Legal

Last updated: 03 August 2026

Privacy Policy

CyberException Ltd respects your privacy. This policy explains what data we collect, why we collect it, and how we keep it safe — in plain English.

Who We Are

CyberException Ltd ("CyberException," "we," "us," or "our") is a UK-based cybersecurity and technology consultancy registered in England and Wales. Our registered office is in London, United Kingdom.

This Privacy Policy applies to our website at cyberexception.com and all associated services, forms, and communications (together, "Services"). By using our Services you agree to the practices described here.

For questions about this policy or to exercise your data rights, email us at [email protected].

Information We Collect

We only collect what we genuinely need. Depending on how you interact with us, we may collect:

  • Contact information — name, email address, phone number, and company name when you fill in a contact or booking form.
  • Enquiry content — details of your project, technical environment, or security questions that you choose to share with us.
  • Usage data — pages visited, time on site, referral source, browser type, device type, and IP address, collected automatically via cookies and analytics tools.
  • Communications — emails, call notes, and records of conversations when you engage with our team.
  • Marketing preferences — whether you opt in or out of marketing emails.

We do not collect sensitive personal data (such as health, financial account, or biometric data) through our website.

How We Use It

We use the information we collect for the following purposes, each with a corresponding lawful basis under UK GDPR:

  • To respond to enquiries and deliver our Services — performance of a contract or steps taken at your request prior to entering into one.
  • To send service-related communications — including project updates, invoices, and meeting confirmations — legitimate interests / contractual necessity.
  • To send marketing emails (blog posts, case studies, news) — only with your explicit consent, which you may withdraw at any time.
  • To improve our website — analysing usage patterns through aggregated, anonymised analytics — legitimate interests.
  • To comply with legal obligations — such as tax records or responding to lawful requests from regulators.

We will never use your data for automated decision-making that produces significant legal or similarly significant effects on you.

How We Share It

We do not sell your personal data. We share data only where necessary, with the following categories of recipients:

  • Service providers — such as email platforms, CRM tools, scheduling software, and cloud hosting providers, acting as data processors under contract with us.
  • Analytics providers — including Google Analytics (anonymised/aggregated data only). You may opt out of Google Analytics at tools.google.com/dlpage/gaoptout.
  • Legal or regulatory bodies — if we are required to disclose data under applicable law or to protect our rights and the safety of others.
  • Business successors — in the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity under equivalent protections.

Any third-party processors are bound by data processing agreements requiring them to protect your data in accordance with UK GDPR.

Cookies & Tracking

We use cookies and similar technologies to make our website work, understand how it is used, and — with your consent — to support marketing. Cookies are small text files stored on your device. We use the following types:

  • Strictly necessary — essential for the website to function (e.g. security, session management). These cannot be disabled.
  • Analytics — help us understand how visitors use the site so we can improve it. Used only with your consent.
  • Marketing / Preferences — remember your preferences and support any retargeting we may use. Used only with your consent.

You can review and change your cookie preferences at any time:

Most browsers also allow you to refuse or delete cookies via their settings. Note that disabling analytics cookies will not affect your ability to use the site.

Data Retention

We keep your data only for as long as necessary for the purpose it was collected, or as required by law:

  • Enquiry and contact data — retained for up to 3 years from last contact, unless we enter a client relationship.
  • Client records — retained for 7 years after the end of an engagement to comply with UK financial and legal obligations.
  • Marketing consent records — retained until you withdraw consent, plus a reasonable period for compliance evidence.
  • Website analytics — aggregated data retained for up to 26 months; raw session data deleted sooner.

When data is no longer needed, we securely delete or anonymise it.

Security

We take security seriously — it's literally what we do. We apply appropriate technical and organisational measures to protect your data from unauthorised access, disclosure, alteration, and loss. These include:

  • Encrypted data transmission (TLS) across all our systems
  • Access controls limiting data to those who need it
  • Regular security reviews of our own infrastructure and tooling
  • Vetted, contracted third-party processors only

No internet transmission is completely secure, but we take all reasonable steps to protect your information. If you have concerns about a specific data security issue, please contact us immediately.

Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data where there is no legitimate reason to retain it.
  • Restriction — ask us to limit how we process your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have handled your data unlawfully.

Children

Our Services are not directed at children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, please contact us and we will delete it promptly.

International Transfers

CyberException is a UK-based company and we store data primarily within the UK and EEA. Where we use third-party service providers based outside the UK/EEA, we ensure appropriate safeguards are in place, such as UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses approved by the relevant authority, to ensure your data receives equivalent protection.

Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, notify you by email. Your continued use of our Services after any changes constitutes your acceptance of the updated policy.

We recommend reviewing this page periodically to stay informed of how we protect your data.

Contact Us

If you have any questions about this Privacy Policy, how we handle your data, or to exercise your rights, please get in touch:

CyberException Ltd

London, United Kingdom
Email: [email protected]
Phone: 07352 131 787

Scroll to Top