São Paulo, Brazil — GLCTech Group HQ, est. 2016 Salford, Greater Manchester, UK — GLCTech Sec operations
Trust & Compliance Centre

What's live, what's in progress, and what's available on request.

Built so you don't need to wait for a security questionnaire to find out where we stand. Anything marked "in progress" is a live commitment, not a vague ambition.

UK GDPR Data Processing Agreement

Our standard DPA covers how personal data is processed, stored and secured when you use our monitoring, security or backup services. Available for review before you sign anything else.

Available on request

Incident response & 72-hour ICO reporting

Our incident response process is built around the UK GDPR expectation of notifying the ICO within 72 hours of becoming aware of a qualifying breach, with a clear internal escalation path.

In place

Cyber Essentials

We're working towards Cyber Essentials certification as the baseline standard most UK SME procurement processes expect. This page will be updated the day it's confirmed.

In progress

Professional indemnity & cyber liability insurance

Certificates of currency and policy summaries are shared directly with prospective and existing clients as part of onboarding and renewal conversations.

Confirm with your account manager

Vendor-agnostic security selection

We maintain a shortlist of endpoint and network security platforms — including Kaspersky, Microsoft Defender for Business, Bitdefender GravityZone and Sophos — and document why a given platform was chosen for your environment.

Standard practice

UK & Brazil data protection basis

Our processes are built with UK GDPR as the primary basis for UK clients, with LGPD (Brazil's data protection law) understood group-wide from our origin market.

Documented

A note on Kaspersky

Kaspersky is one of several security platforms we can deploy, not our default. Some jurisdictions and some clients — particularly in the public sector or highly regulated industries — apply additional scrutiny to security software based on its country of origin, independent of any technical assessment. Where that matters to you, we'll deploy Microsoft Defender for Business, Bitdefender GravityZone or Sophos instead, and document the decision for your own compliance file. We're happy to talk through the trade-offs rather than make the choice for you silently.

Questions we get in procurement

If your security questionnaire, insurer or client asks something not covered on this page — data residency, sub-processors, penetration testing history, business continuity plans — ask us directly. We'd rather answer it in a call than have you guess.

Want to go through this together?

Book a free 30-minute Security Gap Assessment and we'll walk through exactly what applies to your environment.

Book an assessment