I
ISOvault
Product How it works Compare Pricing Templates FAQ
Start free trial
Legal

Privacy Policy

Last updated: 6 July 2026

This policy explains what personal data we collect through the ISOvault website and application, why we collect it, and the rights you have over it. We have written it in plain English, because a privacy policy you cannot understand protects nobody.

1. Who we are

ISOvault is a trading name of Mayne Consulting Ltd, a company registered in England and Wales (company number 14618424) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

For the personal data described in this policy, Mayne Consulting Ltd is the data controller. You can contact us about anything in this policy at privacy.isovault@agentmail.to.

Controller and processor: an important distinction. This policy covers the personal data we control, such as your account details and website enquiries. The content you store inside ISOvault, including your policies, risk registers, asset registers and any personal data they contain, belongs to you. For that content we act only as a processor on your instructions, under our Data Processing Agreement.

2. The data we collect

Website visitors

Our marketing website uses cookie-free, privacy-focused analytics. It gives us aggregate information such as page views, referral sources and country-level location. It does not use cookies, does not build individual profiles, does not track you across other sites and does not collect your IP address in any form we can read. This is why our website has no cookie banner: there is nothing to consent to.

Like almost all websites, our hosting infrastructure keeps standard server logs, which include IP addresses. We retain these for a short period for security and troubleshooting only.

Waitlist and trial sign-ups

If you join our waitlist or start a trial, we collect your name, work email address and company name. We use these to set up your workspace and to contact you about your trial and the product.

Account users

When you use the ISOvault application we hold your name, work email address, role and workspace permissions, together with login and activity records needed to run the service securely. Authentication is handled by our identity provider, Auth0.

Billing contacts

Payments are handled by Stripe. We hold your billing contact details and invoice history. We never see or store your full card details; those go directly to Stripe.

Correspondence

If you email us, we keep the correspondence for as long as we need it to help you and to keep a record of the discussion.

3. Why we collect it, and our lawful bases

PurposeData usedLawful basis (UK GDPR)
Providing and administering the ISOvault serviceAccount, login and billing dataPerformance of a contract
Responding to enquiries and providing supportContact details, correspondenceLegitimate interests
Securing the service, preventing fraud and abuseLogin records, server logsLegitimate interests
Sending product updates to trial and waitlist sign-upsName, emailLegitimate interests, with an unsubscribe link in every email
Sending marketing emails to anyone elseName, emailConsent, which you can withdraw at any time
Understanding aggregate website usageAnonymous, cookie-free analyticsLegitimate interests
Invoicing, accounting and taxBilling dataLegal obligation

4. Cookies

The marketing website sets no cookies. The ISOvault application sets only the essential cookies required to keep you securely signed in. We do not use advertising cookies, tracking pixels or third-party marketing tags anywhere.

5. Who we share data with

We do not sell personal data, and we do not share it with advertisers. We share it only with:

  • Our sub-processors, the small number of service providers who help us run ISOvault, such as our hosting and authentication providers. The current list, including what each one does and where it processes data, is published in our sub-processor register.
  • Stripe, our payment provider, which processes billing data on our behalf and processes payment and card data as an independent controller for payment services, fraud prevention and financial compliance.
  • Professional advisers, such as accountants and solicitors, where necessary.
  • Authorities, where we are legally required to do so.

6. International transfers

Customer data, documents and backups are hosted in the United Kingdom (London). Some of our sub-processors are based outside the UK. Where personal data leaves the UK we rely on UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as set out in the sub-processor register.

7. How long we keep data

  • Account data: for the life of your subscription, then deleted within 90 days of termination, in line with our DPA.
  • Waitlist and trial data: until you ask us to remove it, or after a prolonged period of inactivity.
  • Billing records: six years, as required by UK tax law.
  • Server logs: a rolling short-term window, typically no more than 90 days.
  • Correspondence: as long as reasonably needed for the matter it relates to.

8. Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to our processing in certain circumstances;
  • receive your data in a portable format;
  • withdraw consent at any time, where consent is our lawful basis.

To exercise any of these rights, email privacy.isovault@agentmail.to. We will respond within one month.

If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve your concern first.

9. Security

ISOvault is a product built for information security professionals, and we hold ourselves to the standard our customers are certified against. Data is encrypted in transit and at rest, every customer has isolated database and document storage, and access is controlled and logged. Full details are on our security page.

10. Children

ISOvault is a business product and is not directed at anyone under 18. We do not knowingly collect data about children.

11. Changes to this policy

If we make material changes we will update the date at the top of this page and, for significant changes affecting account holders, notify you by email. Minor clarifications may be made without notice.

12. Contact

Mayne Consulting Ltd (trading as ISOvault)
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
privacy.isovault@agentmail.to

I
ISOvault

Simple ISO 27001 document and evidence management software for small businesses. Made in London.

Product

  • Features
  • Pricing
  • Compare
  • Security

Templates

  • Risk register
  • Statement of Applicability
  • Evidence tracker
  • Internal audit checklist

Legal

  • Privacy policy
  • Terms & conditions
  • Data Processing Agreement
  • Sub-processor register
© 2026 ISOvault is a trading name of Mayne Consulting Ltd, registered in England and Wales, No. 14618424. isovault.co.uk