remain subscribed. After withdrawal, we retain only the information needed to record your choice and prevent further briefing emails.
- Incident-response engagement records: in line with contractual, legal and evidential requirements.
- Intro-call request correspondence: only while needed to arrange the call and manage the relationship.
- Business-contact (outreach) data: reviewed every 12 months and deleted if there has been no engagement; objections and unsubscribes are actioned within 48 business hours and the address is retained only on a suppression list so that we do not contact you again.
5 · Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. Write to jalil@musketeers-security.com. If you want to know where we obtained your details, ask and we will tell you the specific source. You may complain to the Information Commissioner's Office: ico.org.uk.
6 · Changes
Versioned and dated at the top of this page; material changes announced on the site before they take effect.
Website terms
The conditions for using the website, intellectual property, acceptable use and limitations.
By using this website you accept these terms. Content is general information, not legal, regulatory, insurance or security advice. It must not replace an assessment of your circumstances.
You may not probe, scan or test this site without written authorisation, introduce malicious code, misuse content or scrape it at scale. Approved security research must follow the Responsible Disclosure Policy.
Links to third-party websites are provided for convenience. Musketeers is not responsible for third-party availability or content. These terms are governed by the law of England and Wales.
Terms of business
The approved commercial terms for an engagement.
Musketeers assesses, assembles and coordinates independent specialist practices. The engagement proposal and statement of work identify the scope, commercial route, named responsibilities, dependencies, fees and definition of done.
Specialists may contract directly with the client or operate under one agreed umbrella route. Whichever route is selected, delivery responsibilities, intellectual property, confidentiality, liability, insurance, change control and termination are confirmed in the signed engagement documents.
Full terms are issued with each proposal and take precedence over this website summary.
Data protection & security
How the company approaches security, processors, transfers, access and incident handling.
We apply data minimisation, least-privilege access, multi-factor authentication, encryption in transit and at rest, controlled sharing, supplier due diligence and documented incident procedures.
Personal data is shared with a consortium member only when required for an agreed engagement and subject to the appropriate NDA, controller-to-controller or processor terms. Suspected breaches are assessed promptly and notified where legal thresholds are met.
Responsible disclosure
How a security researcher can report a suspected vulnerability safely and what to include.
If you believe you have found a security vulnerability affecting this site or a Musketeers service, email security@musketeers-security.com with a clear description, affected location and safe reproduction steps.
Do not access data that is not yours, degrade service, use destructive testing, publish details before resolution or demand payment. We will acknowledge valid reports, investigate and keep the reporter informed where contact details are supplied.
Cookie preferences
Review and change your cookie choices.
Analytics is your choice. You can change your analytics choice at any time. Rejecting analytics stops collection and removes the Google Analytics cookies set by this integration.