Data Protection

    Data Protection Built Into How We Operate

    Security and data protection are embedded into For-Sight's platform architecture, operational processes, and organisational culture. Our ISO-certified management systems provide the framework for continuous, verifiable protection.

    Certified
    ISO 27001
    Certified
    ISO 9001
    Hosted
    UK & EU

    For-Sight as Processor

    For-Sight operates as a GDPR-aligned data processor. We process data only as instructed by customers under documented agreements.

    Customers as Controllers

    Our customers remain data controllers for their guest data. Lawful basis, consent, and data subject rights are customer responsibilities.

    Clearly Defined

    Responsibilities are documented in our Data Processing Agreement. Security is a shared responsibility with clear boundaries.

    Certifications & Independent Assurance

    Our certifications are actively maintained and independently audited. They represent ongoing operational discipline, not one-off achievements.

    ISO 27001 – Information Security

    Provides independent validation of our information security management system. Covers risk management, access controls, incident response, and continuous improvement. Audited annually by Citation.

    ISO 9001 – Quality Management

    Ensures consistent service quality and reliable delivery. Covers process documentation, customer focus, and continuous improvement. Audited annually by Citation.

    Citation ISO Certification badge for ISO 27001:2022 information security management — Certificate No. 357542021Citation ISO Certification badge for ISO 9001:2015 quality management — Certificate No. 357532021

    How We Protect Your Data

    Enforced controls across the platform protect your data throughout its lifecycle. These are operational realities, not policy statements.

    Encryption

    Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Encryption is enforced at the infrastructure level with no opt-out.

    Access Controls

    Role-based access with least-privilege principles. Multi-factor authentication is enforced for all staff access. Permissions are reviewed regularly.

    Data Residency

    All data is hosted in UK and EU Microsoft Azure data centres. No data is transferred outside these jurisdictions without explicit agreement.

    Data Segregation

    Per-customer logical segregation is enforced at both application and database levels. Customer data is never co-mingled.

    Monitoring & Audits

    Continuous monitoring with regular internal reviews. External audits are conducted annually in line with ISO 27001 certification requirements.

    Vulnerability Management

    We use a risk-based approach to identify and manage vulnerabilities, with regular security assessments and reviews. Issues are prioritised, tracked, and resolved in line with risk and agreed service levels.

    Governance & Accountability

    Security and compliance ownership is clearly assigned and actively managed, not delegated to policy documents.

    Named Ownership

    Dedicated security and compliance roles with clear accountability for controls and certifications.

    Risk Management

    Formal risk registers and Data Protection Impact Assessments inform control decisions and priorities.

    Policy Review

    Security policies are reviewed annually and updated in response to changes in risk or regulation.

    Incident Readiness

    Documented incident response procedures are tested and maintained as part of ISO 27001 compliance.

    Incident Response

    A formal incident response process is in place and documented. In the event of a security incident, our team assesses impact, contains the issue, and initiates remediation. Where a personal data breach occurs, notification to affected customers and relevant authorities is made within GDPR-required timeframes. Our process is aligned with ISO 27001 requirements and tested regularly.

    Security as a Shared Responsibility

    Strong security outcomes require clear responsibilities on both sides. Here's how we divide them.

    For-Sight Is Responsible For

    • Platform security, encryption, and access controls
    • Infrastructure monitoring and vulnerability management
    • Data residency and logical segregation
    • Incident detection, response, and notification
    • Maintaining ISO certifications and audit readiness

    Customers Are Responsible For

    • Lawful basis and consent for data collection
    • Managing user access and credentials within the platform
    • Responding to data subject rights requests
    • Accuracy and appropriateness of data entered
    • Training staff on secure use of the platform

    Frequently Asked Questions

    Common questions from procurement, legal, and IT security teams.

    All For-Sight customer data is hosted in Microsoft Azure data centres located in the UK and EU. Our hosting locations are designed to support data protection and regulatory requirements and are documented in our Data Processing Agreement.

    Access to customer data is tightly controlled and limited to authorised For-Sight team members who need it to support the service. Access is role-based, protected with multi-factor authentication, and regularly reviewed to help ensure data is handled securely and responsibly.

    Customer data is logically segregated at both application and database level to prevent cross-customer access. These controls form part of our ISO 27001-certified security framework and are reviewed regularly as part of our assurance activities.

    We maintain a structured incident response process aligned with ISO 27001 and GDPR principles. If a security incident occurs, it is assessed and contained promptly. Where required, affected customers are informed in a timely and transparent way, in line with regulatory expectations.

    For-Sight operates as a data processor under GDPR. We support our customers through contractual safeguards, documented processes, and practical controls that help protect personal data. This includes providing a Data Processing Agreement, supporting data subject rights requests where appropriate, and maintaining records that support accountability.

    Yes. A comprehensive Data Processing Agreement is provided as part of onboarding and outlines our responsibilities as a data processor, alongside your role as data controller. If you need a signed copy or have questions about the agreement, our team is happy to help.

    ISO 27001 and ISO 9001 certifications are available on request. If you need copies of certificates, security questionnaires, or additional assurance information, our team can support you as part of standard procurement and due-diligence processes.

    Security & Procurement Enquiries

    For security questionnaires, Data Processing Agreements, audit documentation, or other procurement-related queries, contact our security team. We respond to standard security questionnaires as part of normal enterprise operations.