Privacy Policy

Who We Are - Data Controller Details

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller for personal data collected through our UK website and services is:

Detail Information
Organisation Cypherox Technologies Pvt. Ltd
UK Address Office 18010, 182-184 High Street North, East Ham, London, E6 2JA
Email [email protected]
Phone +44 7453 420874
Data Protection Contact [email protected]

Note: Under UK GDPR, organisations that systematically monitor individuals or process special category data at scale must appoint a Data Protection Officer (DPO). If Cypherox's processing activities meet this threshold, a formal DPO should be designated and notified to the ICO.

What Personal Data We Collect

We collect personal data in the following categories:

Category Examples When Collected
Identity Data First name, last name, job title, company name Contact forms, enquiries, onboarding
Contact Data Email address, phone number, postal address Contact forms, calls, emails
Technical Data IP address, browser type, device type, OS, referral source, pages visited, session duration Automatically via cookies and analytics
Usage Data How you interact with our website; pages viewed; links clicked Automatically during website visits
Communication Data Content of emails, enquiries, messages, or call notes When you contact us or we communicate during a project
Financial Data Invoice details, payment records (we do not store card numbers) During invoicing and payment processing
Project Data Files, documents, content and assets shared for project delivery During active engagements
Marketing Data Preferences for receiving marketing communications When you opt in or contact us

We do not knowingly collect special category data (such as health, biometric, or racial data) or personal data from individuals under 18. If you believe we have inadvertently collected such data, please contact us immediately.

How We Collect Your Data

We collect personal data through the following means:

  • Direct interactions: When you complete our contact form, book a call, send us an email, or engage our services
  • Automated technologies: Via cookies, web beacons and analytics tools as you navigate our website
  • Third parties: Through business introductions, referrals, professional networking platforms (such as LinkedIn), or publicly available business directories
  • Project delivery: Data and content you share with us in the course of our work together

Lawful Basis for Processing

We process your personal data under the following lawful bases as defined in UK GDPR Article 6:

Purpose of Processing Lawful Basis
Responding to enquiries and providing quotations Legitimate interests / Pre-contractual steps
Delivering agreed services and managing projects Performance of a contract
Sending invoices and processing payments Performance of a contract / Legal obligation
Maintaining legal and accounting records Legal obligation (HMRC requirements; 6 years)
Sending marketing emails and newsletters Consent (you can withdraw at any time)
Website analytics and performance monitoring Legitimate interests (with cookie consent where required)
Improving our services and client experience Legitimate interests
Preventing fraud and ensuring security Legitimate interests / Legal obligation

How We Use Your Personal Data

We use the personal data we collect to:

  • Respond to your enquiries and provide the information or services you request
  • Deliver, manage and improve the services outlined in our service agreements
  • Issue invoices, process payments and maintain financial records
  • Communicate with you about your project, including progress updates and issue resolution
  • Send you relevant updates, case studies and service information (where you have consented)
  • Comply with legal obligations, including tax, anti-money laundering and accounting regulations
  • Detect, investigate and prevent fraud, security breaches, or illegal activity
  • Improve the performance, usability and content of our website

We will not use your data for purposes incompatible with those stated in this policy without first notifying you and obtaining any required consent.

Data Sharing & Third Parties

We do not sell your personal data. We share personal data only in the following circumstances:

  • Service providers: Trusted third parties who assist us in operating our business (e.g., cloud hosting providers, payment processors, project management tools, analytics platforms). These providers are bound by contractual data processing agreements
  • Professional advisors: Solicitors, accountants, or auditors where necessary for legal or compliance purposes, subject to professional confidentiality obligations
  • Subcontractors: Specialist developers or designers engaged to assist with project delivery, under confidentiality and data protection obligations
  • Law enforcement and regulators: Where required by law, court order, or a legitimate regulatory request
  • Business transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to equivalent protections

International Data Transfers

Cypherox Technologies operates from India and the United Kingdom. When personal data is transferred from the UK to our India-based team or infrastructure, we ensure appropriate safeguards are in place as required by UK GDPR Chapter V.

Transfers to India are protected by one or more of the following mechanisms:

  • Standard Contractual Clauses (SCCs) approved by the ICO for international transfers
  • Binding Corporate Rules (BCRs), where applicable
  • Your explicit consent (where used as the transfer mechanism, you will be informed)

Where we use third-party service providers based in countries outside the UK, we conduct a Transfer Impact Assessment (TIA) and implement appropriate safeguards.

How Long We Keep Your Data

We retain personal data for no longer than necessary for the purposes for which it was collected:

Data Type Retention Period Reason
Client contracts & project records 7 years after project completion Legal / contractual obligation
Financial & invoicing records 6 years from end of tax year HMRC legal requirement
Enquiry & contact form data 2 years if no contract follows Legitimate interests (follow-up)
Marketing consent records Until consent is withdrawn Consent-based processing
Website analytics data 26 months (anonymised after 13 months) Legitimate interests
Job application data 12 months if unsuccessful Legitimate interests

After the applicable retention period, data is securely deleted or anonymised.

Your Rights Under UK GDPR

Under the UK GDPR and the Data Protection Act 2018, you have the following rights:

  • Right of Access: Request a copy of the personal data we hold about you (Subject Access Request). We will respond within 30 days at no charge.
  • Right to Rectification: Ask us to correct inaccurate or incomplete personal data without delay.
  • Right to Erasure: Request deletion of your personal data where it is no longer necessary or you withdraw consent, subject to legal retention requirements.
  • Right to Restrict Processing: Ask us to pause processing of your data in certain circumstances, such as while you contest its accuracy.
  • Right to Data Portability: Receive your personal data in a structured, machine-readable format and transfer it to another controller where processing is consent-based or contract-based.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing. We will stop unless we can demonstrate compelling legitimate grounds.
  • Rights Related to Automated Decisions: Not be subject to solely automated decisions that produce significant legal effects. We do not currently use automated decision-making of this nature.
  • Right to Withdraw Consent: Withdraw consent at any time for consent-based processing. This does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month. We may need to verify your identity before processing your request.

Cookies & Tracking Technologies

Our website uses cookies in accordance with the Privacy and Electronic Communications Regulations (PECR) 2003 and UK GDPR. A cookie is a small file placed on your device when you visit our website.

Cookie Type Purpose Consent Required?
Strictly Necessary Essential for website functionality (e.g., security, form submission, session management) No (exempt)
Analytics Understand how visitors use our website (e.g., Google Analytics) Yes
Functional Remember your preferences and improve your experience Yes
Marketing Track visitors for remarketing and targeted advertising purposes Yes

When you first visit our website, you will be presented with a cookie consent banner. You may accept all cookies, reject non-essential cookies, or manage your preferences. You can withdraw or change your cookie preferences at any time via the cookie settings link in our website footer.

Most browsers also allow you to control cookies through your browser settings. Please note that blocking essential cookies may affect website functionality.

Marketing Communications

We will only send you marketing emails, newsletters, or updates where you have given us explicit consent to do so, or where we have an existing business relationship and you have not opted out.

Every marketing communication includes an unsubscribe link. You may also opt out at any time by:

Withdrawal of marketing consent does not affect our ability to contact you for service or contractual purposes.

Data Security

We take data security seriously and implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure.

These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest where appropriate
  • Access controls and role-based permissions for internal systems
  • Regular security assessments and code reviews
  • Staff training on data protection and information security
  • Secure disposal of data when no longer required

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, in accordance with UK GDPR Article 33.

Children's Privacy

Our website and services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.

If we become aware that we have collected personal data from a child without verifiable parental consent, we will delete that data promptly. If you believe we may have collected data from a minor, please contact us at [email protected].

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal obligations, or regulatory guidance. We will post the revised policy on our website with an updated "Last Updated" date.

Where changes are material, we will notify active clients and newsletter subscribers by email at least 14 days before the changes take effect.

How to Make a Complaint

If you are unhappy with how we have handled your personal data, please contact us first at [email protected]. We will investigate and respond within 30 days.

If you remain unsatisfied with our response, you have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO):

Detail Information
Website ico.org.uk
Helpline 0303 123 1113
Address Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Contact Our Privacy Team

For all data protection enquiries, Subject Access Requests, or to exercise your rights under UK GDPR, please contact us:

Detail Information
Privacy Email [email protected]
General Enquiries [email protected]
UK Phone +44 7453 420874
UK Address Office 18010, 182-184 High Street North, East Ham, London, E6 2JA