Trust Center
Legal Framework &
Privacy Policy.
Transparency isn't a marketing buzzword; it's the legal foundation of our business. Below is our mandatory Information Commissioner's Office (ICO) Privacy Policy, Environment Agency public register details, and Physical Security framework.
Data Protection & Privacy Policy
Effective Date: March 2026 | Status: Active
1. Regulatory Status
RandomSnail Ltd ("we", "our", "us") is a commercial IT Asset Disposition (ITAD) facility operating in Taunton, Somerset. Under the UK General Data Protection Regulation (UK GDPR), we act as both a Data Controller (for our clients' administrative data) and a Data Processor (for the physical hardware supplied to us for destruction). We are formally registered with the Information Commissioner's Office (ICO).
2. Physical Security & Chain of Custody
Data security extends beyond software; it requires strict physical controls. RandomSnail Ltd operates a strict single-handler chain of custody.
• Air-Gapped Triage: All incoming client hardware is quarantined in an air-gapped intake zone. Zero network access guarantees zero risk of network-based data leaks prior to sanitization.
• Isolated Sanitization Vault: Cryptographic wiping occurs in a physically segregated, access-controlled vault within our TA1 facility, operating on a Zero-Trust Network Architecture.
3. Hardware Data (Processing for Destruction)
When physical media is transferred to RandomSnail Ltd, we do not access, view, copy, or mine the user data contained within. Our sole processing activity is irrecoverable cryptographic destruction utilizing industry-leading cryptographic erasure software in accordance with NIST SP 800-88 Rev. 2 standards. Upon completion, a serialized Certificate of Destruction (CoD) is issued, and liability is fully discharged.
4. Client Administrative Data
To conduct business and generate legally binding Waste Transfer Notes (WTNs), we collect basic corporate information:
• Business names, company registration numbers, and collection addresses.
• Contact names, email addresses, and billing details.
Digital copies of Certificates of Destruction are securely retained for 2 years to assist clients with their own ISO 27001 / GDPR audits.
5. Your Legal Rights
Under UK GDPR, you have the right to request access to, rectification of, or erasure of your administrative personal data. To exercise these rights, email: hello@randomsnail.co.uk. If you believe we have mishandled your data, you have the right to lodge a complaint with the ICO at ico.org.uk.
Environmental & Operational Compliance
Environment Agency
Upper Tier Waste Carrier, Broker & Dealer.
ICO Registered
Registered Data Controller under UK GDPR.
Commercial Cover
Comprehensive B2B Professional & Public Liability.