Legal

Privacy Policy

Last updated: 27 March 2026

1. Introduction

CYBERZONIC LIMITED (“we”, “us”, “our”) is a enterprise technology company registered in England and Wales. We are the data controller for personal data collected through this website and our services.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have any questions about this policy or our data practices, please contact us at privacy@cyberzonic.com.

2. What Data We Collect

We collect the following categories of personal data:

  • Identity data: Name, job title, and organisation name provided through contact forms, chat, or project submissions.
  • Contact data: Email addresses provided when submitting contact forms, newsletter sign-ups, or project briefs.
  • Communication data: Messages submitted via our contact form, advisory desk conversations, and project briefs.
  • Usage data: Pages visited, timestamps, session identifiers, and interaction data with our platform.
  • Technical data: IP addresses, browser type and version, device type, and operating system — collected automatically by our hosting provider.
  • Newsletter data: Email address and optional name provided when subscribing to our newsletter, along with subscription status and confirmation timestamp.

3. How We Use Your Data

We use your personal data for the following purposes:

  • To provide our enterprise technology company services and deliver project outcomes.
  • To respond to enquiries submitted through our contact form or chat assistant.
  • To send our weekly cybersecurity intelligence newsletter to subscribers who have given explicit consent.
  • To improve and maintain our platform, including monitoring for security incidents and debugging technical issues.
  • To comply with our legal and regulatory obligations.
  • To pursue our legitimate interests in operating a cybersecurity business.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Consent: Newsletter subscriptions and chat lead capture (you may withdraw consent at any time by contacting us or unsubscribing).
  • Contract: Processing data necessary to deliver a project or service you have requested from us.
  • Legitimate interests: Platform improvement, security monitoring, and responding to enquiries where we have a legitimate business interest that does not override your rights.
  • Legal obligation: Retaining records required by law, including tax and accounting records.

5. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only where necessary for service delivery with the following processors, all operating under appropriate data protection agreements:

  • Vercel: Our website hosting and serverless infrastructure provider.
  • Neon (PostgreSQL): Our database provider where project data, conversation records, and subscriber lists are stored.
  • Microsoft Azure: Email delivery via Microsoft Graph API, sending from our own Microsoft 365 infrastructure.
  • OpenAI: Supports selected internal processing and digital advisory workflows. We do not send identifiable personal data (such as name or email) to model providers; only message content required for the specific interaction is processed.
  • GitHub: Code repository used by the VAST Agent pipeline for customer project delivery (branch and code management only — no personal data is committed to the repository).

6. International Transfers

Some of our processors operate infrastructure outside the United Kingdom, including in the United States and European Economic Area. Where data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the Information Commissioner's Office or adequacy decisions.

7. Data Retention

We retain personal data for the following periods:

  • Project and account data: Retained for the duration of the engagement plus six years (in accordance with standard legal requirements for business records).
  • Newsletter subscriber data: Retained until you unsubscribe. Unsubscribed records are retained with “unsubscribed” status for suppression purposes.
  • Chat conversation data: Retained for 12 months from the date of the conversation.
  • Marketing leads and enquiries: Retained for 24 months unless converted to an active engagement.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data where there is no legitimate reason for us to continue processing it.
  • Right to restriction: Request that we restrict processing of your data in certain circumstances.
  • Right to portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at privacy@cyberzonic.com. We will respond within one month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data appropriately.

9. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher.
  • Encryption of data at rest in our database infrastructure.
  • Access controls limiting data access to authorised personnel only.
  • Regular security reviews and monitoring of our platform.
  • Incident response procedures for detecting and responding to data breaches.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will update the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

11. Contact Us

For any questions about this Privacy Policy or to exercise your rights, please contact CYBERZONIC LIMITED at:

privacy@cyberzonic.com