Privacy Policy
Last updated: 3rd February 2026
This Privacy Policy explains how CyberSentrx Ltd ("CyberSentrx", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you access or use our website, platform, products, and related services (collectively, the "Services").
CyberSentrx Ltd is a cybersecurity company registered in the United Kingdom with operations in both the United Kingdom and the United States, delivering enterprise‑grade solutions that help small and medium‑sized businesses protect and manage their external digital identity and security posture.
This policy applies to visitors to https://cybersentrx.com/ and users of our Services worldwide.
1. Controller Information
For purposes of data protection law, including the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU GDPR, the data controller is:
CyberSentrx Ltd
Website: https://cybersentrx.com/
2. Scope of This Policy
This Privacy Policy covers personal data collected when you:
- Visit or interact with our website
- Request information or demos
- Register for or use our platform
- Communicate with us as a customer, partner, or supplier
- Attend events or marketing activities
- Interact with our communications or marketing materials
This policy does not apply to third‑party websites or services linked from our Services.
3. Personal Data We Collect
We may collect the following categories of personal data.
A. Information You Provide
This may include:
- Name and job title
- Company name and business contact details
- Email address and telephone number
- Account login credentials
- Billing and contract information
- Communications and support requests
- Information provided in forms or event registrations
B. Information Collected Automatically
When you use our Services, we may collect:
- IP address and approximate location
- Browser and device information
- Usage data and access logs
- Platform interaction data
- Cookies and similar technology data
C. Information From Third Parties
We may receive information from:
- Business partners and resellers
- Marketing or event partners
- Publicly available business sources
- Security and fraud prevention providers
4. How We Use Personal Data
We use personal data to:
- Provide, operate, and maintain our Services
- Authenticate users and manage accounts
- Deliver cybersecurity services and platform functionality
- Detect, prevent, and investigate security incidents
- Provide customer and technical support
- Process transactions and manage contracts
- Communicate service updates and notices
- Improve service quality and performance
- Conduct analytics and business planning
- Provide marketing communications where permitted
- Comply with legal and regulatory obligations
We aim to minimise personal data processing and use aggregated or anonymised data where possible.
5. Legal Bases for Processing (UK & EEA)
Under UK GDPR and EU GDPR, we rely on one or more of the following legal bases:
- Performance of a contract
- Legitimate interests, including operating and securing our Services
- Compliance with legal obligations
- Consent, where required
Legitimate interests include service security, fraud prevention, service improvement, and business operations, balanced against individual rights.
6. How We Share Personal Data
We do not sell personal data. We may share data with:
A. Service Providers
Providers supporting our operations, including:
- Cloud hosting and infrastructure providers
- Security and monitoring services
- Analytics providers
- Customer support tools
- Billing and payment processors
- Marketing and CRM providers
All providers are contractually required to protect personal data.
B. Business Transfers
In connection with mergers, acquisitions, or asset transfers.
C. Legal and Regulatory Requirements
Where required by law, regulation, court order, or to protect rights, safety, or security.
D. Corporate Customers
Where users access Services through an employer or organisation, relevant usage data may be accessible to that organisation as part of service administration.
7. International Data Transfers
CyberSentrx operates globally, and personal data may be processed outside the UK.
Where data is transferred internationally, we implement safeguards such as:
- UK International Data Transfer Agreements or Addenda
- Standard Contractual Clauses
- Transfers to jurisdictions with recognised adequacy protections
8. Data Security
As a cybersecurity provider, protecting data is central to our operations. We implement appropriate technical and organisational measures, including:
- Encryption and access controls
- Monitoring and incident detection
- Secure infrastructure practices
- Principle of least‑privilege access
- Regular security reviews and improvements
No system is completely secure, but we continuously improve our security posture.
9. Data Retention
We retain personal data only as long as necessary for:
- Service delivery
- Legal and regulatory compliance
- Contractual obligations
- Legitimate business purposes
- Dispute resolution and enforcement
Retention periods vary based on data type and operational requirements.
10. Individual Rights (UK & EEA)
Individuals may have rights to:
- Access personal data
- Correct inaccurate data
- Request erasure
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent where applicable
Requests can be submitted using the contact details below. We may require identity verification.
Individuals also have the right to complain to a data protection authority, including the UK Information Commissioner’s Office (ICO).
11. Marketing Communications
We may send business‑related marketing communications where permitted by law. Recipients may opt out at any time via unsubscribe links or by contacting us.
Service and transactional communications are not marketing and cannot be opted out of while using Services.
12. Cookies and Tracking Technologies
We use cookies and related technologies as described in our Cookies Policy available at: https://cybersentrx.com/
Users may control cookie preferences through browser settings or consent tools where required.
13. Children’s Privacy
Our Services are not directed to children, and we do not knowingly collect personal data from individuals under 16 years of age.
14. Third‑Party Services
Our Services may contain links or integrations with third‑party platforms. We are not responsible for third‑party privacy practices.
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect legal, technical, or operational changes. Updates will be posted with a revised effective date.
16. Contact Us
For privacy or data protection enquiries, please use the contact us form on our website:
CyberSentrx Ltd
Website: https://cybersentrx.com/
17. Enterprise and Customer Data Processing
Where CyberSentrx processes personal data on behalf of customers as part of providing platform services, we act as a data processor, and processing is governed by customer agreements and Data Processing Agreements (DPAs).
Customers remain responsible for data uploaded or processed through their use of the platform.
