- Who we are and how to reach us
- Scope: controller and processor roles
- Personal data we collect
- Purposes and legal bases
- Cookies
- Who we share data with
- International data transfers
- How long we keep personal data
- How we protect personal data
- Your rights - UK & EU
- Your rights - Australia
- Automated decision-making
- Children
- Third-party links
- Changes to this policy
- Contact and complaints
1. Who we are and how to reach us
Cyse Ltd ("Cyse", "we", "us") is a cybersecurity and information security service provider. We are a company registered in England and Wales, with our registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, and further offices in Sydney and New York.
For personal data processed through this website and in the course of our own business relationships, Cyse Ltd is the data controller for the purposes of the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, and - where our services are offered to individuals in the European Economic Area - the EU General Data Protection Regulation ("EU GDPR"). In respect of personal information handled through our Australian operations, we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
Privacy questions, rights requests, and complaints can be raised at any time through our contact page or by post to the registered office above, marked for the attention of the Privacy Team.
2. Scope: when we are controller and when we are processor
This policy covers the personal data for which Cyse is the controller: information about website visitors, prospective and current clients, suppliers, job applicants, and people who correspond with us.
It works differently during service delivery. When we perform security engagements - penetration testing, incident response, monitoring, and similar - we routinely encounter personal data held in our clients' systems. In those situations the client is the controller and Cyse acts as a processor (or, in Australian terms, handles the information on the client's behalf), under a written contract and data processing agreement that governs what we may do with it. That data is used solely to deliver the engagement, is minimised and protected as described in our contracts, and is never used for our own purposes.
3. Personal data we collect
We collect only the personal data we need, most of it provided directly by you:
- Enquiries and correspondence - your name, email address, chosen subject, and the content of your message when you use our contact form, email us, or speak with us.
- Vulnerability reports - the name or alias, email address, report content, and any evidence files you submit through our vulnerability disclosure form.
- Client and supplier relationship data - business contact details, engagement records, and billing information needed to scope, deliver, and invoice our services.
- Job applications - the information you include when applying for a role, such as your CV, work history, and interview notes.
- Technical data - standard server logs (IP address, user agent, pages requested) generated automatically when you browse this website, kept for security and troubleshooting.
We do not buy personal data from third parties, we do not use advertising trackers on this website, and we do not intentionally collect special category (sensitive) data through this site - please don't include it in enquiry or report forms.
4. Purposes and legal bases for processing
Under the UK and EU GDPR, each use of personal data needs a lawful basis. Ours are:
- Responding to enquiries and providing services - performance of a contract, or steps taken at your request before entering one (Article 6(1)(b)); otherwise our legitimate interest in running our business (Article 6(1)(f)).
- Handling vulnerability reports - our legitimate interests in securing our systems and operating a responsible disclosure programme (Article 6(1)(f)).
- Assessing job applications - steps taken at your request prior to entering an employment contract (Article 6(1)(b)).
- Protecting this website and our infrastructure from abuse - our legitimate interests in security and fraud prevention (Article 6(1)(f)).
- Meeting legal and regulatory obligations - such as accounting, tax, and lawful requests from authorities (Article 6(1)(c)).
- Anything based on consent - where we ever rely on consent (Article 6(1)(a)), it is asked for separately and can be withdrawn at any time without affecting prior processing.
Where the Privacy Act 1988 applies, we collect personal information only where it is reasonably necessary for our functions and activities (APP 3), by lawful and fair means, and we use or disclose it only for the purpose it was collected for, a directly related secondary purpose you would reasonably expect, or otherwise with your consent or as permitted by law (APP 6).
5. Cookies
This website uses only the minimal cookies necessary for it to function - for example, a session cookie that protects our forms against cross-site request forgery. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list.
6. Who we share data with
We do not sell personal data, and we never will. We share it only with:
- Service providers who host our infrastructure, email, and business tooling, under contracts that bind them to confidentiality and to processing data only on our instructions.
- Professional advisers - lawyers, accountants, auditors, and insurers - where necessary and subject to their own professional duties of confidence.
- Authorities and regulators, where disclosure is required by law, by a binding order, or is necessary to establish, exercise, or defend legal claims.
- A successor organisation, in the unlikely event of a merger, acquisition, or restructuring - in which case this policy would continue to apply to your data.
7. International data transfers
Because we operate from the United Kingdom, Australia, and the United States, personal data may be accessed from or transferred between these locations. Wherever data protected by the UK or EU GDPR leaves the UK or EEA, we rely on recognised safeguards: an adequacy decision where one exists, or standard contractual clauses (including the UK International Data Transfer Addendum) together with any additional measures needed to keep the data protected to the same standard.
Where the Privacy Act 1988 applies, we take reasonable steps before disclosing personal information overseas to ensure the recipient handles it consistently with the APPs (APP 8), and we remain accountable for it in accordance with the Act.
8. How long we keep personal data
We keep personal data only as long as we need it for the purpose it was collected, then delete or anonymise it. Typical periods:
| Data | Retention |
|---|---|
| Enquiry correspondence | As long as needed to handle your request, then typically no more than 24 months. |
| Vulnerability reports | For the life of the issue and a reasonable audit period afterwards. |
| Client engagement and billing records | For the duration of the relationship, then as required by law (typically 6-7 years for accounting and tax records). |
| Unsuccessful job applications | Deleted within 6 months of the decision unless you ask us to keep them on file. |
| Server logs | Rotated on a short cycle, typically 30 days. |
9. How we protect personal data
We hold ourselves to the standards we advise on. Personal data is protected with encryption in transit and at rest, least-privilege access controls, logging and monitoring, and vetted personnel bound by confidentiality obligations. In the event of a data breach likely to result in risk to individuals, we will notify the relevant supervisory authority - the ICO within 72 hours where the UK GDPR requires it, and the OAIC and affected individuals where the Australian Notifiable Data Breaches scheme applies - and tell affected people without undue delay. Our own security practices are described further on our Security page.
10. Your rights UK & EU
If the UK or EU GDPR applies to our processing of your data, you have the right to:
- Access - obtain a copy of the personal data we hold about you, along with information about how we use it.
- Rectification - have inaccurate data corrected and incomplete data completed.
- Erasure - have your data deleted where there is no longer a lawful reason for us to keep it.
- Restriction - limit how we use your data while a dispute about it is resolved.
- Portability - receive data you provided to us in a structured, machine-readable format.
- Objection - object to processing based on our legitimate interests, and to any direct marketing at any time.
- Withdraw consent - where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us. We respond within one month, we don't charge for reasonable requests, and we may need to verify your identity first. If you're unhappy with our answer, you can complain to your supervisory authority - in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, your national data protection authority.
11. Your rights Australia
If your personal information is handled through our Australian operations, the Privacy Act 1988 gives you the right to:
- Access the personal information we hold about you (APP 12).
- Correction of information that is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13).
- Anonymity - deal with us anonymously or under a pseudonym where lawful and practicable (APP 2).
- Complain about a breach of the APPs and have that complaint handled promptly.
Requests and complaints can be made through our contact page; we will acknowledge and respond within a reasonable period. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
12. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, and we do not profile visitors to this website.
13. Children
Our services and this website are directed at businesses and professionals, not at children. We do not knowingly collect personal data from anyone under 16; if you believe a child has provided us with personal data, contact us and we will delete it.
14. Third-party links
This website links to external sites - such as our social media profiles and the regulators mentioned above. Those sites have their own privacy policies, and we are not responsible for their content or practices.
15. Changes to this policy
We may update this policy from time to time as our services or the law change. The "last updated" date at the top of this page always reflects the current version, and material changes will be highlighted here. Significant changes affecting existing clients are communicated directly.
16. Contact and complaints
Questions about this policy or our handling of your data can be sent via our contact page, or by post to:
Cyse Ltd
71-75 Shelton Street, Covent Garden
London, WC2H 9JQ
United Kingdom
We take every privacy concern seriously and would welcome the chance to resolve yours directly - but nothing in this policy limits your right to go straight to the ICO, the OAIC, or your local supervisory authority.