Last Updated: 14 August 2025
Policy Owner: Amit Patel, Director

1. Purpose

This policy outlines how Count Creation protects client and business data, maintains cyber security, and ensures compliance with the UK General Data Protection Regulation (UK GDPR) and other relevant laws.

2. Scope

This policy applies to:
• All staff, contractors, and partners working with Count Creation.
• All devices, systems, and services used for storing, processing, or transmitting data.

3. Data Protection
• Lawful use: Personal data is collected and used only for agreed business purposes.
• Data minimisation: We only collect the information we need.
• Secure storage: All client data is stored on encrypted, password-protected systems.
• Data sharing: We do not share client data with third parties without consent, except when legally required.
• Retention & disposal: Data is kept only as long as necessary and securely deleted when no longer needed.

4. Cyber Security Practices
• Access control: Systems and files are accessible only to authorised users.
• Password security: Strong, unique passwords and multi-factor authentication (MFA) are used wherever possible.
• Device security: All devices have up-to-date antivirus and firewall protection.
• Network security: Secure Wi-Fi with strong encryption is used for all business activities.
• Software updates: All systems and applications are updated promptly to apply security patches.

5. Incident Response

If a data breach or cyber incident occurs:
1. Contain the breach immediately.
2. Notify the Director and affected clients within 72 hours.
3. Investigate the cause and take corrective action.
4. Document the incident and lessons learned.

6. Training & Awareness

All staff and contractors are briefed on this policy and understand their responsibilities in keeping data secure.

7. Compliance & Review
• This policy will be reviewed annually or when there are significant changes to business processes or regulations.
• Count Creation aims to maintain recognised cyber security standards, such as Cyber Essentials certification.

Signed:
Amit Patel
Director, Count Creation