Glaxtons Policies
Every policy Glaxtons Consulting Limited publishes, in full and as a branded PDF. Written for the supplier questionnaires and vendor due diligence assessments our clients and their buyers run on us, so an evaluator can cite the clause, the reference and the version without asking.
Information Security Policy Suite
Version 6.0, effective May 2026, approved by The Board of Glaxtons Consulting Limited, next scheduled review May 2027. Each policy's section 5 maps it to the vendor due diligence reference points it answers.
GCL-ACP-01 · Version 6.0
Access Control Policy
This policy ensures that access to Company and client systems and data is granted, reviewed and removed on a controlled, least privilege, need to know basis.
Owner: Operations Director. Effective May 2026. Next review May 2027.
GCL-BCP-01 · Version 6.0
Business Continuity and Disaster Recovery Policy
This policy ensures the Company can maintain, or promptly resume, critical operations, including services delivered to clients, following a disruptive event.
Owner: Operations Director. Effective May 2026. Next review May 2027.
GCL-CMP-01 · Version 6.0
Change Management Policy
This policy ensures that changes to the services the Company provides, to its IT systems, and to the locations where Company or client data is stored or processed, are planned, assessed and communicated in a controlled manner.
Owner: Operations Director. Effective May 2026. Next review May 2027.
GCL-DPC-01 · Version 6.0
Data Protection and Compliance Policy
This policy ensures the Company handles personal data and other regulated information lawfully, retains records only for as long as necessary, and can demonstrate compliance to clients and regulators.
Owner: Data Protection Lead. Effective May 2026. Next review May 2027.
GCL-DSP-01 · Version 6.0
Data Security Policy
This policy protects the confidentiality and integrity of Company and client data throughout its lifecycle, whether at rest, in transit, or at the point of disposal.
Owner: Operations Director. Effective May 2026. Next review May 2027.
GCL-HRS-01 · Version 6.0
HR Security Policy
This policy ensures that individuals engaged by the Company are suitable for their role, understand their information security responsibilities, and are equipped to protect Company and client information throughout their engagement and on departure.
Owner: Head of HR. Effective May 2026. Next review May 2027.
GCL-IMP-01 · Version 6.0
Incident Management Policy
This policy enables the Company to identify, contain, investigate and communicate information security incidents promptly, so as to limit harm to the Company, its clients and any affected data subjects.
Owner: Operations Director. Effective May 2026. Next review May 2027.
GCL-RAP-01 · Version 6.0
Risk Assessment and Vulnerability Management Policy
This policy governs how the Company identifies, evaluates and treats information security risks, and manages vulnerabilities in its systems, on an ongoing basis.
Owner: Operations Director. Effective May 2026. Next review May 2027.
GCL-TPM-01 · Version 6.0
Third Party and Supplier Security Policy
This policy manages the information security risk arising from suppliers, subcontractors and cloud service providers engaged by the Company.
Owner: Operations Director. Effective May 2026. Next review May 2027.
Other published documents
Need a policy a questionnaire asks for that is not here?
Evidence of compliance with any policy on this page is available to clients on request. Contact the Information Security Lead, Jean-Pascal Olivier, at info@glaxtons.co.uk or on 020 3668 5488.
020 3668 5488Glaxtons, 3 More London Place, London SE1 2RE