Green Team One

Cyber Security Policy

Effective Date: 26/01/2026

At Green Team One, we regard the privacy and security of our customers’ data as a matter of critical importance. In fulfilment of our commitment to protecting the personal data of our customers and partners, we have established this Cyber Security Policy. This policy sets out the measures and controls implemented to safeguard the data we collect, store, and process in the course of our business activities.

This Cyber Security Policy has been established to protect the confidentiality, integrity, and availability of all data collected and processed by Green Team One, and to reduce the risk of unauthorised access, disclosure, loss, or compromise arising from cyber security threats. This Policy applies to all employees, contractors, and third-party partners who are authorised to access Green Team One systems, networks, or data.

  1. Data Collection and Storage
    1.1 Green Team One collects and retains customer data, including personal information such as names, addresses, contact details, and energy usage data, together with any additional information supplied during the lead generation process.

    1.2 Customer information is stored within the Company’s CRM system and is protected through appropriate security controls, including encryption and multi-factor authentication (MFA).

  2. Access Control
    2.1 Access to customer data held within Green Team One systems is restricted to authorised personnel only. Access permissions are granted on a role-based basis and limited to what is necessary for the performance of duties, in accordance with the Principle of Minimal Privilege.

    2.2 All employees are required to use secure login credentials. Access to sensitive information is restricted, controlled, and subject to appropriate monitoring.

    2.3 Contractors and third-party service providers must comply with Green Team One security requirements and procedures when accessing, processing, or handling customer data.

  3. Data Encryption
    3.1 All sensitive data, including customer personal information, is encrypted both in transit and at rest using industry-standard encryption protocols (for example, SSL/TLS for data transmission and AES-256 for data storage).

    3.2 Email communications that contain sensitive information are encrypted to protect confidentiality and maintain data privacy.

  4. Regular Security Audits
    4.1 Green Team One undertakes routine security audits and vulnerability assessments in order to identify, assess, and address potential cyber security risks.

    4.2 Any issues identified through these activities are remediated promptly to ensure the continued security of our systems.

  5. Incident Response Plan5.1 In the event of a suspected or confirmed cyber incident, including a data breach or cyber-attack, Green Team One maintains an incident response plan designed to contain, manage, and minimise any impact as quickly as possible.

    5.2 Where customer data is compromised, affected individuals will be notified as required and in accordance with applicable data protection laws.

  6. Data Retention and Deletion6.1 Customer data is retained only for as long as is necessary to fulfil the purposes for which it was collected, or as otherwise required to meet legal and regulatory obligations.

    6.2 Subject to applicable legal requirements, customers may request the permanent deletion of their personal data from our systems.

  7. Employee Training7.1 All Green Team One employees receive ongoing training in cyber security best practice, including secure data handling, phishing awareness, and effective password management.

    7.2 Green Team One enforces strict internal cyber security standards to ensure employees understand and fulfil their responsibilities in protecting customer and business information.

  8. Third-Party Security8.1 Third-party service providers and contractors who access customer data are required to meet the security standards and obligations set out within this policy.

    8.2 Green Team One undertakes periodic reviews and assessments of third-party suppliers to support continued compliance with applicable security requirements.

  9. Compliance with Data Protection Laws9.1 Green Team One complies with all applicable data protection laws and regulations, including the UK Data Protection Act 2018 and the UK GDPR.

    9.2 Customers have the right to request access to, rectification of, or deletion of their personal data, in accordance with applicable legal requirements.

  10. Continuous Improvement10.1 Green Team One is committed to the ongoing development and enhancement of its cyber security controls in response to emerging threats, evolving technologies, and changes in best practice.

    10.2 We monitor relevant cyber security developments and implement appropriate tools, processes, and technical measures to strengthen our protection framework.

  11. Contact Us11.1 If you have any questions regarding this Cyber Security Policy, or if you believe your information may have been compromised, please contact our Data Protection Officer at: info@greenteamone.co.uk.