Governance
We assign responsibility for information handling, review risks, limit collection to defined purposes and maintain policies appropriate to our size, services and legal obligations.
Trust centre
Gradence Global Ltd. treats responsible information handling as part of service quality, not an administrative afterthought.
Effective and last reviewed: 3 August 2026We assign responsibility for information handling, review risks, limit collection to defined purposes and maintain policies appropriate to our size, services and legal obligations.
Access is granted on a need-to-know basis, reviewed when responsibilities change and removed when no longer required. Personnel and delivery partners are expected to maintain confidentiality and follow secure working practices.
Controls may include encryption in transit, identity and access management, strong authentication, secure configuration, vulnerability and patch management, protected backups, logging and monitoring, selected according to risk.
We assess material providers, use appropriate contractual protections, minimise information, apply retention schedules and securely delete or anonymise records when the purpose and legal requirements end.
Suspected incidents are assessed, contained, documented and remediated. Where a personal data breach meets the legal threshold, we notify the ICO and affected people within the applicable requirements.
We review controls as technology, threats and services change. This statement does not claim a certification unless expressly stated. Security or data protection enquiries can be sent to contact@gradenceglobal.com. Effective: 3 August 2026.