Legal

    Security Statement

    Last updated: August 2026 | Version: v2.0

    IngredientsWorldwide.com is operated by DiversecitiUK Ltd (Manchester, United Kingdom). This statement describes, in general terms, the technical and organisational measures we apply to the platform. It is written to be accurate rather than promotional: we describe only measures we actually operate or that are provided by the infrastructure providers we use.

    Our Security Approach

    We apply technical and organisational measures appropriate to the nature of the platform and the limited personal data we handle. We follow data minimisation: enquiry and buyer request handling is designed to avoid retaining personal data where it is not required.

    1. Measures We Operate

    Access Controls

    • Administrative functions are restricted to authorised personnel using role-based permissions
    • Access is granted on least-privilege principles, limited to role and purpose
    • Database access is restricted by row-level security policies, with public-facing data exposed only through restricted, non-sensitive views
    • Administrative access is removed when no longer required

    Data Handling

    • Data minimisation is applied to public enquiry and buyer request flows
    • Public listings and Live Buyer Requests are published in anonymised or generalised form; buyer identity and contact details are not published
    • Supplier documents are not publicly accessible
    • Internal identifiers and non-public information are not exposed on public pages

    Logging

    • Certain platform events (such as enquiry handling and message delivery outcomes) are logged for operational and compliance purposes
    • Logs are reviewed when investigating an issue or incident

    Maintenance

    • We carry out reasonable security maintenance, including applying dependency and platform updates when issues are identified

    2. Measures Provided by Our Providers

    The platform is hosted on managed cloud infrastructure and delivered through a managed hosting and content delivery provider. Certain protections are provided by those providers rather than by us directly, and are subject to their own terms and capabilities. These typically include:

    • Encryption of traffic in transit over HTTPS/TLS
    • Encryption at rest as provided by the managed database and storage services used
    • Network-level protections and platform monitoring operated by the provider
    • Backup and recovery capabilities offered by the managed database service

    We do not independently guarantee the availability, configuration or performance of provider-operated controls.

    3. What We Do Not Claim

    To avoid overstating our position:

    • We do not hold ISO, SOC or PCI certification
    • We do not carry out a formal programme of regular penetration testing
    • We do not operate continuous 24/7 security monitoring
    • We do not carry out formal employee background screening
    • We do not guarantee that data is secure in all circumstances

    If any of these change, this statement will be updated.

    4. Incident Handling

    Where we become aware of a security incident, we will handle it proportionately to the nature and seriousness of the event. This may include investigating and containing the issue, taking corrective action, notifying the Information Commissioner's Office where a qualifying personal data breach occurs (without undue delay and, where feasible, within 72 hours of becoming aware of it), and notifying affected individuals where required under UK GDPR.

    5. Third Parties

    We use third-party service providers (for example hosting, database, email delivery and telephony). Providers are selected on the basis of their published security and data protection practices. Our sub-processors are listed on our Sub-Processors page.

    6. User Responsibilities

    Users are responsible for:

    • Maintaining the confidentiality of any account credentials
    • Using secure networks and devices when accessing the platform
    • Not submitting sensitive personal data through public forms
    • Reporting suspicious activity promptly

    7. Reporting a Security Concern

    If you believe you have found a security vulnerability, please contact sales@ingredientsworldwide.com with enough detail for us to reproduce the issue. Please do not publicly disclose the issue before we have had a reasonable opportunity to respond. We appreciate responsible disclosure.

    8. Limitations

    No online platform can be completely secure. While we apply appropriate measures, we cannot guarantee absolute security of information transmitted to or stored on the platform.

    9. Compliance Context

    Our practices are designed to support our obligations under UK GDPR and the Data Protection Act 2018. This statement is not a certification and does not create contractual security commitments beyond those set out in our Terms and Conditions.

    Contact

    For security enquiries: sales@ingredientsworldwide.com