Skip to main content
Policy • Version 1.0

Information Security Policy

How we protect the confidentiality, integrity and availability of the information entrusted to us.

Document control

Document title
Information Security Policy
Version
1.0
Effective date
August 2026
Review date
August 2027
Document owner
Directors, ProMediate (UK) Limited

1. Purpose

ProMediate (UK) Limited is committed to protecting the confidentiality, integrity and availability of all information entrusted to us by consumers, traders, ADR Officials, staff and other stakeholders.

This Policy sets out the measures taken to safeguard information, reduce the risk of unauthorised access and ensure compliance with applicable legal and regulatory obligations.

2. Scope

This Policy applies to:

  • Directors;
  • ADR Officials;
  • employees;
  • consultants;
  • contractors; and
  • any person handling information on behalf of ProMediate.

It applies to both electronic and paper records.

3. Information Security Principles

ProMediate will:

Protect confidential information.

Restrict access to authorised persons only.

Maintain secure systems and procedures.

Minimise the collection of personal information where appropriate.

Regularly review security arrangements.

Comply with applicable data protection legislation.

4. Access Controls

Access to case information and personal data will only be granted where necessary for the performance of an individual's role.

User accounts, passwords and permissions will be managed to minimise unauthorised access.

Access will be removed promptly when no longer required.

5. Password Security

Users must:

  • use strong passwords;
  • keep passwords confidential;
  • avoid sharing passwords;
  • change passwords where compromise is suspected; and
  • enable multi-factor authentication where available.

6. Secure Storage

Electronic and paper records

Electronic records will be stored using secure systems with appropriate technical safeguards.

Paper files containing confidential information will be stored securely and access restricted.

7. Remote Working

Where information is accessed remotely:

  • secure internet connections should be used;
  • devices should be password protected;
  • confidential information should not be left unattended; and
  • appropriate care should be taken when working in public locations.

Working away from the office

These requirements apply equally to ADR Officials, consultants and contractors accessing case information from any location.

8. Email and Electronic Communications

Care should be taken to ensure that emails are sent to the correct recipients.

Confidential information should only be shared where necessary and appropriate.

Sensitive documents

Sensitive documents should be password protected or encrypted where appropriate.

9. Data Breaches

Any suspected loss, unauthorised disclosure or security incident must be reported to the Directors immediately.

Appropriate steps will be taken to:

  • investigate the incident;
  • minimise any risk;
  • comply with legal reporting obligations where applicable; and
  • prevent recurrence.

10. Business Continuity

ProMediate will take reasonable steps to ensure that information remains available in the event of system failure or other disruption.

Appropriate backup arrangements and recovery procedures will be maintained where reasonably practicable.

11. Disposal of Information

Information will be securely disposed of in accordance with the Data Retention Policy.

Electronic records will be securely deleted.

Paper records will be confidentially shredded or otherwise securely destroyed.

12. Responsibilities

All Directors, ADR Officials, employees and contractors are responsible for protecting confidential information.

The Directors have overall responsibility for maintaining appropriate information security arrangements.

13. Review

This Policy will be reviewed annually or sooner if required by changes in legislation, regulatory guidance or operational requirements.

Contact

To report a security concern or ask about how we protect your information, please contact us.

Post

ProMediate (UK) Limited
Brow Farm
Top Road
Frodsham
WA6 6SP

Version History

Version history of the ProMediate Information Security Policy
VersionEffective dateReview dateSummary of changes
1.0August 2026August 2027First issue.

This policy is reviewed at least annually.