Privacy Policy

Last updated 15 June 2026

Who we are

Cyber Alchemy Ltd (“we”, “us”, “our”) is the data controller for the personal information described in this notice. We are a UK cyber security consultancy registered in England and Wales (company number 14103809, with our registered office at Unit G1, Advanced Manufacturing Park Technology Centre, Brunel Way, Catcliffe, Rotherham, S60 5WG.

This notice explains what personal information we collect, why, and what rights you have over it. It applies when you visit https://cyberalchemy.co.uk, contact us, request resources such as our threat guides, or deal with us in the course of sales, marketing or the delivery of our services.

For anything relating to your data or this notice, you can contact our Data Protection Officer (DPO) by email at info@cyberalchemy.co.uk, or by post at the address above.

Summary

  • We mainly collect business contact details you give us — name, work email, phone, company, job title — plus the content of your enquiries.
  • We use this to respond to you, deliver our services, run and secure our website, and (where appropriate) market relevant services to you.
  • We do not process special category (“sensitive”) data, and we do not knowingly collect data about children.
  • We use a small number of third-party providers, some of which are based outside the UK.
  • Non-essential cookies are only set with your consent. You can change your choices at any time via the cookie banner.
  • You have rights over your data, including access, correction and deletion, and the right to complain to the ICO.

1. What information we collect

Information you give us. When you contact us, request a resource, or engage us, you may provide:

  • name
  • business email address
  • phone number
  • company name and job title
  • the content of your message or enquiry
  • contact and marketing preferences

We do not ask for special category data (such as health, race or political opinions) and ask that you do not send it to us through the website.

Information collected automatically. When you use the site we collect technical data such as IP address, browser and device type, operating system, referring pages, and how you interact with the site. We use this to keep the site working and secure and to understand how it is used. Some of this is collected through cookies and similar technologies — see our Cookie Policy and section 5 below.


2. How we use your information, and our legal bases

Under UK GDPR we must have a lawful basis for each use of your information. Ours are:

To respond to enquiries and deliver our services — contract / legitimate interests. Replying to you, scoping work, and delivering the engagements you have asked for.

To run and secure our website — legitimate interests. Keeping the site available, diagnosing faults, and protecting against fraud and abuse.

To understand and improve how the site is used — consent. Analytics and similar measurement that relies on non-essential cookies is only carried out with your consent.

To send you relevant marketing — legitimate interests / consent. We may send business-to-business marketing about our services to existing and prospective business contacts, in line with PECR. You can opt out at any time (see section 9). Where consent is required, we rely on it, and you can withdraw it at any time.

To meet our legal obligations — legal obligation. For example, keeping financial records for tax purposes or responding to lawful requests.


3. Who we share it with

We do not sell your personal information. We share it only where necessary to run our business and deliver our services, and only with providers who are bound by contract to protect it and use it solely on our instructions. The categories of recipient are:

  • IT, hosting and infrastructure providers — the platforms that host and run the website.
  • Security and anti-fraud providers — services that protect the site and our systems against abuse, spam and malicious activity.
  • Analytics and website-measurement providers — services that help us understand how the site is used. These rely on non-essential cookies and operate only with your consent (see section 5).
  • Communication and customer-management providers — the tools we use to correspond with you, manage enquiries and, where relevant, send marketing.
  • Professional advisers — such as accountants, lawyers and insurers, where needed.

We may also disclose information where required by law, or in connection with a sale, merger or reorganisation of our business.

We can provide the identity of the specific providers within each category on request — please contact info@cyberalchemy.co.uk.


4. International transfers

Some of the providers we use are based in, or store data in, countries outside the UK, including the United States. Where we transfer personal information outside the UK, we rely on appropriate safeguards recognised under UK data protection law — such as UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework, or the ICO’s International Data Transfer Agreement (or the Addendum to the EU Standard Contractual Clauses). You can ask us for details of the safeguards that apply to a particular transfer.


5. Cookies and similar technologies

We use cookies and similar technologies to make the site work, to remember your preferences, to keep it secure, and — with your consent — to measure how it is used. Essential cookies are set automatically; non-essential cookies (analytics, measurement, and any marketing cookies) are only set after you consent through our cookie banner, and you can change or withdraw your choices at any time using that banner. Full details of each cookie are in our Cookie Policy.

We use Microsoft Clarity to understand how visitors use our site. Clarity captures usage data through cookies and similar technologies — including behavioural metrics, heatmaps and session replay — which we use to improve the website and help keep it secure. This is non-essential, so it only runs after you consent through our cookie banner, and you can withdraw your consent at any time. Microsoft also uses this data for its own purposes as an independent controller; see the Microsoft Privacy Statement for how Microsoft collects and uses it.


6. How long we keep it

We keep personal information only for as long as we need it:

  • enquiry and contact data: while we are in contact with you and for a reasonable period afterwards.
  • customer and contract records: for the duration of the engagement and as required for tax and accounting purposes (usually six years)
  • marketing data: until you opt out or ask us to stop

When we no longer need it, we delete or anonymise it.


7. How we keep it safe

We use appropriate technical and organisational measures to protect personal information, and we review them regularly. No method of transmission or storage is completely secure, but we take the security of your data seriously.


8. Children

Our services are for businesses and are not directed at children. We do not knowingly collect data about anyone under 18. If you believe we hold data about a child, contact us at info@cyberalchemy.co.uk and we will delete it.


9. Your rights

Under UK GDPR you have the right to:

  • access a copy of your personal information
  • have inaccurate data corrected
  • have your data deleted in certain circumstances
  • restrict or object to our processing
  • data portability
  • withdraw consent at any time, where we rely on it (this does not affect processing already carried out)

Marketing opt-out. You can unsubscribe from marketing at any time using the link in our emails or by contacting info@cyberalchemy.co.uk. We may still send you service-related messages where necessary.

To exercise any of these rights, contact info@cyberalchemy.co.uk. We will respond in line with UK GDPR, normally within one month.

Complaints. If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk, helpline 0303 123 1113. We would appreciate the chance to address your concern first.


10. Do Not Track

Some browsers send “Do Not Track” signals. There is no agreed standard for these yet, so we do not currently respond to them. We will update this notice if that changes.


11. Changes to this notice

We may update this notice from time to time. We will change the “last updated” date above and, for material changes, take reasonable steps to bring them to your attention.


12. How to contact us

If you have questions or comments about this notice, or wish to exercise any of your rights, contact our Data Protection Officer (DPO):

Cyber Alchemy Ltd
Data Protection Officer
Unit G1, Advanced Manufacturing Park Technology Centre, Brunel Way, Catcliffe, Rotherham, S60 5WG, United Kingdom
Email: info@cyberalchemy.co.uk
Phone: 0114 4000377