Advanced Blast & Ballistic Systems Limited (“ABBS”) operates within the defence and security sector and applies a principle of controlled disclosure. We handle personal, investor and shareholder data with appropriate security, governance and regulatory controls.
Scope and Accountability
ABBS is committed to handling personal data lawfully, fairly, transparently and securely in accordance with the UK GDPR, the Data Protection Act 2018 and applicable privacy and electronic communications law. This Statement applies to personal data handled through our public website, customer portal and investor portal, and to related business processes.
ABBS will identify and document when it acts as controller, joint controller or processor. The responsible contact is the Company Secretary. Material concerns will be escalated to senior management, and we will maintain appropriate records, policies, training and oversight proportionate to our processing risks.
Our Principles
Purpose and fairness: use personal data only for specified, legitimate purposes on an appropriate lawful basis.
Transparency: give clear information at the right time, including where a customer, investor, shareholder, agent or other party supplies data about someone else.
Data minimisation: collect only what is adequate, relevant and reasonably necessary.
Accuracy: take reasonable steps to keep records accurate and current.
Retention: keep identifiable data only for as long as needed for the stated purposes, legal obligations, claims, security and defensible business records.
Security and confidentiality: use proportionate technical and organisational controls.
Privacy by design and default: assess privacy risks when changing the portal, introducing providers, collecting new data or using new technologies.
Respect for rights: make it straightforward for people to exercise applicable data-protection rights.
Portal Data and Purposes
Depending on the relationship and portal functionality, ABBS may handle identity and contact data; employer, role and authority information; account credentials and security logs; customer enquiries, specifications, orders and support records; investor, prospective investor and shareholder records; communications and preferences; transaction and payment information; due-diligence or compliance information; document-access records; and technical, device and usage data.
We use this information to administer accounts and access; authenticate users and prevent misuse; respond to enquiries; deliver customer services and contracts; maintain shareholding and investor communications; support legitimate corporate, governance and fundraising activity; meet legal, regulatory, tax, accounting, sanctions and record-keeping duties; protect systems and confidential information; and improve the service. The Privacy Policy must state the applicable lawful basis for each material purpose, rather than relying on consent for all processing.
Access and Sharing
Access is limited according to role and need. We may share data with authorised ABBS personnel and group companies; professional advisers; IT, hosting, identity, security, analytics, CRM, communications, payment, registry and document-management providers; authorised global agents where needed to respond or provide service; counterparties in a financing, investment, sale or reorganisation; and public authorities or regulators where required or permitted by law.
ABBS will conduct proportionate supplier due diligence, put appropriate contractual terms in place, restrict provider use, and review access. The Privacy Policy should identify categories of recipients clearly and name providers where this is necessary for transparency, especially analytics, lead-identification and fundraising platforms.
International Transfers
Where personal data is transferred or made accessible outside the United Kingdom, ABBS will first determine whether the transfer rules apply and will use a lawful mechanism. Depending on the destination and recipient, this may include UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework for an eligible, actively certified US recipient), the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, binding corporate rules, or a permitted exception. Where required, ABBS will complete an appropriate transfer risk assessment and apply supplementary measures.
Security and Incident Response
Controls will be proportionate to the sensitivity of customer, technical, investor and shareholder information and may include access approval and periodic review, least privilege, multi-factor authentication, encryption in transit and where appropriate at rest, logging and monitoring, secure configuration, vulnerability and patch management, backups, supplier assurance, staff confidentiality and training, and tested incident-response procedures.
Suspected personal-data breaches must be reported immediately to the Company Secretary. ABBS will contain and assess incidents, document decisions, and notify the Information Commissioner’s Office and affected people where and within the time required by law.
Retention and Deletion
ABBS will maintain a retention schedule covering portal accounts, access logs, enquiries, contracts, technical records, investor and shareholder records, corporate and tax records, marketing preferences and due-diligence information. Periods will be based on purpose, legal and regulatory requirements, limitation periods, security needs and the continuing shareholder/customer relationship. Data will then be securely deleted, anonymised or archived with restricted access. Backups will be protected and expire under defined cycles.
Individual Rights
Subject to legal conditions and exemptions, individuals may request access, correction, erasure, restriction, portability or objection; withdraw consent where processing relies on consent; and ask for safeguards relating to solely automated decisions with legal or similarly significant effects. Requests may be made through the contact form. We may need to verify identity and authority. Individuals may complain to the UK Information Commissioner’s Office at ico.org.uk.
Cookies, Analytics and Marketing
ABBS will not set or access non-essential cookies or similar technologies before obtaining any consent required by PECR and data-protection law. Refusing must be as easy as accepting, choices must be recorded and withdrawable, and the banner and Cookie Policy must match the technologies actually deployed. Direct marketing will be sent only where a lawful basis and any required consent or soft opt-in exists, with a clear opt-out.
Review and Assurance
We will review this Statement and the supporting controls at least annually and when there is a material change to the portal, processing, providers, law or risk. We will investigate concerns, track corrective actions and update public information when practices change.
