Flexify Ltd Get in touch
Security & trust

Security & Trust

Trust isn’t a badge — it’s how a company handles your data, your access and your code when no one’s watching. Flexify builds and runs its own software, which means we hold client work to the same security standards we depend on ourselves. This page sets out, plainly, how we protect what you hand us and how to reach us if something looks wrong.

Entity
Flexify Ltd, England & Wales
Company no.
16871618
Data
UK GDPR aligned
Disclosure
Responsible, no legal action
How we work

Ethics first, even when it costs us the invoice

We do honest work, and we say no to work that isn’t. We won’t build deceptive patterns, scrape data unlawfully, buy fake reviews, or ship grey-hat SEO that risks your domain. We tell you the truth about scope and risk even when it costs us the bigger invoice, and we don’t take on projects that would harm your customers or ours.

If a request crosses a legal or ethical line, we’ll explain why and offer a route that doesn’t.

Our controls

What we commit to, in detail

Five domains, stated plainly enough that you can hold us to them.

Data protection & privacy

We treat personal data as something we’re borrowing, not something we own.

UK GDPR aligned
We handle personal data in line with UK GDPR and the Data Protection Act 2018 — lawful basis, data minimisation, purpose limitation and your data-subject rights.
Only what’s needed
We ask for the minimum access and data required to do the job, and no more.
Encryption in transit
Data is encrypted in transit over TLS across every site and application we run.
Retention & deletion
We keep project data only as long as the engagement and legal obligations require. Ask us to remove your data and we will, then confirm when it is done.
Sub-processors
Where we use third-party services to deliver your project, we choose reputable, GDPR-compliant providers. The current list is available on request.
Payment data
We never store your customers’ card details. Payments run through PCI-DSS-compliant providers such as Shopify Payments and Stripe, so card data stays with the processor, not with us.

Infrastructure

The systems we operate are built to survive real-world faults, not just the happy path.

Reputable hosting
We deploy to established cloud and hosting providers with their own physical and network security.
Encryption everywhere it matters
HTTPS/TLS across sites and apps; secrets and credentials stored securely, never committed to code.
Backups & continuity
Regular backups of the systems we run, so data can be restored after failure.
Resilient by design
We build integrations and apps with retries, timeouts and reconciliation, so a transient fault does not become data loss.
Monitoring
The products we operate are monitored for availability and errors, so problems are caught early.

Access control

Least privilege, applied to our systems and yours.

Least privilege
People get the minimum access needed for their role, and no standing access they don’t use.
Strong authentication
Multi-factor authentication on the accounts and admin panels we control; unique credentials, never shared logins.
Your systems stay yours
We ask for scoped, revocable access, and prefer that you add and remove us rather than share master passwords. When a project ends, our access is removed.
Secure development
Code review, dependency updates and secure coding practices; secrets kept out of repositories.

Compliance

What we are held to, stated without embellishment.

UK GDPR & DPA 2018
The framework we work to for all personal data.
PCI-DSS by design
Card data is handled only by compliant payment processors and never stored by us.
Platform standards
We build to Shopify’s app and data requirements, and to other platform rules where your project touches them.
Aligned, not certified
Our controls are aligned with widely recognised security frameworks. We will display a formal certification only once it is genuinely held.
Incident response

If something goes wrong, silence is the worst response

  1. 01

    Detect & contain

    We act quickly to stop the issue spreading and limit impact.

  2. 02

    Assess

    We work out what happened, what data or systems were affected, and the root cause.

  3. 03

    Notify

    We tell affected clients promptly and, where a personal-data breach requires it, support notification to the ICO within the timelines UK GDPR sets.

  4. 04

    Fix & learn

    We remediate, then change what let it happen so it doesn’t recur — and share a plain-English account with you.

Responsible disclosure

Found a security issue? Tell us first.

We welcome reports from security researchers and users. If you believe you’ve found a security issue in our website, our products or a site we run, please tell us before disclosing it publicly, and give us reasonable time to fix it.

/.well-known/security.txt
Contact security@flexify.ltd

What to include

  • Where you found it
  • How to reproduce it
  • The potential impact

What we ask

  • Don’t access or modify data that isn’t yours
  • Don’t run attacks that degrade service — no DDoS or spam
  • Don’t disclose publicly until we’ve resolved it

We’ll acknowledge your report, keep you updated, and fix confirmed issues promptly. Acting in good faith within these rules, we won’t pursue legal action against you — and we’re happy to credit you once the issue is resolved.

Questions

What clients ask before sharing access

Is Flexify GDPR compliant?

Yes. Flexify handles personal data in line with UK GDPR and the Data Protection Act 2018 — using a lawful basis, collecting only what’s needed, encrypting data in transit, and honouring data-subject rights. Where you handle personal data, we sign a Data Processing Agreement setting out our obligations as your processor.

How does Flexify protect my data?

We apply least-privilege access with multi-factor authentication, encrypt data in transit, keep secrets out of code, back up the systems we run, and use only reputable GDPR-compliant providers. We never store customer card data — payments run through PCI-DSS-compliant processors.

How do I report a security vulnerability to Flexify?

Email security@flexify.ltd with where you found the issue, how to reproduce it, and its impact. Please don’t access data that isn’t yours or disclose publicly until we’ve fixed it. We acknowledge every report, fix confirmed issues promptly, and won’t pursue good-faith researchers who follow these rules.

Does Flexify sign an NDA?

Yes. We sign your NDA on request and treat your business, code and data as confidential as standard — before, during and after the engagement. Flexify Ltd is a UK-registered company (no. 16871618), so there’s an accountable legal entity behind that commitment.

Who owns the code and IP Flexify builds?

You do. On full payment, the intellectual property in the work we build for you transfers to you. Your code and your data are yours to keep, move or take elsewhere.

Questions about how we handle your data?

Ask before you share access. We’ll answer specifically, and put it in writing.

Chat on WhatsApp