Trust & governance

Our clients are publicly funded and accountable — to governors, auditors, regulators and the public. This page exists so that anyone conducting due diligence on us can verify who we are and how we operate, without having to ask. It states only what is true today, and is updated as facts change.

Company identity

Legal name
TWOPOINTZERO.IO LTD (trading as TwoPointZero.io)
Company number
13059563 — registered in England & Wales, incorporated 3 December 2020; filings are up to date and can be verified at Companies House
Registered office
24 1 Wesley Avenue, London E16 1SW
Director
Wai Hang (Peter) Lau
VAT
Not VAT-registered; no VAT is chargeable on our invoices. Should registration become required, quoted prices in an engagement are the total amounts payable unless expressly agreed otherwise.

Data protection

ICO registration
Registration as a fee payer with the Information Commissioner's Office is in progress; this page will carry the registration number once issued.
Role
When handling client personal data (for example student records), we act as a processor under a written data-sharing or data-processing agreement, with the client as controller. We do not use client personal data for any purpose beyond the engagement.
Where your data lives
The systems we build are deployed into the client's own Microsoft Azure tenancy, under the client's policies and identity platform. Client data stays inside the client's environment — it does not leave it, and it is not copied into ours.
Practices
  • Data minimisation: we work on the smallest extract that does the job, for the shortest time.
  • Client personal data is never committed to code repositories.
  • Client personal data never appears in our demonstrations or marketing — demonstration environments use invented data and published datasets only.
  • Retention and erasure follow the client's own policies, encoded in the systems we deliver.
  • On exit, any client data in our custody is returned or destroyed, with written confirmation.

Security

Certifications
None held yet. Cyber Essentials is the first we intend to obtain; this page lists certifications only once they are actually in place.
Security by architecture
Security in what we deliver is a product property, not a policy document: role-based access through the client's own identity platform (least privilege by default), maker-checker sign-off so no one approves their own changes, a tamper-evident audit trail of every write, and erasure workflows with cryptographic erasure. All of it is demonstrable, and clients are encouraged to test it.

Continuity — including ours

We advise clients on key-person risk, so we hold ourselves to the same standard. Every engagement includes:

The client is never dependent on our continued existence to operate its system. We would rather be retained for usefulness than for lock-in.

Procurement & due diligence

We are happy to complete supplier due-diligence questionnaires, provide references, and enter into data-sharing and data-processing agreements on client or institutional templates. Milestone acceptance criteria are agreed in writing before work starts, and payment falls due on acceptance. Requests to contact.

This page was last reviewed on 30 July 2026. If anything here appears out of date, please tell us.