Legal
Information security policy
Scope
This policy summarises the controls FixSpotter Ltd applies to the information it handles: client and partner contact details, campaign settings and reports, contracts and billing records, and the systems used to deliver software and equipment projects.
Principles
- Least access. Only the people working on an engagement have access to its data. Access is removed when the engagement ends.
- Encryption. Data is transmitted over TLS and stored on encrypted, access-controlled systems.
- Client-owned measurement. Campaign attribution runs in the client’s own platform. FixSpotter works with access granted by the client and does not copy end-user data into its own systems.
- Credentials. Multi-factor authentication is required on all business accounts. Shared passwords are not used; secrets are stored in a password manager.
- Devices. Company devices are encrypted, kept up to date and can be remotely wiped.
- Hosting. This website and delivered projects are hosted with providers in the European Union, behind a firewall, with automatic security updates and no unnecessary services.
- Software delivery. Code is kept in version control; credentials and documentation are handed over to the client and rotated at handover.
- Suppliers. Providers that process data on our behalf are bound by written agreements.
Incidents
Suspected incidents are reported to info@fixspotter.com and assessed the same business day. Affected clients or partners are informed without undue delay, and regulators where the law requires.
Review
This policy is reviewed at least annually and when our systems change.
Last updated 2026-09-13