Security & Trust
Trust isn’t a badge — it’s how a company handles your data, your access and your code when no one’s watching. Flexify builds and runs its own software, which means we hold client work to the same security standards we depend on ourselves. This page sets out, plainly, how we protect what you hand us and how to reach us if something looks wrong.
- Entity
- Flexify Ltd, England & Wales
- Company no.
- 16871618
- Data
- UK GDPR aligned
- Disclosure
- Responsible, no legal action
Ethics first, even when it costs us the invoice
We do honest work, and we say no to work that isn’t. We won’t build deceptive patterns, scrape data unlawfully, buy fake reviews, or ship grey-hat SEO that risks your domain. We tell you the truth about scope and risk even when it costs us the bigger invoice, and we don’t take on projects that would harm your customers or ours.
If a request crosses a legal or ethical line, we’ll explain why and offer a route that doesn’t.
What we commit to, in detail
Five domains, stated plainly enough that you can hold us to them.
Legal & contractual protection
Every engagement is put in writing before work starts — scope, deliverables, liability and confidentiality, plus a Data Processing Agreement where you handle personal data.
- Confidentiality & NDAs
- We sign your NDA on request, and keep your business, code and data confidential as standard — before, during and after the engagement.
- You own your IP
- On full payment, intellectual property in the work we build for you transfers to you. Your code and data are yours.
- UK-registered entity
- Flexify Ltd is registered in England and Wales, company no. 16871618 — a real, accountable legal entity, not an anonymous freelancer.
- Data Processing Agreement
- Where you handle personal data, a DPA sets out our obligations as your processor under UK GDPR.
Data protection & privacy
We treat personal data as something we’re borrowing, not something we own.
- UK GDPR aligned
- We handle personal data in line with UK GDPR and the Data Protection Act 2018 — lawful basis, data minimisation, purpose limitation and your data-subject rights.
- Only what’s needed
- We ask for the minimum access and data required to do the job, and no more.
- Encryption in transit
- Data is encrypted in transit over TLS across every site and application we run.
- Retention & deletion
- We keep project data only as long as the engagement and legal obligations require. Ask us to remove your data and we will, then confirm when it is done.
- Sub-processors
- Where we use third-party services to deliver your project, we choose reputable, GDPR-compliant providers. The current list is available on request.
- Payment data
- We never store your customers’ card details. Payments run through PCI-DSS-compliant providers such as Shopify Payments and Stripe, so card data stays with the processor, not with us.
Infrastructure
The systems we operate are built to survive real-world faults, not just the happy path.
- Reputable hosting
- We deploy to established cloud and hosting providers with their own physical and network security.
- Encryption everywhere it matters
- HTTPS/TLS across sites and apps; secrets and credentials stored securely, never committed to code.
- Backups & continuity
- Regular backups of the systems we run, so data can be restored after failure.
- Resilient by design
- We build integrations and apps with retries, timeouts and reconciliation, so a transient fault does not become data loss.
- Monitoring
- The products we operate are monitored for availability and errors, so problems are caught early.
Access control
Least privilege, applied to our systems and yours.
- Least privilege
- People get the minimum access needed for their role, and no standing access they don’t use.
- Strong authentication
- Multi-factor authentication on the accounts and admin panels we control; unique credentials, never shared logins.
- Your systems stay yours
- We ask for scoped, revocable access, and prefer that you add and remove us rather than share master passwords. When a project ends, our access is removed.
- Secure development
- Code review, dependency updates and secure coding practices; secrets kept out of repositories.
Compliance
What we are held to, stated without embellishment.
- UK GDPR & DPA 2018
- The framework we work to for all personal data.
- PCI-DSS by design
- Card data is handled only by compliant payment processors and never stored by us.
- Platform standards
- We build to Shopify’s app and data requirements, and to other platform rules where your project touches them.
- Aligned, not certified
- Our controls are aligned with widely recognised security frameworks. We will display a formal certification only once it is genuinely held.
If something goes wrong, silence is the worst response
- 01
Detect & contain
We act quickly to stop the issue spreading and limit impact.
- 02
Assess
We work out what happened, what data or systems were affected, and the root cause.
- 03
Notify
We tell affected clients promptly and, where a personal-data breach requires it, support notification to the ICO within the timelines UK GDPR sets.
- 04
Fix & learn
We remediate, then change what let it happen so it doesn’t recur — and share a plain-English account with you.
Found a security issue? Tell us first.
We welcome reports from security researchers and users. If you believe you’ve found a security issue in our website, our products or a site we run, please tell us before disclosing it publicly, and give us reasonable time to fix it.
What to include
- Where you found it
- How to reproduce it
- The potential impact
What we ask
- Don’t access or modify data that isn’t yours
- Don’t run attacks that degrade service — no DDoS or spam
- Don’t disclose publicly until we’ve resolved it
We’ll acknowledge your report, keep you updated, and fix confirmed issues promptly. Acting in good faith within these rules, we won’t pursue legal action against you — and we’re happy to credit you once the issue is resolved.
What clients ask before sharing access
Is Flexify GDPR compliant?
Yes. Flexify handles personal data in line with UK GDPR and the Data Protection Act 2018 — using a lawful basis, collecting only what’s needed, encrypting data in transit, and honouring data-subject rights. Where you handle personal data, we sign a Data Processing Agreement setting out our obligations as your processor.
How does Flexify protect my data?
We apply least-privilege access with multi-factor authentication, encrypt data in transit, keep secrets out of code, back up the systems we run, and use only reputable GDPR-compliant providers. We never store customer card data — payments run through PCI-DSS-compliant processors.
How do I report a security vulnerability to Flexify?
Email security@flexify.ltd with where you found the issue, how to reproduce it, and its impact. Please don’t access data that isn’t yours or disclose publicly until we’ve fixed it. We acknowledge every report, fix confirmed issues promptly, and won’t pursue good-faith researchers who follow these rules.
Does Flexify sign an NDA?
Yes. We sign your NDA on request and treat your business, code and data as confidential as standard — before, during and after the engagement. Flexify Ltd is a UK-registered company (no. 16871618), so there’s an accountable legal entity behind that commitment.
Who owns the code and IP Flexify builds?
You do. On full payment, the intellectual property in the work we build for you transfers to you. Your code and your data are yours to keep, move or take elsewhere.
Questions about how we handle your data?
Ask before you share access. We’ll answer specifically, and put it in writing.