Call us — 0161 871 0788
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
Security · confidentiality

What happens to your data while we have it.

By the time a drive reaches us it usually holds the things somebody would least want read by a stranger. What follows is how that is handled in practice rather than a statement of intent — ICO registration, one named engineer per job, no subcontracting, and nothing crossing a border at any stage.

Free 48-hour diagnostic
Handled in-house
No fix, no fee · most jobs
// in short

In-house, never shared.

On the ICO register and GDPR-compliant. One named engineer per job, confidentiality assumed rather than negotiated, and working copies destroyed on a schedule you set rather than one we choose.

ICO
Registered
GDPR
Compliant
In-house
Never outsourced
NDA
On request
// where your data goes

One building, one set of hands.

The arrangements stated plainly rather than buried in terms.

// what we don’t do

Three things worth stating.

Because the absence of a policy is not the same as a policy.

We don’t read what we recover. Verification means confirming files open and the structure matches what you described — not examining content. On privileged or sensitive material, tell us and we will take your instruction on how you want verification handled.

We don’t keep copies indefinitely. There is no archive, no ‘just in case’ retention, and nothing held back. After the agreed period the working copies are destroyed.

We don’t move data offshore. Not for processing, not for storage, not for a specialist step. If a job needed something we could not do here, we would tell you rather than send your data somewhere without saying.

// for regulated work

NDAs, DPAs and chain of custody.

Standard rather than requested, because most of our business clients need them.

NDAs are signed as a matter of course for business work, and data processing agreements where personal data is involved — clinical records, HR files, client data held under contract. Each job runs through a single named contact from diagnostic to delivery, which keeps the number of people with access as short as it can be.

Where material may later be scrutinised, handling is documented: signed exhibit records, logged movements, and cryptographic hashes taken at imaging and re-verified at each stage so any alteration would be demonstrable. That follows ACPO principles and it is available on any job, not only forensic ones — which matters because a routine recovery occasionally turns out to involve a personal data breach or an insurance claim, and by then the imaging has already happened.

// secure disposal

Getting rid of media when you are done with it.

For hardware that is not coming back into service.

Deleting and formatting both leave data recoverable, and one method does not fit every device. A hard drive is overwritten and then verified. An SSD is cryptographically erased, because wear levelling keeps reserved blocks out of reach of any overwrite. A drive that no longer answers is destroyed physically, since nothing else can be confirmed.

Certificates record make, model, serial number, method and date — which is usually the actual deliverable, because it is what an auditor or the ICO asks to see. Your original device always comes back after a recovery unless you ask us to destroy it, and we confirm exactly what is being destroyed, by serial number, before doing anything irreversible.

// faq

Frequent questions.

Quick answers to what we're asked most.

No, at any stage. There is no offshore processing, no cloud staging in another jurisdiction, and no third-party lab abroad.

No. A good deal of UK data recovery is passed on to a handful of larger labs; ours is done in-house by our own engineers. Fewer hands, less transit, and a shorter list of people with access to your data.

No. Verification means confirming files open and the structure matches what you described, not examining content. On privileged material, tell us and we will take your instruction on how verification should be handled.

For a retention period you choose, after which working copies are securely destroyed. Some clients want a window in case something was missed; others want it gone immediately. It is your decision.

Yes. Signed exhibit records, logged movements, and hashes taken at acquisition and re-verified at each stage, so any alteration would be arithmetically demonstrable rather than a matter of assurance. Standard on forensic work, and available on any job that might later be scrutinised.

Both, as standard for business work. DPAs where personal data is involved, one named contact throughout, and everything kept in the UK.

// your data's safe with us

Want a recovery kept discreet?

A confidential business issue or personal files you can't replace — either way, it's in safe hands here in the UK. Kick off with a free diagnostic, or ask us about setting up an NDA first.