Skip to content

Security practices

Data Protection

How WebCastle collects, stores, encrypts, separates and retains customer data across development, hosting and support work, and how that data is deleted.

10 of 12 controls operating todayDomainOperatingReviewed 12 August 2026

At a glance

  • Customer data is processed only to deliver contracted services.
  • TLS in transit; cloud provider managed encryption at rest.
  • Client environments and data are kept logically separate.
  • Classification, retention and disposal procedures are being formalised.

Overview

WebCastle builds, deploys and supports web and mobile applications for its clients. In most engagements WebCastle is a processor acting on the instructions of the client, who determines what data is collected and why. WebCastle holds customer data because delivering, hosting and supporting those systems requires it — not for any independent purpose.

The baseline is consistent across engagements: transport is encrypted, storage in WebCastle-operated cloud environments uses cloud provider managed encryption, each client is kept logically separate from every other client, and access to production data is limited to the technical personnel working on that engagement.

Above that baseline, several practices are being formalised. Classification, retention schedules and disposal procedures exist as working practice today but are not yet written down and approved. This page states which is which so that a security reviewer can rely on it.

How WebCastle classifies data

A four-tier scheme is being adopted so handling rules follow sensitivity rather than project convention.

  • Public

    Information already published or intended for publication, including marketing content and public documentation. No handling restrictions beyond integrity.

  • Internal

    WebCastle operational information such as project plans, estimates and internal notes. Shared inside the company on a need-to-know basis and not disclosed externally.

  • Confidential

    Client business information, source code, architecture detail and credentials-adjacent configuration. Access limited to the assigned delivery team and covered by contractual confidentiality.

  • Personal data

    Data relating to identified or identifiable individuals held inside client applications. Handled under the client instructions and the applicable data protection terms, with the tightest access restrictions.

Data protection controls

Each control shows its current maturity. Items marked in-progress or developing describe practice that exists but is not yet documented and approved.

Encryption in transit

Established

Data moving between customers, end users and WebCastle-managed services travels over TLS. Public endpoints delivered by WebCastle are served over HTTPS.

  • Applications and administrative interfaces operated by WebCastle are configured to use HTTPS.
  • Connections to cloud provider consoles and APIs use the provider encrypted endpoints.
  • Where WebCastle inherits an environment built by a third party, transport configuration is reviewed during handover.

Encryption at rest

Established

Storage volumes, object storage and managed databases in WebCastle-operated cloud environments use cloud provider managed encryption at rest.

  • Encryption is provided by the cloud platform using provider-managed keys.
  • Backups produced by managed database services inherit the same provider-managed encryption.

Customer data segregation

Established

Each client engagement is kept logically separate. Environments, storage, databases and repositories are not shared between clients.

  • Client workloads run in separate cloud accounts, projects or logically isolated environments rather than a shared multi-tenant estate.
  • Source code repositories and issue trackers are scoped per client.
  • Older environments inherited from previous providers are migrated to this model as they are brought under WebCastle management.

Restricted access to production data

Established

Access to production systems and customer data is limited to a small number of technical personnel who need it to deliver the contracted work.

  • Cloud provider consoles and critical administrative services require multi-factor authentication.
  • Access is granted per engagement rather than across the whole client portfolio.
  • Access is removed when personnel leave a project or the company.

Purpose limitation

Established

Customer data is processed only to deliver the services set out in the contract. WebCastle does not sell customer data or use it to train third-party models.

  • Processing activity is limited to development, deployment, support and troubleshooting of the contracted systems.
  • Any new processing purpose is raised with the customer before it begins.

Data classification scheme

Operating

A written classification scheme is being introduced so that handling rules follow the sensitivity of the data rather than the habits of an individual project team.

  • Draft tiers cover public, internal, confidential and personal data.
  • Handling rules for each tier are being drafted alongside the scheme.

Data inventory and mapping

In practice

WebCastle is building a consolidated record of what customer data each engagement holds, where it is stored and which third parties are involved.

  • Project-level knowledge exists today and is captured during onboarding and architecture discussions.
  • Consolidating that knowledge into a single maintained inventory is under way.

Retention schedules

Operating

Retention is currently driven by contract terms and the configuration of each application. Standard retention schedules that apply across engagements are being defined.

  • Where a customer specifies retention terms in the contract, those terms govern.
  • Application-level retention is set during design and reviewed with the customer.

Deletion and disposal

Operating

Customer data is deleted on request and at the end of an engagement. A documented, repeatable disposal procedure with written confirmation to the customer is being completed.

  • Deletion covers production data stores, non-production copies and WebCastle-held working artefacts.
  • Residual copies may persist in cloud provider managed backups until those backups age out under provider retention.
  • WebCastle does not currently offer certified third-party destruction services.

Handling of data in non-production environments

In practice

Development and staging environments are separated from production. Standard rules on the use of production data for testing are being tightened.

  • Preference is for synthetic or anonymised data in development and staging.
  • Where a production copy is genuinely required for a defect investigation, access follows the same restrictions as production.

Encryption key management

Under Evaluation

WebCastle relies on cloud provider managed keys today. A formal key management standard, including customer-managed key options, is being assessed.

  • Customer requirements for dedicated or customer-managed keys are handled case by case at design time.

Data loss prevention

Under Evaluation

Automated data loss prevention tooling is not in place. WebCastle is assessing whether endpoint and collaboration-suite controls are proportionate to its delivery model.

  • Current mitigation is administrative: restricted access, per-client separation and contractual confidentiality obligations.

What WebCastle holds and why

Categories of data typically involved in an engagement. The specifics of any one project are defined in its contract and design documentation.

What WebCastle holds and why
CategoryWhy WebCastle holds itWhat governs how long it is kept
Client application dataRequired to build, host, migrate and support the application under contract.The customer contract and the retention configured in the application itself.
End-user personal dataPresent inside client applications that WebCastle develops or operates on the client behalf.The client instructions as controller, and applicable data protection terms.
Source code and configurationThe deliverable itself, plus the configuration needed to run it.Retained for the life of the engagement and the agreed support period.
Operational logsTroubleshooting, defect investigation and service availability.Cloud provider and application log settings for the environment.
Commercial and contact dataManaging the commercial relationship, billing and support contact.Statutory record-keeping obligations and the customer contract.

WebCastle does not publish fixed retention periods on this page. Retention applying to a specific engagement is set out in that customer agreement.

Data lifecycle in practice

Collection
WebCastle does not decide what an application collects. Collection is designed with the client, and WebCastle raises data minimisation during design review where a field or integration is not needed.
Storage location
Customer data is stored in the cloud region agreed for the engagement. Where a client requires a specific region for residency reasons, that requirement is set at design time and honoured for the life of the engagement.
Backups
Managed databases use cloud provider native backup capabilities. Backup copies inherit the encryption and access controls of the environment they belong to. Backup retention follows the provider configuration for that environment rather than a published WebCastle-wide schedule.
Export
Customers can request an export of their data in a standard machine-readable format. Exports are delivered over an authenticated channel agreed with the customer contact, and are handled as a defined request rather than a self-service feature.
Deletion
On written request, or at the end of an engagement, WebCastle deletes customer data from production and non-production environments under its control. Copies held in cloud provider managed backups expire under the provider retention for that environment.

Sub-processing and third parties

WebCastle uses a limited set of third-party providers to deliver its services. AWS is a primary cloud infrastructure provider. Other providers support source control, communication, ticketing and, in some engagements, client-selected services such as payment or messaging platforms.

Third parties involved in an engagement are agreed with the client during design. Client-selected services are integrated on the client instruction and remain under the client relationship with that vendor. A current list of the providers that may process customer data is maintained on the subprocessors page, and how WebCastle handles personal data more broadly is described in the privacy notice.

Notification of changes to the subprocessor list is handled through the customer agreement. Where a contract requires advance notice of a new subprocessor, that term governs.

What customers can request

Requests are made through the customer account contact or the security mailbox. Response times are good-faith targets and are not contractual service levels.

  • An export of your data

    A machine-readable extract of the data held in your environment, delivered over an agreed authenticated channel.

  • Deletion of your data

    Removal of your data from environments under WebCastle control at the end of an engagement or on written request, with confirmation once complete.

  • A list of who has access

    The WebCastle personnel with access to your production environment, and the basis for that access.

  • Details of third parties involved

    The providers processing data in your engagement, what they process, and the region in which they operate.

  • Assistance with data subject requests

    Support in locating, exporting or deleting an individual record where you are responding to a request from one of your users.