Privacy Policy
Your privacy matters to Jellybean Cyber. This policy explains how we collect, use, and protect your information in accordance with UK law and the UK GDPR.
Information We Collect
- Contact Information: Name, email address, company name, phone number, and enquiry details provided via our contact forms.
- Business Information: Company size, industry sector, current security measures, and specific cybersecurity requirements discussed during consultations.
- Technical Data: IP addresses, browser types, and access logs collected by our hosting provider for security monitoring and system administration.
- Service Data: Information gathered during security assessments, penetration tests, and other professional services (handled under separate confidentiality agreements).
- We do not use cookies, tracking pixels, or third-party analytics tools on this website.
How We Use Your Information
- Service Delivery: To respond to enquiries, provide cybersecurity consultations, deliver contracted services, and maintain ongoing client relationships.
- Business Operations: To improve our website, services, and security offerings based on client feedback and industry developments.
- Legal Compliance: To comply with legal obligations, regulatory requirements, and professional standards in the cybersecurity industry.
- Security & Fraud Prevention: To protect our business and clients from fraud, abuse, and security threats.
- Emergency Response: To provide urgent incident response services when contacted for security breaches or cyber attacks.
Data Collection, Storage & Retention
- Form Processing: Contact form submissions are securely processed and stored by Formspree, a GDPR-compliant service provider.
- Data Storage: Client data is stored on secure, UK-based servers with appropriate encryption and access controls.
- Retention Periods: Contact enquiries are retained for 2 years, active client data for the duration of engagement plus 7 years for legal compliance.
- Marketing: We do not use your data for marketing without explicit consent and provide easy opt-out mechanisms.
- Third Parties: We never sell your data and only share with trusted service providers under strict confidentiality agreements.
- International Transfers: Data is primarily processed within the UK/EEA with appropriate safeguards for any international transfers.
Information Security Measures
- Technical Safeguards: We implement industry-leading security measures including AES-256 encryption, multi-factor authentication, and regular security audits.
- Access Controls: Strict role-based access controls ensure only authorised personnel can access client data on a need-to-know basis.
- Network Security: Our systems are protected by enterprise-grade firewalls, intrusion detection systems, and continuous monitoring.
- Staff Training: All employees undergo regular security awareness training and sign comprehensive confidentiality agreements.
- Incident Response: We maintain a formal incident response plan and will notify clients of any data breaches within 72 hours as required by law.
- Third-Party Security: All service providers (including Formspree) are vetted for GDPR compliance and security standards.
Your Data Protection Rights
- Access Rights: You can request a copy of all personal data we hold about you, provided free of charge within one month.
- Rectification: You can request correction of inaccurate or incomplete personal data.
- Erasure: You can request deletion of your personal data, subject to legal retention requirements and legitimate business interests.
- Portability: You can request your data in a structured, machine-readable format for transfer to another provider.
- Objection & Restriction: You may object to or restrict certain types of data processing.
- Exercising Rights: Contact our Data Protection Officer at dpo@jellybeancyber.co.uk or info@jellybeancyber.co.uk.
- Complaints: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Data Sharing & Disclosure
- Service Providers: We may share data with trusted third-party service providers who assist in delivering our services, all bound by strict confidentiality agreements.
- Legal Requirements: We may disclose information when required by law, court order, or to protect our legal rights and those of our clients.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, client data may be transferred subject to equivalent privacy protections.
- Emergency Situations: We may share information to prevent serious harm to individuals or to assist in cybersecurity incident response.
- No Marketing Sales: We never sell, rent, or trade personal data for marketing purposes.
Policy Updates
This privacy policy may be updated to reflect changes in our practices, services, or legal requirements. We will notify clients of significant changes via email where appropriate. Please check this page regularly for the latest version. Last updated: January 2025.