PRIVACY POLICY

Last updated: June 2026

1. Introduction

Pegasus Ops Ltd (“we”, “us”, or “our”) is a private security and risk management company incorporated and operating in the United Kingdom, with its principal place of business at:

275 New North Road
London
N1 7AA
United Kingdom

We are committed to protecting your privacy and handling personal data in a transparent and secure manner. This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit pegasus-ops.com or contact us.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Personal Data We Collect

2.1 Data You Provide Directly

When you contact us or submit a form on our website, we may collect:

  • Full name
  • Email address
  • Phone number
  • Company name and job title
  • Nature of your enquiry
  • Message content and any other information you voluntarily provide

2.2 Automatically Collected Data

When you visit pegasus-ops.com, we may automatically collect:

  • IP address
  • Browser type and version
  • Device and operating system information
  • Pages visited and time spent on the website
  • Referring and exit URLs

 

This information is collected using cookies and similar technologies. Please refer to our Cookie Policy for full details.

2.3 Special Category and Sensitive Data

In the course of providing our security and risk management services, we may collect and process special category data and other sensitive personal information. This may include:

  • Personal risk profiles and threat assessments
  • Location data and movement patterns
  • Family composition and household information
  • Health and medical information where relevant to protective planning
  • Background screening and vetting information including criminal records data where legally permitted
  • Information relating to legal proceedings or sensitive personal circumstances

 

This category of data is collected and processed only where strictly necessary for the delivery of our services, with the explicit consent of the individual concerned or where we are legally permitted to do so under the Data Protection Act 2018 and UK GDPR Schedule 1. Such data is subject to enhanced security measures and strictly limited access controls.

3. Purpose of Processing

We process personal data for the following purposes:

  • To respond to enquiries and communicate with you
  • To provide and manage security and risk management services
  • To manage and maintain business relationships
  • To operate, maintain and improve our website
  • To analyse website usage and performance
  • To comply with legal and regulatory obligations
  • To protect our legal rights and prevent misuse of our website and services

4. Legal Basis for Processing

We process personal data based on one or more of the following legal grounds under UK GDPR:

  • Your consent
  • The performance of a contract or pre-contractual measures at your request
  • Compliance with a legal obligation
  • Our legitimate business interests, provided such interests do not override your fundamental rights and freedoms

 

Special Category Data

Where we process special category data in connection with our services, we rely on one or more of the following additional legal bases under UK GDPR Article 9 and the Data Protection Act 2018:

  • Explicit consent of the data subject
  • Processing necessary for reasons of substantial public interest under Schedule 1 of the Data Protection Act 2018
  • Processing necessary for the establishment, exercise or defence of legal claims
  • Processing necessary to protect the vital interests of the data subject or another person where the data subject is physically or legally incapable of giving consent

 

Criminal Records Data

Where our services involve the processing of criminal records data, including DBS checks and background screening, we process such data only where we have a legal basis under Schedule 1 of the Data Protection Act 2018 and where an appropriate policy document is in place as required by law.

5. Data Controller and Data Processor

Depending on the nature of the engagement, Pegasus Ops Ltd may act as either a data controller or a data processor.

Where we collect and determine the purpose and means of processing personal data independently, we act as a data controller.

Where we process personal data on behalf of a client who has determined the purpose and means of processing, we act as a data processor. In such circumstances, processing is governed by a written data processing agreement between Pegasus Ops Ltd and the client setting out the scope, nature and purpose of the processing, the type of personal data involved and the obligations of each party.

Clients who engage us to conduct surveillance, intelligence gathering or background screening activities retain responsibility as data controllers for ensuring that such activities are conducted lawfully and that appropriate notices have been provided to data subjects where required.

6. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to ensure proper functionality and to analyse website traffic.

Essential Cookies

These cookies are necessary for the website to function and cannot be disabled. They do not store any personally identifiable information.

Analytical Cookies

We use Google Analytics, a web analytics service provided by Google LLC, to understand how visitors interact with our website and to improve our services. Google Analytics uses cookies to collect information such as:

  • IP address
  • Browser and device information
  • Pages visited and interaction data

 

Where technically feasible, IP addresses are anonymised before storage. Data collected through Google Analytics may be transferred to and processed on servers located outside the United Kingdom, including in the United States.

You can control or disable cookies through your browser settings or by using Google’s opt-out tools available at tools.google.com/dlpage/gaoptout. Non-essential cookies are only used where you have provided consent via our cookie banner on pegasus-ops.com.

Please refer to our Cookie Policy for a full list of cookies used on this website.

7. Data Sharing and Disclosure

We do not sell personal data under any circumstances.

We may share personal data with:

  • Trusted service providers including website hosting, IT services and analytics providers
  • Professional advisers including legal, accounting and compliance professionals
  • Regulatory authorities or law enforcement bodies where required by applicable law
  • Other security or intelligence professionals engaged as part of service delivery, subject to confidentiality obligations

 

All third parties are contractually required to process personal data securely and only for the purposes specified by us.

Given the sensitive nature of our services and the clients we serve, we apply enhanced due diligence to all third parties with whom personal data is shared. No personal data relating to our clients or the subjects of any investigation or assessment is shared with any third party without explicit authorisation.

8. International Data Transfers

As we serve international clients, personal data may in some circumstances be transferred to, stored or processed in countries outside the United Kingdom.

Where such transfers occur, we take all reasonable steps to ensure that personal data is protected through appropriate safeguards, adequacy decisions or standard contractual clauses in accordance with UK GDPR requirements.

9. Data Retention

We retain personal data only for as long as necessary to:

  • Fulfil the purposes described in this Privacy Policy
  • Meet legal, regulatory and contractual obligations

 

Enquiry data submitted via our website is retained for a period of 24 months from the date of receipt. Client engagement data including contracts, correspondence and service records is retained for the duration of the engagement and for a period of 6 years thereafter in accordance with UK legal requirements. Security risk assessments, threat intelligence reports and vetting records are retained only for the period specified in the relevant client agreement and are securely destroyed upon expiry of that period.

When personal data is no longer required it is securely deleted or anonymised in accordance with our internal data destruction procedures.

10. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Given the nature of our business and the clients we serve, data security is treated as a primary operational concern and not merely a compliance requirement.

These measures include:

  • Encrypted transmission and storage of personal data
  • Strictly limited access controls on a need-to-know basis
  • Regular review and testing of our security practices and systems
  • Confidentiality obligations imposed on all personnel and contractors
  • Secure destruction of physical and digital records when no longer required

 

Despite these measures, no method of electronic transmission or storage is completely secure and we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Information Commissioner’s Office (ICO) in accordance with our legal obligations under UK GDPR Article 33 and 34.

11. Your Rights

Under UK GDPR you have the right to:

  • Request access to your personal data
  • Request correction of inaccurate or incomplete data
  • Request deletion of your personal data
  • Withdraw consent where processing is based on consent
  • Object to or request restriction of certain processing activities
  • Data portability where processing is carried out by automated means
  • Lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk

 

All requests will be responded to within one calendar month of receipt. Please note that certain rights may be limited where we are processing personal data for the purposes of the prevention, investigation or detection of crime, or where disclosure would prejudice an ongoing operation or legal proceeding.

To exercise any of these rights please contact us using the details provided in section 14.

12. Children's Data

Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors through our website.

Where our services involve the protection or safeguarding of children at the instruction of a parent, guardian or family office, personal data relating to minors is processed only to the extent strictly necessary for the delivery of those services, with the consent of the parent or legal guardian, and is subject to the highest level of security and confidentiality controls.

13. Third-Party Websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites and encourage you to review their respective privacy policies before providing any personal data.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on pegasus-ops.com with a revised last updated date. We encourage you to review this page periodically.

15. Contact Us

If you have any questions about this Privacy Policy or our data protection practices please contact us:

Pegasus-Ops Ltd

Email: [email protected]

Telephone: +44 20 8050 7106

Address: 275 New North Road, London, N1 7AA, United Kingdom