Security & Compliance
Last updated: 6 September 2026
Aynsley Mill takes the security of your data seriously. This page documents the technical and organisational measures we maintain across our website, and how they align with recognised information security frameworks.
1. Framework Alignment
Our security controls are designed to align with the principles of the following frameworks. Note that alignment is not the same as formal certification — certification requires an independent audit, which we have not undergone.
- ISO 27001 (Information Security Management): we follow its core principles — risk-based controls, access management, input validation, incident readiness, and documented data handling — even though we do not hold a formal ISO 27001 certificate.
- SOC 2 (Trust Service Criteria): our controls map to the Security and Confidentiality categories — encrypted storage, role-based access, rate limiting, and audit logging of public submissions.
- HIPAA: not applicable. Aynsley Mill is a UK commercial property and events venue. We do not collect, process, or store any Protected Health Information (PHI), and no healthcare data flows through our systems. HIPAA is a US healthcare regulation and does not apply to our operations.
2. Access Controls
- Row-Level Security (RLS) is enforced on every data entity — public visitors can read published content; only authenticated administrators can create, update, or delete records.
- Admin routes are gated behind authenticated, role-checked access. Unauthorised visitors are redirected.
- Public form submissions are processed by a dedicated server-side function — no direct database access is exposed to the client.
3. Data Protection
- All data in transit is encrypted via HTTPS/TLS.
- Data at rest is stored on our platform's encrypted backend infrastructure.
- No API keys, secrets, or credentials are exposed in frontend code — all sensitive operations run server-side.
- Form inputs are validated, length-capped, and sanitised server-side to prevent injection and field tampering.
4. Abuse Prevention
- Per-IP rate limiting on all public submissions (maximum 3 per 10-minute window).
- Honeypot fields detect and silently reject automated bot submissions.
- Submission logs record IP addresses and timestamps for security auditing; these are accessible to administrators only.
5. Data Retention
- Commercial inquiries: retained for 24 months after last contact, then deleted unless a tenancy is active.
- Newsletter subscriptions: retained until the subscriber unsubscribes or requests deletion.
- Security logs (IP addresses): retained for 90 days for abuse prevention, then automatically purged.
6. Incident Response
In the event of a confirmed personal data breach, we will assess the scope and notify affected individuals and the Information Commissioner's Office (ICO) within 72 hours, in accordance with UK GDPR Article 33. A breach log is maintained by our administrative team.
7. Sub-Processors
- Base44: provides the application platform, database, and hosting infrastructure. Data is processed under their terms of service.
- Skiddle: handles event ticketing independently. We do not share inquiry or newsletter data with Skiddle. Ticket purchases are subject to Skiddle's own terms and privacy policy.
8. Your Rights
Under UK GDPR, you have the right to access, correct, or delete your personal data, and to withdraw consent at any time. To exercise these rights, contact us through the inquiry form on the Site or write to Aynsley Mill, Sutherland Road, Longton, Stoke-on-Trent, ST3 1HG.
9. Contact
For security-related questions or to report a vulnerability, please contact us through the inquiry form on the Site. We take all reports seriously and will respond promptly.
