Who We Are - Data Controller Details
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller for personal data collected through our UK website and services is:
| Detail | Information |
|---|---|
| Organisation | Cypherox Technologies Pvt. Ltd |
| UK Address | Office 18010, 182-184 High Street North, East Ham, London, E6 2JA |
| [email protected] | |
| Phone | +44 7453 420874 |
| Data Protection Contact | [email protected] |
Note: Under UK GDPR, organisations that systematically monitor individuals or process special category data at scale must appoint a Data Protection Officer (DPO). If Cypherox's processing activities meet this threshold, a formal DPO should be designated and notified to the ICO.
What Personal Data We Collect
We collect personal data in the following categories:
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | First name, last name, job title, company name | Contact forms, enquiries, onboarding |
| Contact Data | Email address, phone number, postal address | Contact forms, calls, emails |
| Technical Data | IP address, browser type, device type, OS, referral source, pages visited, session duration | Automatically via cookies and analytics |
| Usage Data | How you interact with our website; pages viewed; links clicked | Automatically during website visits |
| Communication Data | Content of emails, enquiries, messages, or call notes | When you contact us or we communicate during a project |
| Financial Data | Invoice details, payment records (we do not store card numbers) | During invoicing and payment processing |
| Project Data | Files, documents, content and assets shared for project delivery | During active engagements |
| Marketing Data | Preferences for receiving marketing communications | When you opt in or contact us |
We do not knowingly collect special category data (such as health, biometric, or racial data) or personal data from individuals under 18. If you believe we have inadvertently collected such data, please contact us immediately.
How We Collect Your Data
We collect personal data through the following means:
- Direct interactions: When you complete our contact form, book a call, send us an email, or engage our services
- Automated technologies: Via cookies, web beacons and analytics tools as you navigate our website
- Third parties: Through business introductions, referrals, professional networking platforms (such as LinkedIn), or publicly available business directories
- Project delivery: Data and content you share with us in the course of our work together
Lawful Basis for Processing
We process your personal data under the following lawful bases as defined in UK GDPR Article 6:
| Purpose of Processing | Lawful Basis |
|---|---|
| Responding to enquiries and providing quotations | Legitimate interests / Pre-contractual steps |
| Delivering agreed services and managing projects | Performance of a contract |
| Sending invoices and processing payments | Performance of a contract / Legal obligation |
| Maintaining legal and accounting records | Legal obligation (HMRC requirements; 6 years) |
| Sending marketing emails and newsletters | Consent (you can withdraw at any time) |
| Website analytics and performance monitoring | Legitimate interests (with cookie consent where required) |
| Improving our services and client experience | Legitimate interests |
| Preventing fraud and ensuring security | Legitimate interests / Legal obligation |
How We Use Your Personal Data
We use the personal data we collect to:
- Respond to your enquiries and provide the information or services you request
- Deliver, manage and improve the services outlined in our service agreements
- Issue invoices, process payments and maintain financial records
- Communicate with you about your project, including progress updates and issue resolution
- Send you relevant updates, case studies and service information (where you have consented)
- Comply with legal obligations, including tax, anti-money laundering and accounting regulations
- Detect, investigate and prevent fraud, security breaches, or illegal activity
- Improve the performance, usability and content of our website
We will not use your data for purposes incompatible with those stated in this policy without first notifying you and obtaining any required consent.
Data Sharing & Third Parties
We do not sell your personal data. We share personal data only in the following circumstances:
- Service providers: Trusted third parties who assist us in operating our business (e.g., cloud hosting providers, payment processors, project management tools, analytics platforms). These providers are bound by contractual data processing agreements
- Professional advisors: Solicitors, accountants, or auditors where necessary for legal or compliance purposes, subject to professional confidentiality obligations
- Subcontractors: Specialist developers or designers engaged to assist with project delivery, under confidentiality and data protection obligations
- Law enforcement and regulators: Where required by law, court order, or a legitimate regulatory request
- Business transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction, subject to equivalent protections
International Data Transfers
Cypherox Technologies operates from India and the United Kingdom. When personal data is transferred from the UK to our India-based team or infrastructure, we ensure appropriate safeguards are in place as required by UK GDPR Chapter V.
Transfers to India are protected by one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs) approved by the ICO for international transfers
- Binding Corporate Rules (BCRs), where applicable
- Your explicit consent (where used as the transfer mechanism, you will be informed)
Where we use third-party service providers based in countries outside the UK, we conduct a Transfer Impact Assessment (TIA) and implement appropriate safeguards.
How Long We Keep Your Data
We retain personal data for no longer than necessary for the purposes for which it was collected:
| Data Type | Retention Period | Reason |
|---|---|---|
| Client contracts & project records | 7 years after project completion | Legal / contractual obligation |
| Financial & invoicing records | 6 years from end of tax year | HMRC legal requirement |
| Enquiry & contact form data | 2 years if no contract follows | Legitimate interests (follow-up) |
| Marketing consent records | Until consent is withdrawn | Consent-based processing |
| Website analytics data | 26 months (anonymised after 13 months) | Legitimate interests |
| Job application data | 12 months if unsuccessful | Legitimate interests |
After the applicable retention period, data is securely deleted or anonymised.
Your Rights Under UK GDPR
Under the UK GDPR and the Data Protection Act 2018, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you (Subject Access Request). We will respond within 30 days at no charge.
- Right to Rectification: Ask us to correct inaccurate or incomplete personal data without delay.
- Right to Erasure: Request deletion of your personal data where it is no longer necessary or you withdraw consent, subject to legal retention requirements.
- Right to Restrict Processing: Ask us to pause processing of your data in certain circumstances, such as while you contest its accuracy.
- Right to Data Portability: Receive your personal data in a structured, machine-readable format and transfer it to another controller where processing is consent-based or contract-based.
- Right to Object: Object to processing based on legitimate interests or for direct marketing. We will stop unless we can demonstrate compelling legitimate grounds.
- Rights Related to Automated Decisions: Not be subject to solely automated decisions that produce significant legal effects. We do not currently use automated decision-making of this nature.
- Right to Withdraw Consent: Withdraw consent at any time for consent-based processing. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond within one calendar month. We may need to verify your identity before processing your request.
Marketing Communications
We will only send you marketing emails, newsletters, or updates where you have given us explicit consent to do so, or where we have an existing business relationship and you have not opted out.
Every marketing communication includes an unsubscribe link. You may also opt out at any time by:
- Clicking "unsubscribe" in any marketing email
- Emailing us at [email protected] with the subject line "Unsubscribe"
- Calling our UK office on +44 7453 420874
Withdrawal of marketing consent does not affect our ability to contact you for service or contractual purposes.
Data Security
We take data security seriously and implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure.
These measures include:
- Encryption of data in transit (TLS/SSL) and at rest where appropriate
- Access controls and role-based permissions for internal systems
- Regular security assessments and code reviews
- Staff training on data protection and information security
- Secure disposal of data when no longer required
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours and inform affected individuals without undue delay, in accordance with UK GDPR Article 33.
Third-Party Links
Our website may contain links to third-party websites, including partner platforms, review sites and social media networks. This Privacy Policy does not apply to those external websites. We encourage you to review the privacy policies of any third-party site you visit.
We are not responsible for the content, privacy practices, or data security of third-party websites.
Children's Privacy
Our website and services are directed at business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
If we become aware that we have collected personal data from a child without verifiable parental consent, we will delete that data promptly. If you believe we may have collected data from a minor, please contact us at [email protected].
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal obligations, or regulatory guidance. We will post the revised policy on our website with an updated "Last Updated" date.
Where changes are material, we will notify active clients and newsletter subscribers by email at least 14 days before the changes take effect.
How to Make a Complaint
If you are unhappy with how we have handled your personal data, please contact us first at [email protected]. We will investigate and respond within 30 days.
If you remain unsatisfied with our response, you have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO):
| Detail | Information |
|---|---|
| Website | ico.org.uk |
| Helpline | 0303 123 1113 |
| Address | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
Contact Our Privacy Team
For all data protection enquiries, Subject Access Requests, or to exercise your rights under UK GDPR, please contact us:
| Detail | Information |
|---|---|
| Privacy Email | [email protected] |
| General Enquiries | [email protected] |
| UK Phone | +44 7453 420874 |
| UK Address | Office 18010, 182-184 High Street North, East Ham, London, E6 2JA |