Privacy Policy
Last updated: 14 September 2026
This policy explains how Nettorra handles personal information when you visit nettorra.com, use seo.nettorra.com or secure.nettorra.com, ask Mia for a quotation, contact us or become a client.
1. Who we are
Nettorra is a digital services business operating from Surrey, United Kingdom and serving clients globally. Nettorra is the data controller for the personal information described in this policy.
For privacy questions or requests, email enquiry@nettorra.com.
2. Information we collect
We collect only the information reasonably needed to respond to you, provide our services and operate our websites.
- Contact and business details: your name, email address, telephone number, company, website and the information you include in an enquiry.
- Quotation and project information: the services you select, your brief, budget indicators, preferred timing, workflow answers and Mia’s resulting estimate.
- SEO information: a website address submitted for an audit, publicly available information retrieved from that website, audit findings, your name, email, company and any separate marketing choice.
- N-Secure information: the website address you submit, publicly observable website responses and security configuration, automated findings, scan time and your confirmation that you are authorised to assess the website. If you request remediation, we also collect your name, work email, company, authority confirmation, contact consent and the findings sent for human review.
- Client and transaction records: proposals, contracts, correspondence, project materials, invoices, payment status and service history. We do not collect complete payment-card details through this website.
- Technical information: basic request, security and diagnostic information supplied by hosting infrastructure, which may include IP address, browser or device information and timestamps.
- Browser storage: the cookie preference saved on your device and a session marker used to avoid repeating the homepage introduction.
We normally receive information directly from you. The SEO audit and N-Secure check also retrieve publicly available information from the website address you choose to submit. N-Secure does not require login credentials or attempt to access private areas of the submitted website.
3. How and why we use personal information
| Purpose | Usual lawful basis |
|---|---|
| Answer enquiries, prepare quotations and take requested steps before a contract | Steps at your request before entering a contract; legitimate interests in responding to business enquiries |
| Provide, manage and support purchased services | Performance of a contract |
| Run the SEO audit and deliver a requested report | Steps at your request before entering a contract; legitimate interests in providing and improving the requested tool |
| Run an authorised N-Secure check, provide the requested report and prevent misuse | Steps at your request before entering a contract; legitimate interests in providing a secure and reliable tool |
| Review N-Secure findings and prepare a remediation proposal when requested | Steps at your request before entering a contract; legitimate interests in responding to the remediation enquiry |
| Maintain business, tax and accounting records | Legal obligations and legitimate interests |
| Protect our services, prevent misuse and diagnose faults | Legitimate interests in security and reliable operations |
| Send optional news or marketing | Consent, where requested; you may withdraw it at any time |
Where we rely on legitimate interests, we consider the business need, necessity and likely effect on you. We do not sell personal information.
4. Mia and automated recommendations
Mia uses the answers you provide and published Nettorra pricing rules to create a starting estimate and, for AI Automation, a suggested workflow. It does not make solely automated decisions that have legal or similarly significant effects. Every quotation is non-binding and is reviewed by a person before Nettorra confirms scope, timing or price.
6. International services and transfers
Nettorra serves clients globally and some technology providers may process information outside the United Kingdom. Where UK data-protection transfer rules apply, we use an applicable lawful mechanism, such as UK adequacy regulations or approved contractual safeguards. You may contact us for more information about the safeguards relevant to your information.
7. How long we keep information
- Enquiries and unaccepted quotations: normally up to 24 months after the last meaningful contact.
- Client, contract, invoice and project records: for the relationship and normally up to seven years afterwards where needed for tax, legal or contractual records.
- SEO audit and report requests: normally up to 24 months so we can deliver, support and compare the requested service.
- N-Secure checks: ordinary scan results are processed to return the requested report and are not intentionally added to Nettorra’s enquiry database. If you request remediation, the request, authority confirmation and submitted findings are normally kept for up to 24 months after the last meaningful contact. Hosting and security logs may be retained temporarily as described below.
- Optional marketing records: until you withdraw consent or after 24 months without meaningful engagement, unless a minimal suppression record is needed to respect an opt-out.
- Technical and security records: only for as long as reasonably needed for security, troubleshooting and provider operations, normally no longer than 12 months.
We may keep information longer where a legal obligation, dispute, fraud-prevention need or active client relationship requires it. We delete or anonymise it when it is no longer needed.
8. Security
We use proportionate technical and organisational measures designed to protect personal information, including controlled access, encrypted connections and reputable service providers. No internet service can guarantee absolute security, so please do not send passwords, complete payment-card details or unnecessary sensitive information through an enquiry form.
9. Your rights
Depending on the circumstances, UK data-protection law may give you the right to:
- ask for a copy of your personal information;
- correct inaccurate or incomplete information;
- ask for deletion or restriction;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format; and
- withdraw consent at any time where consent is the lawful basis.
To exercise a right, email enquiry@nettorra.com. We may need to verify your identity. These rights are not absolute, and we will explain if an exemption applies.
You may object at any time to direct marketing. You may also object to other processing based on legitimate interests by explaining your particular situation.
If you are unhappy with our response, you may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint/. If another data-protection authority applies where you live, you may also have the right to contact that authority.
11. Children
Nettorra’s business services are not directed at children, and we do not knowingly request personal information from anyone under 18 through this website.
12. Changes to this policy
We may update this policy when our services, providers or legal obligations change. The date at the top shows the latest revision. Where a change materially affects how we use existing personal information, we will take reasonable steps to bring it to the attention of affected people.
