Privacy &
Legal Statements

Cookie Policy

Effective Date: 21-Feb-2024 Last Updated: 21-Feb-2024
What are cookies?
How do we use cookies?
Cookie Settings
You can change your cookie preferences any time by clicking the above button. This will let you revisit the cookie consent banner and change your preferences or withdraw your consent right away. In addition to this, different browsers provide different methods to block and delete cookies used by websites. You can change the settings of your browser to block/delete the cookies. Listed below are the links to the support documents on how to manage and delete cookies from the major web browsers. Chrome: https://support.google.com/accounts/answer/32050 Safari: https://support.apple.com/en-in/guide/safari/sfri11471/mac Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectslug=delete-cookies-remove-info-websites-stored&redirectlocale=en-US Internet Explorer: https://support.microsoft.com/en-us/topic/how-to-delete-cookie-files-in-internet-explorer-bca9446f-d873-78de-77ba-d42645fa52fc If you are using any other web browser, please visit your browser’s official support documents.
 

Privacy Policy

Last Updated On 21-Feb-2024
Effective Date 21-Feb-2024

This Privacy Policy describes the policies of Bespoke Data, 77 Station Street, Burton-on-Trent, DE14 1BT, United Kingdom of Great Britain and Northern Ireland (the), email: info@bespoke-data.uk, phone: 07730 143 565 on the collection, use and disclosure of your information that we collect when you use our website ( https://bespoke-data.uk ). (the “Service”). By accessing or using the Service, you are consenting to the collection, use and disclosure of your information in accordance with this Privacy Policy. If you do not consent to the same, please do not access or use the Service.

We may modify this Privacy Policy at any time without any prior notice to you and will post the revised Privacy Policy on the Service. The revised Policy will be effective 180 days from when the revised Policy is posted in the Service and your continued access or use of the Service after such time will constitute your acceptance of the revised Privacy Policy. We therefore recommend that you periodically review this page.

  1. Information We Collect:

    We will collect and process the following personal information about you:

    1. Name
    2. Email
    3. Address
    4. Payment Info
  2. How We Collect Your Information:

    We collect/receive information about you in the following manner:

    1. When a user fills up the registration form or otherwise submits personal information
    2. Interacts with the website
    3. From public sources
  3. How We Use Your Information:

    We will use the information that we collect about you for the following purposes:

    1. Creating user account
    2. Processing payment
    3. Administration info
    4. Manage customer order
    5. Manage user account

    If we want to use your information for any other purpose, we will ask you for consent and will use your information only on receiving your consent and then, only for the purpose(s) for which grant consent unless we are required to do otherwise by law.

  4. How We Share Your Information:

    We will not transfer your personal information to any third party without seeking your consent, except in limited circumstances as described below:

    1. Analytics

    We require such third party’s to use the personal information we transfer to them only for the purpose for which it was transferred and not to retain it for longer than is required for fulfilling the said purpose.

    We may also disclose your personal information for the following: (1) to comply with applicable law, regulation, court order or other legal process; (2) to enforce your agreements with us, including this Privacy Policy; or (3) to respond to claims that your use of the Service violates any third-party rights. If the Service or our company is merged or acquired with another company, your information will be one of the assets that is transferred to the new owner.

  5. Retention Of Your Information:

    We will retain your personal information with us for 90 days to 2 years after users terminate their accounts or for as long as we need it to fulfill the purposes for which it was collected as detailed in this Privacy Policy. We may need to retain certain information for longer periods such as record-keeping / reporting in accordance with applicable law or for other legitimate reasons like enforcement of legal rights, fraud prevention, etc. Residual anonymous information and aggregate information, neither of which identifies you (directly or indirectly), may be stored indefinitely.

  6. Your Rights:

    Depending on the law that applies, you may have a right to access and rectify or erase your personal data or receive a copy of your personal data, restrict or object to the active processing of your data, ask us to share (port) your personal information to another entity, withdraw any consent you provided to us to process your data, a right to lodge a complaint with a statutory authority and such other rights as may be relevant under applicable laws. To exercise these rights, you can write to us at info@bespoke-data.uk. We will respond to your request in accordance with applicable law.

    You may opt-out of direct marketing communications or the profiling we carry out for marketing purposes by writing to us at info@bespoke-data.uk.

    Do note that if you do not allow us to collect or process the required personal information or withdraw the consent to process the same for the required purposes, you may not be able to access or use the services for which your information was sought.

  7. Cookies Etc.

    To learn more about how we use these and your choices in relation to these tracking technologies, please refer to our Cookie Policy.

  8. Security:

    The security of your information is important to us and we will use reasonable security measures to prevent the loss, misuse or unauthorised alteration of your information under our control. However, given the inherent risks, we cannot guarantee absolute security and consequently, we cannot ensure or warrant the security of any information you transmit to us and you do so at your own risk.

  9. Grievance / Data Protection Officer:

    If you have any queries or concerns about the processing of your information that is available with us, you may email our Grievance Officer at Bespoke Data, Anglesey House, Anglesey Road, email: info@bespoke-data.uk. We will address your concerns in accordance with applicable law.

Infrastructure Security

This IT Security Report provides an overview of the security measures implemented by Bespoke Data to safeguard its IT infrastructure and website.

The focus is on protecting sensitive data, ensuring the availability of services, and mitigating potential risks. The report covers various aspects of information security, including network security, data protection, access controls, and incident response.

1.0 Firewalls

Bespoke Data employs state-of-the-art firewalls to monitor and control incoming and outgoing network traffic, preventing unauthorised access and protecting against cyber threats. Our Web Application Firewall (WAF) protects your data and software by blocking suspicious activity.

Our WAF helps prevent attacks by inspecting every HTTP request for SQL injection, trojans, cross-site scripting, path traversal and many other types of attack. It does this at the edge of our network, so it happens before any scripts from web apps execute. It takes less than a millisecond.

2.0 Intrusion Detection and Prevention Systems (IDPS)

Our website is also protected 1Tbps+ Distributed Denial of Service attacks (DDoS) and network defences. These are based on IP address and network-level (automated system) level reputation. They’re designed to block likely attackers before an attack starts.

Suspicious IP addresses and networks are routed to different web servers automatically, so traffic and load is kept away from standard web servers. IP addresses that have a bad reputation are blocked at the network edge, and entire ranges of IP addresses can be blocked too.

3.0 Automatic Malware Scanning

We scan our website daily for common malware. Using both commercial tools and systems developed in-house. Viruses or Malware – such as web shells or mail/spam daemons – are identified and neutralised quickly as part of this process.

The unique ways we set up our servers gives us enterprise class security:

  1. Autoscaling – A cyber-attack uses up a lot of web hosting resources, even if it’s unsuccessful, our autoscaling servers will account for the attack, meaning that our site will stay fast and online.
  2. No single point of failure – Our platform has redundancy at every level. In the event of a hardware, software or network failure, automatic failover occurs to bring services back online. This redundant hardware and software design helps availability and mitigate data loss.
  3. Isolated server roles – Our Web servers serve only our website files. MySQL servers just run MySQL and email servers only email. Logs are sent to central log servers. These isolated server roles mean that even in the worst-case scenario, if our website was compromised, an attacker won’t be able to cover their tracks or access database content or emails.

Data Protection

SSL/TLS Encryption

Bespoke Data implements SSL/TLS encryption to secure data transmitted between users and the website, safeguarding sensitive information such as login credentials and payment details.

Data-at-Rest Encryption

Critical data stored on servers is encrypted to protect against unauthorised access in case of a security breach.

Automated Backup Systems:
Scheduled backups are performed regularly to ensure data recovery in the event of data loss, system failures, or cyberattacks.

Offsite Backup Storage:

Backup copies are stored securely in an offsite location to prevent data loss in case of physical disasters or on-premises breaches.

Access Control

Strong Password Policies:

Bespoke Data enforces strong password policies, including regular password changes and complexity requirements, to enhance user authentication security.

Multi-Factor Authentication (MFA):

MFA is implemented to add an extra layer of protection, requiring users to verify their identity through multiple authentication methods.

Role-Based Access Control (RBAC):

Access rights are assigned based on job roles, ensuring that employees have the minimum necessary privileges to perform their tasks.

Reporting Mechanism:

Bespoke Data has established an efficient incident reporting mechanism for employees and users to report security incidents promptly.

Incident Response Plan:

Bespoke Data maintains a well-defined incident response plan, outlining the steps to be taken in the event of a security incident. This plan includes communication protocols, mitigation strategies, and recovery procedures.

Power BI

Power BI is an online software service (SaaS, or Software as a Service) offering from Microsoft that lets you easily and quickly create self-service Business Intelligence dashboards, reports, semantic models, and visualizations. With Power BI, you can connect to many different data sources, combine and shape data from those connections, then create reports and dashboards that can be shared with others.

The world is rapidly changing; organizations are going through an accelerated digital transformation, and we’re seeing a massive increase in remote working, increased customer demand for online services, and increased use of advanced technologies in operations and business decision-making. And all of this is powered by the cloud.

As the transition to the cloud has changed from a trickle to a flood, and with the new, exposed surface area that comes with it, more companies are asking How secure is my data in the cloud? and What end-to-end protection is available to prevent my sensitive data from leaking? And for the BI platforms that often handle some of the most strategic information in the enterprise, these questions are doubly important.

The decades-old foundations of the BI security model – object-level and row-level security – while still important, clearly no longer suffice for providing the kind of security needed in the cloud era. Instead, organizations must look for a cloud-native, multi-tiered, defense-in-depth security solution for their business intelligence data.

Power BI was built to provide industry-leading complete and hermetic protection for data. The product has earned the highest security classifications available in the industry, and today many national security agencies, financial institutions, and health care providers entrust it with their most sensitive information.

It all starts with the foundation. After a rough period in the early 2000s, Microsoft made massive investments to address its security vulnerabilities, and in the following decades built a strong security stack that goes as deep as the machine on-chip bios kernel and extends all the way up to end-user experiences. These deep investments continue, and today over 3,500 Microsoft engineers are engaged in building and enhancing Microsoft’s security stack and proactively addressing the ever-shifting threat landscape. With billions of computers, trillions of logins, and countless zettabytes of information entrusted to Microsoft’s protection, the company now possesses the most advanced security stack in the tech industry and is broadly viewed as the global leader in the fight against malicious actors.

Power BI builds on this strong foundation. It uses the same security stack that earned Azure the right to serve and protect the world’s most sensitive data, and it integrates with the most advanced information protection and compliance tools of Microsoft 365. On top of these, it delivers security through multi-layered security measures, resulting in end-to-end protection designed to deal with the unique challenges of the cloud era.

To provide an end-to-end solution for protecting sensitive assets, the product team needed to address challenging customer concerns on multiple simultaneous fronts:

  • How do we control who can connect, where they connect from, and how they connect? How can we control the connections?
  • How is the data stored? How is it encrypted? What controls do I have on my data?
  • How do I control and protect my sensitive data? How do I ensure this data can’t leak outside the organization?
  • How do I audit who conducts what operations? How do I react quickly if there’s suspicious activity on the service?

This article provides a comprehensive answer to all these questions. It starts with an overview of the service architecture and explains how the main flows in the system work. It then moves on to describe how users authenticate to Power BI, how data connections are established, and how Power BI stores and moves data through the service. The last section discusses the security features that allow you, as the service admin, to protect your most valuable assets.

The Power BI service is governed by the Microsoft Online Services Terms, and the Microsoft Enterprise Privacy Statement. For the location of data processing, refer to the Location of Data Processing terms in the Microsoft Online Services Terms and to the Data Protection Addendum. For compliance information, the Microsoft Trust Center is the primary resource for Power BI. The Power BI team is working hard to bring its customers the latest innovations and productivity. Learn more about compliance in the Microsoft compliance offerings.

The Power BI service follows the Security Development Lifecycle (SDL), strict security practices that support security assurance and compliance requirements. The SDL helps developers build more secure software by reducing the number and severity of vulnerabilities in software, while reducing development cost. Learn more at Microsoft Security Development Lifecycle Practices.

For detailed information about Power BI security, see the Power BI Security white paper.

This page tells you the terms and conditions on which we will supply to you the products (Products) listed on our website www.bespoke-data.uk (our site) via one of our subscription services (Services). Please read these terms and conditions carefully before subscribing to one of our Services. You should understand that by subscribing to one of our Services, you agree to be bound by these terms and conditions.

You should print a copy of these terms and conditions for future reference.. 

  1. YOUR STATUS

By placing an order through our site, you warrant that:

1.1 you are legally capable of entering into binding contracts; and

1.2 you are at least 18 years old;

  1. HOW THE CONTRACT IS FORMED BETWEEN YOU AND US

2.1 After completing signup, you will receive an e-mail from us acknowledging that we have received your first payment. The contract between us (Contract) will only be formed when we send you the e-mail.

2.2 The subscription plan to our Services consists of an initial charge and then followed by recurring period charges as agreed to by you. By entering into this Agreement, you acknowledge that your subscription has an initial and recurring payment feature and you accept responsibility for all recurring charges prior to cancellation. Bespoke Data may submit periodic charges (e.g., monthly) without further authorisation from you, until you provide prior notice that you have terminated this authorisation or wish to change your payment method. Such notice will not affect charges submitted before Bespoke M&A Ltd (Bespoke Data) reasonably could act. To terminate your authorisation or change your payment method, log into your account and manage your automatic subscription payment.

2.3 By subscribing to our Services you are agreeing to pay recurring periodic subscriptions for an indefinite time until cancelled by you. You can cancel your subscription at any time. You will not be charged for any cancellation. You can re-subscribe at any time following your cancellation, but we reserve the right not to permit re-subscription where we have previously elected to terminate a subscription by you.

2.4 Account Cancellations. If you wish to cancel your monthly subscription with us, you must cancel 7 days before your next payment is due to be collected, in order to avoid receiving the following months’ access to our subscription products. Customers cancelling after their payment has been taken will receive the following months access to our subscription products.

2.5 We reserve the right at our absolute discretion not to renew your subscription at any time without giving any reasons for our decision.

  1. PRICE AND PAYMENT

3.1 The price of the Products will be as quoted on our site, except in cases of obvious error.

3.2 Product prices exclude VAT.

3.3 Product prices are liable to change at any time.

3.4 Payment for all Services are processed via Stripe and GoCardless. We accept all major debit and credit cards.

  1. WARRANTY

The Customer acknowledges that Bespoke Data has not given any warranties or guarantees of any nature with respect to the success or satisfactory conclusion of the use of our Products or as to the economic, financial or other results that the Customer may obtain or experience as a result of the use of our Products.

  1. OUR LIABILITY

5.1 Bespoke Data shall use reasonable skill and care in the provision of the Products.

5.2 The liability of Bespoke Data in connection with or arising out of the subscription to our Services set out in these terms, or any variation or addition to it, (whether in contract, negligence or wilful or reckless misconduct or otherwise) shall in no circumstances exceed £15,000 in aggregate in respect of all such losses.

5.3 Bespoke Data shall not be responsible for any consequential loss or damage.

5.4 Having regard to Bespoke Data’s and the Customer’s interest in limiting the personal liability and exposure to litigation of individuals, the Customer shall not bring any claim in respect of any damage against any employee or agent of Bespoke M&A personally. For the avoidance of doubt, Bespoke M&A is a Limited Liability Company and all services are provided by or on behalf of The Limited Liability Company and (so far as permissible at law) without personal liability on the part of the individual or individuals involved in providing such services.

5.5 A party shall not be liable to the other party for any delay and/or failure to perform in accordance with the terms of the Services if such delay and/or failure are as a result of events beyond the reasonable control of that party (including, without limitation, fire and flood, acts of government).

5.6 The provisions of this paragraph shall survive termination of subscription to our Services.

  1. WRITTEN COMMUNICATIONS

6.1 All correspondence and papers in Bespoke Data’s possession or control and generated for its internal purposes shall be Bespoke Data’s sole property, kept in strict confidence and not disclosed to any person without the Customer’s consent, unless otherwise required to do so by law or a competent regulatory authority or unless the information contained in them is in the public domain, other than by reason of Bespoke Data’s unlawful disclosure.

All confidential information (including in particular historical financial information concerning the Customer’s business (and that of the Customer’s group companies) disclosed by the Customer to Bespoke Data shall remain owned by the Customer, and Bespoke Data shall use it only for the purposes of the Services, and keep it confidential and not disclose it to any third party without the Customer’s prior written consent, unless otherwise required to do so by law or a competent regulatory authority or unless the information contained in them is in the public domain, other than by reason of Bespoke Data’s unlawful disclosure. Upon cancellation of the Services, Bespoke Data shall (at the Customer’s request and option) return or destroy confidential information disclosed to it by the Customer. Bespoke Data may retain its own working papers generated for the purpose of the Services in accordance for evidential and regulatory purposes, provided such information is kept confidential at all times.  

  1. TRANSFER OF RIGHTS AND OBLIGATIONS

7.1 The contract between you and us is binding on you and us and on our respective successors and assignees.

7.2 You may not transfer, assign, charge or otherwise dispose of a Contract, or any of your rights or obligations arising under it, without our prior written consent.

7.3 We may transfer, assign, charge, sub-contract or otherwise dispose of a Contract, or any of our rights or obligations arising under it, at any time during the term of the Contract.

  1. INTELLECTUAL PROPERTY RIGHTS

8.1 We are the owner or the licensee of all intellectual property rights in our site, whether registered or unregistered, and in the material published on it. These works are protected by copyright laws and all such rights are reserved.

8.2 You may print off one copy, and may download extracts, of any pages from our site for your personal reference. You must not use any part of our copyright materials for commercial purposes without first obtaining a licence to do so from us and our licensors.

8.3 If you post comments on the Products or Services to any website, blog or social media network (Commentary) you must ensure that such Commentary represents your fairly-held opinions. By subscribing to the Services you irrevocably authorise us to quote from your Commentary on our site and in any advertising or social media outlets which we may create or contribute to.  

  1. WAIVER

9.1 If we fail, at any time during the term of a Contract, to insist upon strict performance of any of your obligations under the Contract or any of these terms and conditions, or if we fail to exercise any of the rights or remedies to which we are entitled under the Contract, this will not constitute a waiver of such rights or remedies and will not relieve you from compliance with such obligations.

9.2 A waiver by us of any default will not constitute a waiver of any subsequent default.

9.3 No waiver by us of any of these terms and conditions will be effective unless it is expressly stated to be a waiver and is communicated to you in writing in accordance with clause 6 above.

  1. SEVERABILITY

If any of these terms and Conditions or any provisions of a Contract are determined by any competent authority to be invalid, unlawful or unenforceable to any extent, such term, condition or provision will to that extent be severed from the remaining terms, conditions and provisions which will continue to be valid to the fullest extent permitted by law.

  1. ENTIRE AGREEMENT

11.1 These terms and conditions and any document expressly referred to in them constitute the whole agreement between us and supersede all previous discussions, correspondence, negotiations, previous arrangement, understanding or agreement between us relating to the subject matter of any Contract.

11.2 We each acknowledge that, in entering into a Contract, neither of us relies on any representation or warranty (whether made innocently or negligently) that is not set out in these terms and conditions or the documents referred to in them.

11.3 Each of us agrees that our only liability in respect of those representations and warranties that are set out in this agreement (whether made innocently or negligently) will be for breach of contract.

11.4 Nothing in this clause limits or excludes any liability for fraud.

11.5 You authorise us to use your company logo for marketing purposes to promote our services either on our website or in hard copy format.

  1. OUR RIGHT TO VARY THESE TERMS AND CONDITIONS

12.1 We have the right to revise and amend these terms and conditions from time to time to reflect changes in market conditions affecting our business, changes in technology, changes in payment methods, changes in relevant laws and regulatory requirements and changes in our system’s capabilities.

12.2 You will be subject to the policies and terms and conditions in force at the time that you order Products from us, unless any change to those policies or these terms and conditions is required to be made by law or governmental authority (in which case it will apply to orders previously placed by you), or if we notify you of the change to those policies or these terms and conditions before we send you an order confirmation (in which case we have the right to assume that you have accepted the change to the terms and conditions, unless you notify us to the contrary within fourteen working days of receipt by you of the Products).

  1. LAW AND JURISDICTION

Contracts for the purchase of Products through our site and any dispute or claim arising out of or in connection with them or their subject matter or formation (including non-contractual disputes or claims) will be governed by English law. Any dispute or claim arising out of or in connection with such Contracts or their formation (including non-contractual disputes or claims) will be subject to the non-exclusive jurisdiction of the courts of England and Wales.

Using our experience of building bespoke models and analytics platforms for leading private equity backed companies, Bespoke Data has developed a leading range of subscription forecast model and analytics platforms. While bespoke platform builds are still available, our subscription products are developed to work for the vast majority of businesses. In addition to subscription products our offer extends to professional services to help get up and running with our subscription platforms, if required.

Want the latest product news and updates?

Sign up to our Analytics Insider newsletter to stay up to date.
Talk To One Of Our Experienced Team Today To Find Out How Bespoke Data Can Make A Difference To Your Business
© 2026 - Bespoke Data, All Rights Reserved |
Website By EDGE Creative

A Bespoke Group Company

  • Registered Office:
    77 Station Street,
    Burton-on-Trent
    DE14 1BT
  • info@bespoke-data.uk

Request Free Trial

Fill out the form below, and we will be in touch shortly.