{"id":3,"date":"2025-11-12T21:29:23","date_gmt":"2025-11-12T21:29:23","guid":{"rendered":"https:\/\/www.drspeffle.co.uk\/?page_id=3"},"modified":"2025-11-13T00:15:15","modified_gmt":"2025-11-13T00:15:15","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/portal.drspeffle.co.uk\/index.php\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><strong>1. Introduction<\/strong><\/h2>\n\n\n\n<p>Dr Speffle Cyber Resilience Ltd (\u201cwe\u201d, \u201cus\u201d, \u201cour\u201d) is committed to protecting the privacy and security of your personal data.  This Privacy Policy explains what information we collect, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.<\/p>\n\n\n\n<p>This website is intended for general information, research dissemination, and client communication regarding cyber resilience, consultancy services, technical documentation, and academic work.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>2. What Data We Collect<\/strong><\/h1>\n\n\n\n<p>We may collect and process:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.1 Information you provide directly<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contact form submissions (name, email address, message contents)<\/li>\n\n\n\n<li>Email correspondence<\/li>\n\n\n\n<li>Consultancy enquiries<\/li>\n\n\n\n<li>Optional Newsletter signup (if enabled)<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.2 Automatically collected technical data<\/strong><\/h3>\n\n\n\n<p>Through cookies, analytics, and security plugins:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address (for security + anti-spam protection)<\/li>\n\n\n\n<li>Browser type\/version<\/li>\n\n\n\n<li>Device information<\/li>\n\n\n\n<li>Pages viewed and time spent<\/li>\n\n\n\n<li>Referring website<\/li>\n\n\n\n<li>Error logs and security events<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2.3 Plugin-related data<\/strong><\/h3>\n\n\n\n<p>Our website uses several security, SEO, analytics, and performance plugins. These plugins may process limited technical data to function correctly. We only use reputable, security-focused plugins and do not allow third-party advertising or behavioural tracking.<\/p>\n\n\n\n<p>Below is a full list of plugins that may process technical or personal data:<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83d\udd10 <strong>Security &amp; Anti-Malware Plugins<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Anti-Malware Security and Brute-Force Firewall<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address<\/li>\n\n\n\n<li>User-agent<\/li>\n\n\n\n<li>URL request patterns<\/li>\n\n\n\n<li>Suspicious activity logs<\/li>\n\n\n\n<li>Malware scanning<\/li>\n\n\n\n<li>Threat detection<\/li>\n\n\n\n<li>Firewall defence<br>Lawful basis: <strong>Legitimate Interests (website security)<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Limit Login Attempts Reloaded<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address<\/li>\n\n\n\n<li>Failed login attempts<\/li>\n\n\n\n<li>Username entered (if provided)<\/li>\n\n\n\n<li>Brute-force protection<br>Lawful basis: <strong>Legitimate Interests (security &amp; fraud prevention)<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>WP Armour \u2013 Honeypot Anti-Spam<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Form submission metadata<br>Purpose:<\/li>\n\n\n\n<li>Spam prevention<br>Lawful basis: <strong>Legitimate Interests<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>WP fail2ban &amp; WP fail2ban Blocklist<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address<\/li>\n\n\n\n<li>Login events<\/li>\n\n\n\n<li>Core WordPress activity logs<br>Purpose:<\/li>\n\n\n\n<li>Logging security events to system logs<\/li>\n\n\n\n<li>Automatic blocklist integration<br>Lawful basis: <strong>Legitimate Interests (security monitoring)<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83d\udee1 <strong>Access Restriction Plugins<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Password Protect WordPress Lite<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Password validation attempts<\/li>\n\n\n\n<li>User roles (if logged in)<br>Purpose:<\/li>\n\n\n\n<li>Restricting access to certain pages<br>Lawful basis: <strong>Legitimate Interests (site management)<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\u26a1 <strong>Performance Plugins<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>WP Fastest Cache<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Anonymous cached page data<br>Purpose:<\/li>\n\n\n\n<li>Improve website loading speed<br>Lawful basis: <strong>Legitimate Interests (performance optimisation)<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83d\udcc8 <strong>Analytics &amp; SEO Tools<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Site Kit by Google<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address (anonymised)<\/li>\n\n\n\n<li>Page views<\/li>\n\n\n\n<li>Browser\/device info<\/li>\n\n\n\n<li>Referrer<br>Purpose:<\/li>\n\n\n\n<li>Analytics<\/li>\n\n\n\n<li>Search Console performance<\/li>\n\n\n\n<li>Page speed measurement<br>Lawful basis: <strong>Consent<\/strong> (for non-essential analytics cookies)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Rank Math SEO<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Structured data about posts (not personal data)<\/li>\n\n\n\n<li>Search engine metadata<br>Purpose:<\/li>\n\n\n\n<li>SEO optimisation<br>Lawful basis: <strong>Legitimate Interests (site discoverability)<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>CrawlWP SEO \u2013 Instant Indexing<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Post metadata<\/li>\n\n\n\n<li>URL indexing requests<br>Purpose:<\/li>\n\n\n\n<li>Faster search engine indexing<br>Lawful basis: <strong>Legitimate Interests<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Instant Indexing (Rank Math)<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>URLs submitted for indexing<br>Purpose:<\/li>\n\n\n\n<li>Search engine submission<br>Lawful basis: <strong>Legitimate Interests<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83c\udfa8 <strong>Design &amp; Presentation Plugins<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Favicon by RealFaviconGenerator<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>No personal data<\/li>\n\n\n\n<li>Providing device-specific favicons<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Under Construction<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Visitor role (logged in\/not logged in)<\/li>\n\n\n\n<li>Display maintenance or \u201cunder construction\u201d page<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">\ud83e\udde9 <strong>Summary of Plugin Data Processing<\/strong><\/h1>\n\n\n\n<p>Across all plugins, typical data processed may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>IP address<\/li>\n\n\n\n<li>Browser and device info<\/li>\n\n\n\n<li>Request URLs<\/li>\n\n\n\n<li>Security logs and error logs<\/li>\n\n\n\n<li>Login attempts<\/li>\n\n\n\n<li>Anonymous analytics events<\/li>\n\n\n\n<li>Metadata related to posts or pages<\/li>\n<\/ul>\n\n\n\n<p>No plugin is used for behavioural advertising or third-party marketing.<\/p>\n\n\n\n<p>All data is processed under:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Legitimate Interests (security, analytics, performance)<\/strong><\/li>\n\n\n\n<li><strong>Consent (analytics cookies)<\/strong><\/li>\n\n\n\n<li><strong>Contractual necessity (forms or communication)<\/strong><\/li>\n<\/ul>\n\n\n\n<p>You can request a list of active plugins at any time.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>3. How We Use Your Data<\/strong><\/h1>\n\n\n\n<p>We use your data for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Responding to enquiries<\/li>\n\n\n\n<li>Providing consultancy services (when requested)<\/li>\n\n\n\n<li>Security monitoring and threat prevention<\/li>\n\n\n\n<li>Improving website content and performance<\/li>\n\n\n\n<li>Understanding visitor engagement<\/li>\n\n\n\n<li>Fulfilling legal or regulatory requirements<\/li>\n<\/ul>\n\n\n\n<p>We <strong>do not sell, rent, or trade<\/strong> your personal data.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>4. Legal Basis for Processing<\/strong><\/h1>\n\n\n\n<p>Under UK GDPR, we rely on the following lawful bases:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Legitimate interests<\/strong> (website security, analytics, communication)<\/li>\n\n\n\n<li><strong>Contractual necessity<\/strong> (responding to consultancy requests)<\/li>\n\n\n\n<li><strong>Consent<\/strong> (newsletter sign-ups, optional cookies)<\/li>\n\n\n\n<li><strong>Legal obligation<\/strong> (accounting and compliance)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>5. Cookies and Tracking<\/strong><\/h1>\n\n\n\n<p>This website may use essential and optional cookies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Essential cookies<\/h3>\n\n\n\n<p>Required for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Security<\/li>\n\n\n\n<li>Login sessions<\/li>\n\n\n\n<li>Page performance<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Non-essential cookies<\/h3>\n\n\n\n<p>Used only with consent for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Analytics<\/li>\n\n\n\n<li>Performance metrics<\/li>\n\n\n\n<li>User behaviour insights<\/li>\n<\/ul>\n\n\n\n<p>You can manage cookies via your browser or our cookie banner.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>6. Data Sharing and Transfers<\/strong><\/h1>\n\n\n\n<p>We may share data with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Website hosting providers<\/li>\n\n\n\n<li>Security and anti-spam services<\/li>\n\n\n\n<li>Analytics platforms<\/li>\n\n\n\n<li>Professional service providers (legal\/accounting)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>7. Data Retention<\/strong><\/h1>\n\n\n\n<p>We retain data only as long as necessary:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contact form submissions: up to <strong>12 months<\/strong><\/li>\n\n\n\n<li>Security logs: <strong>30\u201390 days<\/strong><\/li>\n\n\n\n<li>Analytics data: <strong>as configured in your analytics tool<\/strong><\/li>\n\n\n\n<li>Client contract data: <strong>6\u20137 years<\/strong> (legal requirement)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>8. Your Rights<\/strong><\/h1>\n\n\n\n<p>Under UK GDPR, you have the right to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access your data<\/li>\n\n\n\n<li>Correct inaccurate data<\/li>\n\n\n\n<li>Request deletion<\/li>\n\n\n\n<li>Restrict processing<\/li>\n\n\n\n<li>Object to processing<\/li>\n\n\n\n<li>Withdraw consent<\/li>\n\n\n\n<li>Request data portability<\/li>\n<\/ul>\n\n\n\n<p>Please use the contact form to exercise these rights.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>9. How We Protect Your Data<\/strong><\/h1>\n\n\n\n<p>We implement:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Server-level security controls<\/li>\n\n\n\n<li>SSL\/TLS encryption<\/li>\n\n\n\n<li>Firewall and intrusion monitoring<\/li>\n\n\n\n<li>Regular updates to plugins and themes<\/li>\n\n\n\n<li>Principle of least privilege<\/li>\n\n\n\n<li>Encrypted communication pathways<\/li>\n<\/ul>\n\n\n\n<p>For more detail, see our <strong>Cyber Resilience<\/strong> section.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>10. Third-Party Links<\/strong><\/h1>\n\n\n\n<p>This website may contain external links (e.g., GitHub, Medium, LinkedIn).<br>We are not responsible for their privacy practices.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>11. Changes to This Policy<\/strong><\/h1>\n\n\n\n<p>We may update this policy periodically.<br>Changes will be posted on this page with a revised \u201cLast updated\u201d date.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><strong>12. Contact Information<\/strong><\/h1>\n\n\n\n<p>If you have any questions or concerns, contact:<\/p>\n\n\n\n<p><strong>Dr Speffle Cyber Resilience Ltd<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction Dr Speffle Cyber Resilience Ltd (\u201cwe\u201d, \u201cus\u201d, \u201cour\u201d) is committed to protecting the privacy and security of your personal data. This Privacy Policy explains what information we collect, how we use it, and your rights under UK GDPR and the Data Protection Act 2018. This website is intended for general information, research dissemination, and client communication regarding cyber resilience, consultancy services, technical documentation, and academic work. 2. What Data We Collect We may collect and process: 2.1 Information&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/portal.drspeffle.co.uk\/index.php\/privacy-policy\/\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-3","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/pages\/3","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/comments?post=3"}],"version-history":[{"count":2,"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/pages\/3\/revisions"}],"predecessor-version":[{"id":80,"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/pages\/3\/revisions\/80"}],"wp:attachment":[{"href":"https:\/\/portal.drspeffle.co.uk\/index.php\/wp-json\/wp\/v2\/media?parent=3"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}