Privacy Policy

Last updated: 3rd February 2026

This Privacy Policy explains how CyberSentrx Ltd ("CyberSentrx", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you access or use our website, platform, products, and related services (collectively, the "Services").

CyberSentrx Ltd is a cybersecurity company registered in the United Kingdom with operations in both the United Kingdom and the United States, delivering enterprise‑grade solutions that help small and medium‑sized businesses protect and manage their external digital identity and security posture.

This policy applies to visitors to https://cybersentrx.com/ and users of our Services worldwide.

1. Controller Information

For purposes of data protection law, including the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU GDPR, the data controller is:

CyberSentrx Ltd

Website: https://cybersentrx.com/

2. Scope of This Policy

This Privacy Policy covers personal data collected when you:

  • Visit or interact with our website
  • Request information or demos
  • Register for or use our platform
  • Communicate with us as a customer, partner, or supplier
  • Attend events or marketing activities
  • Interact with our communications or marketing materials

This policy does not apply to third‑party websites or services linked from our Services.

3. Personal Data We Collect

We may collect the following categories of personal data.

A. Information You Provide

This may include:

  • Name and job title
  • Company name and business contact details
  • Email address and telephone number
  • Account login credentials
  • Billing and contract information
  • Communications and support requests
  • Information provided in forms or event registrations

B. Information Collected Automatically

When you use our Services, we may collect:

  • IP address and approximate location
  • Browser and device information
  • Usage data and access logs
  • Platform interaction data
  • Cookies and similar technology data

C. Information From Third Parties

We may receive information from:

  • Business partners and resellers
  • Marketing or event partners
  • Publicly available business sources
  • Security and fraud prevention providers

4. How We Use Personal Data

We use personal data to:

  • Provide, operate, and maintain our Services
  • Authenticate users and manage accounts
  • Deliver cybersecurity services and platform functionality
  • Detect, prevent, and investigate security incidents
  • Provide customer and technical support
  • Process transactions and manage contracts
  • Communicate service updates and notices
  • Improve service quality and performance
  • Conduct analytics and business planning
  • Provide marketing communications where permitted
  • Comply with legal and regulatory obligations

We aim to minimise personal data processing and use aggregated or anonymised data where possible.

5. Legal Bases for Processing (UK & EEA)

Under UK GDPR and EU GDPR, we rely on one or more of the following legal bases:

  • Performance of a contract
  • Legitimate interests, including operating and securing our Services
  • Compliance with legal obligations
  • Consent, where required

Legitimate interests include service security, fraud prevention, service improvement, and business operations, balanced against individual rights.

6. How We Share Personal Data

We do not sell personal data. We may share data with:

A. Service Providers

Providers supporting our operations, including:

  • Cloud hosting and infrastructure providers
  • Security and monitoring services
  • Analytics providers
  • Customer support tools
  • Billing and payment processors
  • Marketing and CRM providers

All providers are contractually required to protect personal data.

B. Business Transfers

In connection with mergers, acquisitions, or asset transfers.

C. Legal and Regulatory Requirements

Where required by law, regulation, court order, or to protect rights, safety, or security.

D. Corporate Customers

Where users access Services through an employer or organisation, relevant usage data may be accessible to that organisation as part of service administration.

7. International Data Transfers

CyberSentrx operates globally, and personal data may be processed outside the UK.

Where data is transferred internationally, we implement safeguards such as:

  • UK International Data Transfer Agreements or Addenda
  • Standard Contractual Clauses
  • Transfers to jurisdictions with recognised adequacy protections

8. Data Security

As a cybersecurity provider, protecting data is central to our operations. We implement appropriate technical and organisational measures, including:

  • Encryption and access controls
  • Monitoring and incident detection
  • Secure infrastructure practices
  • Principle of least‑privilege access
  • Regular security reviews and improvements

No system is completely secure, but we continuously improve our security posture.

9. Data Retention

We retain personal data only as long as necessary for:

  • Service delivery
  • Legal and regulatory compliance
  • Contractual obligations
  • Legitimate business purposes
  • Dispute resolution and enforcement

Retention periods vary based on data type and operational requirements.

10. Individual Rights (UK & EEA)

Individuals may have rights to:

  • Access personal data
  • Correct inaccurate data
  • Request erasure
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent where applicable

Requests can be submitted using the contact details below. We may require identity verification.

Individuals also have the right to complain to a data protection authority, including the UK Information Commissioner’s Office (ICO).

11. Marketing Communications

We may send business‑related marketing communications where permitted by law. Recipients may opt out at any time via unsubscribe links or by contacting us.

Service and transactional communications are not marketing and cannot be opted out of while using Services.

12. Cookies and Tracking Technologies

We use cookies and related technologies as described in our Cookies Policy available at: https://cybersentrx.com/

Users may control cookie preferences through browser settings or consent tools where required.

13. Children’s Privacy

Our Services are not directed to children, and we do not knowingly collect personal data from individuals under 16 years of age.

14. Third‑Party Services

Our Services may contain links or integrations with third‑party platforms. We are not responsible for third‑party privacy practices.

15. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. Updates will be posted with a revised effective date.

16. Contact Us

For privacy or data protection enquiries, please use the contact us form on our website:

CyberSentrx Ltd

Website: https://cybersentrx.com/

17. Enterprise and Customer Data Processing

Where CyberSentrx processes personal data on behalf of customers as part of providing platform services, we act as a data processor, and processing is governed by customer agreements and Data Processing Agreements (DPAs).

Customers remain responsible for data uploaded or processed through their use of the platform.