This policy explains what personal data PatientZero collects when you use our website, free malware check, enquiry and callback forms and our security services, why we collect it, how long we keep it and the rights you have under UK data protection law.
Who we are
PatientZero is a trading name of [Company name], a company registered in England and Wales under company number [Company number], with its registered office at [Registered address]. For the personal data described in this policy, we are the controller.
If you have any questions about this policy or how we handle your data, contact us:
- Email: repair@patientzerosolutions.co.uk
- Phone: 01932 593642
- Post: [Company name], [Registered address]
What personal data we collect
We collect only the data we need to answer your enquiry, run our free tools and provide our services. The table below sets out each source, the data involved and why we use it.
| Source | Data | Purpose |
|---|---|---|
| Onboarding wizard ("Get protected" and emergency triage) | Name, email, phone, company, website address, number of sites, hosting and platform details, your answers, risk score, the page you came from, campaign parameters (such as UTM tags and click IDs) and any free check result you link to it | To respond to your enquiry, assess your security needs and recommend a plan |
| Emergency callback form | Name, phone number and website address | To call you back about a suspected hack |
| Free malware check | The website address you enter, the check results and, only if you choose to give it, your email address | To run the check, show your results and, with your consent, email you the report |
| Email, phone and contact | Your contact details and what you tell us | To answer your questions |
| Customers | Account contacts, billing details, and information we process on your servers and websites while providing our services | To provide and bill for the services under our terms |
| Website use | IP address, browser and device information, security logs and, only with consent, analytics data | To keep the website secure, prevent abuse and, with consent, understand how the site is used |
The wizard keeps a draft of your answers in your browser's local storage so you do not lose your progress. No personal data is sent to us until you submit the form. See our cookie policy for details.
How we handle form submissions
When you submit the onboarding wizard or the callback form, your details are emailed to our team so we can respond quickly, and stored securely in our database so we have a record of your enquiry. Emergency callback requests may also trigger a text message alert to our on-call phone containing your name, phone number and website.
Forms are protected by security measures including CSRF tokens, rate limiting and a bot check provided by Cloudflare Turnstile, which processes technical data such as your IP address and browser characteristics to tell people from automated traffic.
If you give us your email in the wizard or free check and consent to follow-up, we may send a short series of emails about website security. Every email includes an unsubscribe link, and we stop as soon as you reply, book a call, become a customer or unsubscribe. Emergency enquiries receive human follow-up only.
The free malware check
The free malware check only looks at publicly available information about the website address you enter. It does not log in to or access your server.
- The website address is checked against Google Safe Browsing, which means the address is sent to Google for that lookup.
- Results are cached for one hour per domain so repeat checks are fast and we do not overload your site. After that they are discarded.
- We do not keep the website address you checked beyond that cache unless you consent, for example by asking for the report by email or linking the result to an enquiry.
- If you give your email address and ask for the report, we email it to you and, with your consent, may send follow-up emails as described above.
Our lawful bases for using your data
Under UK GDPR we must have a lawful basis for each use of personal data. We rely on the following:
- Contract: to provide services to customers and to take steps you ask for before entering a contract, such as preparing a proposal.
- Legitimate interests: to respond to enquiries and callback requests, keep our website and forms secure, prevent fraud and abuse, and keep business records. We balance these interests against your rights and you can object at any time.
- Consent: for analytics cookies, session recording, emailing you a free check report and marketing emails. You can withdraw consent at any time.
- Legal obligation: to keep accounting records and comply with requests from regulators or law enforcement where the law requires it.
Analytics and session recording
We use Google Analytics 4 and Microsoft Clarity only if you accept analytics cookies. Until you do, they do not load. Google Analytics tells us which pages are used and how people arrive; Microsoft Clarity records anonymised interactions, such as clicks and scrolling, on pages such as the wizard and free check so we can improve them.
We use Google Consent Mode, so Google tags respect your choice. Form fields are masked in Clarity recordings. You can change your choice at any time using the cookie settings link in the footer. See our cookie policy for the cookies involved.
Who we share data with
We do not sell your personal data. We share it only with service providers who help us run the website and our services, under contracts that require them to protect it and use it only on our instructions, and where the law requires.
- Website hosting and email delivery (SiteGround)
- Bot protection (Cloudflare Turnstile)
- Safe Browsing lookups for the free check (Google)
- Analytics, only with consent (Google Analytics, Microsoft Clarity)
- Text message alerts for emergency callbacks (our SMS provider)
- Our website and operations partner, Bracket Media Limited, whose team receives enquiry notifications
- Payment processing for customers
- Professional advisers, regulators and law enforcement where required by law
International transfers
Some of our providers, including Google, Microsoft and Cloudflare, may process data outside the UK, including in the United States. Where they do, we rely on appropriate safeguards recognised under UK law, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework or the International Data Transfer Agreement and Addendum. Contact us for more information.
How long we keep your data
We keep personal data only for as long as we need it for the purpose it was collected for, then delete or anonymise it.
| Data | Retention |
|---|---|
| Free check results (without consent) | One hour, then discarded |
| Enquiries that do not become customers | Up to 24 months after our last contact |
| Marketing email consent records | Until you unsubscribe, then a suppression record so we do not email you again |
| Customer account and service records | For the life of the contract and up to 6 years afterwards |
| Accounting records | As required by law, currently 6 years |
| Website security logs | Up to 90 days |
How we protect your data
As a security company, we hold ourselves to a high standard. Our website is served only over HTTPS with strict security headers, forms are protected against forgery and abuse, database queries use prepared statements, and secrets are stored outside the web root. Access to enquiry and customer data is limited to staff who need it. Read more on our security page.
Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data erased in certain circumstances
- restrict or object to how we use your data, including objecting to direct marketing at any time
- receive your data in a portable format where we rely on consent or contract
- withdraw consent at any time, without affecting processing already carried out
To exercise any of these rights, email repair@patientzerosolutions.co.uk. We will respond within one month. If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113, though we would appreciate the chance to resolve it first.
Data we process for customers
When we clean, scan or monitor a customer's websites and servers, we may come across personal data belonging to the customer's own users, such as names in a database or order details. For that data, the customer is the controller and we act as their processor, handling it only to provide the services and under the data processing terms in our terms of service.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last changed. If we make significant changes that affect how we use data you have already given us, we will tell you directly where we can.