Last updated: June 2026
Pegasus Ops Ltd (“we”, “us”, or “our”) is a private security and risk management company incorporated and operating in the United Kingdom, with its principal place of business at:
275 New North Road
London
N1 7AA
United Kingdom
We are committed to protecting your privacy and handling personal data in a transparent and secure manner. This Privacy Policy explains how we collect, use, disclose, store and protect personal data when you visit pegasus-ops.com or contact us.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
When you contact us or submit a form on our website, we may collect:
When you visit pegasus-ops.com, we may automatically collect:
This information is collected using cookies and similar technologies. Please refer to our Cookie Policy for full details.
In the course of providing our security and risk management services, we may collect and process special category data and other sensitive personal information. This may include:
This category of data is collected and processed only where strictly necessary for the delivery of our services, with the explicit consent of the individual concerned or where we are legally permitted to do so under the Data Protection Act 2018 and UK GDPR Schedule 1. Such data is subject to enhanced security measures and strictly limited access controls.
We process personal data for the following purposes:
We process personal data based on one or more of the following legal grounds under UK GDPR:
Special Category Data
Where we process special category data in connection with our services, we rely on one or more of the following additional legal bases under UK GDPR Article 9 and the Data Protection Act 2018:
Criminal Records Data
Where our services involve the processing of criminal records data, including DBS checks and background screening, we process such data only where we have a legal basis under Schedule 1 of the Data Protection Act 2018 and where an appropriate policy document is in place as required by law.
Depending on the nature of the engagement, Pegasus Ops Ltd may act as either a data controller or a data processor.
Where we collect and determine the purpose and means of processing personal data independently, we act as a data controller.
Where we process personal data on behalf of a client who has determined the purpose and means of processing, we act as a data processor. In such circumstances, processing is governed by a written data processing agreement between Pegasus Ops Ltd and the client setting out the scope, nature and purpose of the processing, the type of personal data involved and the obligations of each party.
Clients who engage us to conduct surveillance, intelligence gathering or background screening activities retain responsibility as data controllers for ensuring that such activities are conducted lawfully and that appropriate notices have been provided to data subjects where required.
Our website uses cookies and similar technologies to ensure proper functionality and to analyse website traffic.
Essential Cookies
These cookies are necessary for the website to function and cannot be disabled. They do not store any personally identifiable information.
Analytical Cookies
We use Google Analytics, a web analytics service provided by Google LLC, to understand how visitors interact with our website and to improve our services. Google Analytics uses cookies to collect information such as:
Where technically feasible, IP addresses are anonymised before storage. Data collected through Google Analytics may be transferred to and processed on servers located outside the United Kingdom, including in the United States.
You can control or disable cookies through your browser settings or by using Google’s opt-out tools available at tools.google.com/dlpage/gaoptout. Non-essential cookies are only used where you have provided consent via our cookie banner on pegasus-ops.com.
Please refer to our Cookie Policy for a full list of cookies used on this website.
We do not sell personal data under any circumstances.
We may share personal data with:
All third parties are contractually required to process personal data securely and only for the purposes specified by us.
Given the sensitive nature of our services and the clients we serve, we apply enhanced due diligence to all third parties with whom personal data is shared. No personal data relating to our clients or the subjects of any investigation or assessment is shared with any third party without explicit authorisation.
As we serve international clients, personal data may in some circumstances be transferred to, stored or processed in countries outside the United Kingdom.
Where such transfers occur, we take all reasonable steps to ensure that personal data is protected through appropriate safeguards, adequacy decisions or standard contractual clauses in accordance with UK GDPR requirements.
We retain personal data only for as long as necessary to:
Enquiry data submitted via our website is retained for a period of 24 months from the date of receipt. Client engagement data including contracts, correspondence and service records is retained for the duration of the engagement and for a period of 6 years thereafter in accordance with UK legal requirements. Security risk assessments, threat intelligence reports and vetting records are retained only for the period specified in the relevant client agreement and are securely destroyed upon expiry of that period.
When personal data is no longer required it is securely deleted or anonymised in accordance with our internal data destruction procedures.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Given the nature of our business and the clients we serve, data security is treated as a primary operational concern and not merely a compliance requirement.
These measures include:
Despite these measures, no method of electronic transmission or storage is completely secure and we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Information Commissioner’s Office (ICO) in accordance with our legal obligations under UK GDPR Article 33 and 34.
Under UK GDPR you have the right to:
All requests will be responded to within one calendar month of receipt. Please note that certain rights may be limited where we are processing personal data for the purposes of the prevention, investigation or detection of crime, or where disclosure would prejudice an ongoing operation or legal proceeding.
To exercise any of these rights please contact us using the details provided in section 14.
Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors through our website.
Where our services involve the protection or safeguarding of children at the instruction of a parent, guardian or family office, personal data relating to minors is processed only to the extent strictly necessary for the delivery of those services, with the consent of the parent or legal guardian, and is subject to the highest level of security and confidentiality controls.
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites and encourage you to review their respective privacy policies before providing any personal data.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on pegasus-ops.com with a revised last updated date. We encourage you to review this page periodically.
If you have any questions about this Privacy Policy or our data protection practices please contact us:
Pegasus-Ops Ltd
Email: [email protected]
Telephone: +44 20 8050 7106
Address: 275 New North Road, London, N1 7AA, United Kingdom