Cyber Certain Limited (referred to in this document as “we”, “us” or “our”) is committed to protecting your privacy in alignment with our cybersecurity services. This privacy policy outlines how we collect, use, and safeguard your personal data, as well as your rights and choices regarding the information we gather. This notice applies to all data that we collect about you. Please read this notice carefully and contact us if you have any questions regarding our fractional CISO services, using the details provided in the contact and feedback section below.
Personal data we collect about you, including information relevant to our cybersecurity services. Why we collect your personal data as part of our privacy policy. When we collect your data, how long we keep it for, and how our fractional CISO ensures its security. What we do with your data to enhance our services. How we and other organizations will keep your personal data safe against potential threats. The rights and choices you have when it comes to your personal data remain unchanged.
As the Data Controller, we are committed to ensuring that our systems, processes, suppliers, and employees comply with applicable data protection laws when handling personal data. This commitment is part of our comprehensive cybersecurity services, ensuring effective management of data security. If you have any questions or concerns about our privacy policy or the role of our fractional CISO, you can contact us: Email: info@cybercertain.co.uk Post: Please refer to the contact and feedback section on the website for our registered office address.
We collect your personal details, including your name, telephone number, and email address, to keep you informed about our cybersecurity services and provide updates relevant to the services we are delivering to you. This information is crucial for effective communication.
Special category data refers to sensitive personal information requiring enhanced protection due to its nature. Cyber Certain Limited does not typically require this type of information during interactions. However, in rare cases where it is necessary, rest assured it will be used solely for the specific purpose you provide and to offer the services described in our privacy policy on our website.
Regarding website usage data, we collect information about your interaction with our website through the use of cookies. This data helps us improve your experience and understand usage patterns related to our cybersecurity services.
We are committed to collecting only the personal data necessary to manage and deliver our services to you, ensuring we do not gather any unnecessary information.
If you provide an email address that is shared with others, please note that we may send communications containing special category data to that address. To protect your privacy, make sure the email address is either private or shared only with individuals you trust to have access to this sensitive information. Additionally, should you need guidance, consider consulting a fractional CISO for best practices in data privacy.
We collect your personal data to:
Provide specialist cybersecurity services: If you instruct us or seek to instruct us to act on your behalf or on behalf of someone else, we require your data to assess and fulfill your instructions. Without this information, we may be unable to deliver our services, including our fractional CISO offerings, to you.
Prevent Conflict of Interest: Where relevant, we collect identity information to ensure that we avoid any conflict of interest among our customers in the future.
Protect your privacy: We respect your privacy policy and do not sell your data.
Respect your preferences: We will not share your data for marketing purposes unless we have informed you and obtained your informed consent.
We collect and retain your data as follows:
Before you become a customer of our cybersecurity services: We collect personal data to assess whether we can act for you.
During the course of any business interactions: We collect additional data and, where appropriate, seek additional consent to process your data throughout the consultancy services, including our fractional CISO offerings, we are providing for you. This is done in accordance with our privacy policy.
In most cases, we retain your data for 7 years from the conclusion of the procured service to comply with legal and regulatory obligations, especially in the realm of cybersecurity services. In certain situations, we may need to keep documents for a longer duration, and if that applies to you, we will explain the reasons for this extended retention period. For full details regarding our retention periods and our privacy policy, please feel free to request additional information.
If we intend to use your data for a purpose not covered by this Privacy Policy, we will issue a new Privacy Notice and seek your consent where necessary, especially in relation to our cybersecurity services and the role of a fractional CISO.
We will use your data to:
- Assess whether we can act as your trusted partner in providing cybersecurity services.
- Offer IT consultancy services, advice, and support, including our fractional CISO solutions.
- Manage and oversee the services we provide to ensure compliance with our privacy policy.
- Contact and communicate with you throughout our interactions to enhance your experience.
- Maintain internal record keeping and analysis for better service management.
- Measure and improve customer services and experiences, using surveys and online reviews as feedback mechanisms.
- Investigate any concerns or complaints you may have about our services.
You have a number of legal rights over the personal information we hold, in accordance with our privacy policy. These rights include the ability to:
- Access your personal information kept in our records, whether electronically or manually.
- Correct or update any personal information that you believe is inaccurate.
- Object to further processing of your data.
- Request the deletion of your personal information. We can only fulfill this request if it is no longer necessary for the purposes it was provided or if we no longer have a lawful basis to process your personal information.
- Receive your personal information in a portable format.
- Obtain information about decisions made through any automated means.
- Request us to stop processing your personal information under certain circumstances.
When we utilize Artificial Intelligence (AI) or other automated systems in our cybersecurity services for decision-making, you have the right to understand how these decisions are made and to challenge them if they significantly impact you. We are committed to transparency and fairness in all automated processes, including those led by our fractional CISO.
To exercise these rights, please contact info@cybercertain.co.uk for further details on how to do this.
Additional information can also be found on the Information Commissioner’s Office website (www.ico.org.uk).
I would love to hear how I can assist with your cybersecurity services and address your information security needs. Feel free to get in touch with me to discuss anything from privacy policies to the benefits of a fractional CISO.
Email me: info@cybercertain.co.uk
Limited Company Number: 16919869
Copyright © 2026 Cyber Certain Limited - All Rights Reserved.