1Introduction

This policy covers the use of personal information that Cyjax collects when you visit this website and blog.

2 Who we are

Cyjax is a DigitalThreat Intelligence  and Breach Notification (eDiscovery) company.

Digital Threat Intelligence: We collect publicly available information from varying sources, enabling us to provide consultancy and advisory services to clients about the risks they face, and to ensure their critical assets are secured.

We do this through technologies designed to perform both automated and manual sourcing of threat intelligence information, alongside advanced analytic features that enable business entities to conduct analysis and generate outputs in the form of alerts, reports or data feeds.

Breach Notification (eDiscovery) :This service provides secure and accurate processing of data that has been breached to enable entities to fulfil their notification obligations to regulatory authorities and affected individuals.

Cyjax is dedicated to ensuring that all personal data is handled, stored and processed in compliance with statutory and regulatory requirements.

Our registered office is:

Suite 53

Peek House

20 Eastcheap

London

EC3M 1EB

Cyjax is registered with the United Kingdom Information Commissioner’s Office (ICO) under reference ZA053004, as required by UK legislation.

We have appointed a Data Protection Officer who is responsible for overseeing questions in relation to this privacy notice. If you have any queries about it, including any requests to exercise your legal rights, please email our Data Protection Officer at privacy@cyjax.com.

Questions, comments, and requests regarding this privacy policy are welcomed and should be addressed to privacy@cyjax.com.

3  Collection of Personal data

We collect personal data from you for one or more of the following purposes:

  • To fulfil a contract that we have entered into with you or with the entity that you represent. In these circumstances it may be your entity, rather than yourself, that has provided us with your personal data.
  • To provide you with information that you have requested or that we think may be relevant to a subject you have demonstrated an interest.
  • To initiate a contract and/ or commercial transaction with you or the entity you represent for the purchase of one of our products.
  • To ensure the security and safe operation of our websites and underlying business infrastructure and understand visitors usage of our website.
  • To manage any communication between you and us.

As a visitor, you do not need to submit any personal information in order to use our website. Certain areas of the site allow you to provide us with personal information for purposes such as communicating with us, gaining access to view protected and secured content, or requesting communications about specific areas of interest.  When entering your details in the fields requested, you will be asked to select how we may contact you, thereby giving Cyjax consent to provide you with the information you require.

3.1Technical information

To ensure that each visitor to any of our websites can use and navigate the site effectively, we collect the following:

  • Technical information, including the IP (Internet Protocol) address used to connect your device to the Internet.
  • Your login information, browser type and version, time zone setting, browser plug-in types and versions.
  • Operating system and platform.
  • Information about your visit, including the URL (Uniform Resource Locators) clickstream to, through, and from our site.

Our cookies policy, which can be viewed below in section 11 of this document, describes in detail how we use cookies.

In section 8 below, we identify your rights in respect of the personal data that we collect and describe how you can exercise those rights.

4 Lawful basis for processing personal data

When you supply any personal information to us, we have legal obligations towards you in the way we use it. We will always ensure that whenever personal data processed, industry standards and legal requirements are maintained.

The table below describes the various forms of personal data we collect and the lawful basis for processing this data. We have processes in place to make sure that only those people in our organisation who need to access your data can do so. A number of data elements are collected for multiple purposes, as the table below shows.

When we process data on the lawful basis of legitimate interest, we apply the following test to determine whether it is appropriate:

The purpose test – is there a legitimate interest behind the processing?

Necessity test – is the processing necessary for that purpose?

Balancing test – is the legitimate interest overridden by the individual’s interests, rights, or freedoms?

Data collected Reason for collection Information category Purpose for collection Lawful basis for processing Data shared with Retention period
Name, company name, job title and email address To provide access to the Digital Threat Intelligence Platform User credentials To create and provide access to the Digital Threat Intelligence Platform Contractual fulfilment Internally and Business entity you are a member of 1 month following end of contract
Name, and physical business:

·     address,

·     email address,

·     telephone number,

bank account & details / payment information

Transactional/ invoice Information Transaction/ invoice details To process payments for the Services provided to your organisation and to ensure any issues can be dealt with. For accounting, VAT and taxation purposes

 

Contractual performance

 

 

 

Statutory obligation

Internally only

 

 

 

Internally & Professional advisors

7 Years
Technical information

IP addresses, login information (where applicable),

Security Security information To protect our websites and infrastructure from attacks and threats.

 

To understand user behaviour on the website.

 

To enable trouble shooting.

 

To collect statistics of website usage

Legitimate interest Internally 12 months
Names, contact details Communications Personal data -Contact information To communicate with you regarding the service and new products. Contractual obligations Internally and marketing platform provider 6 months following end of contract
             
Name, contact details Marketing and sales Personal data – Contact information To communicate with you regarding our services and provide articles that we believe will be of interest with you Legitimate Interest Internally and marketing platform provider 2 years

4.2 Policy for handling marketing emails

If you have consented to receiving marketing and content emails from us, your email address will be handled as detailed below:

  • Your email address will not be sold, leased or otherwise made available to another company.
  • All emails will be sent with technology that will not make your email address visible to other subscribers
  • When subscribing to our newsletters and content, you agree that your personal data (name and email address) must be stored in our system for email marketing (Mailchimp)
  • All of our emails contain a link where you can unsubscribe from any further newsletters. If you use this system, your personal data will be deleted from  the system for email marketing (Mailchimp) and we will stop processing this data for marketing purposes.
  • Your consent is valid until you unsubscribe, withdraw your consent by contacting Cyjax via email on privacy@cyjax.com.

4.2 Further information

Cyjax has completed a Data Protection Impact Assessment of all data processing activities it undertakes as required by the GDPR, to ensure both that it has legal bases for processing the information, and that this is necessary and proportionate.

Everyone has the right to object to this processing and if you wish to do so, please see the section below titled “Your rights in relation to personal data”.

5 Security

Cyjax is a UK domiciled company with its main offices located in the UK.  The company dedicated to ensuring that all information is protected against unauthorised access, processed appropriately, and held securely in accordance with the General Data Protection Regulation (GDPR) and Data Protection Act 2018.

Our ISMS (information security management system) is certified to ISO/IEC 27001 demonstrating that we have the appropriate Framework in place to ensure that all our information assets and networks are secure.

All communications and data are secured using end-to-end encryption.

Cyjax is Cyber Essentials certified.

6 Storage

We will make every practical effort to store and process your information in the country in which it was submitted. However, some of our third-party suppliers may be based outside the UK and European Economic Area (EEA), so there may be instances when data is stored and transferred outside the UK or EEA. In the eventuality that data is transferred outside these areas, we have the following safeguards in place:

  • The country or relevant territory has an adequate level of protection as recognised by the Commission.
  • Specific contracts approved by the appropriate Commission which give your personal information the same protection it has as if it stayed in the UK or EEA along with effective data controls.
  • The third-party supplier has met our data security standards and is compliant with our information management security framework.
  • All data is encrypted both in transit, end to end and at rest.
  • Data is stored within defined retention periods and is regularly reviewed.

6.1 Third parties

We may disclose information to our carefully selected third-parties, such as chosen systems for marketing, data analytics and web hosting. If the third party processes data on our behalf, we will ensure that the processor is only entitled to process personal data to our specific instructions.

Our chosen third party providers are:

  • Google Analytics – Web Analytics
    • Google Analytics Privacy policy can be found here
  • Mailchimp – Marketing
    • Mailchimp’s privacy policy can be found here
  • Server services:
    • AWS – AWS Privacy Policy can be found
    • Dedicated servers in an N+2 facility that operates a strict physical access policy and maintains logical separation controls ensuring the confidentiality and integrity of Cyjax information.
    • The data centre has a second N+2 facility in a different geographical location that provides failover services to ensure availability of the information is maintained. Some of the geographical locations are outside the EEA.

7 Sharing

Any information you provide to Cyjax, or that Cyjax collects, will only be used within Cyjax. It will not be shared with any third parties for commercial gain, or sold.

The only other instances in which we would share this information is where we are obliged or permitted to by law, or consent has been given.

8 Your rights in relation to personal data

Under data protection laws in the European Union and the UK, you have certain rights in relation to your personal information. You have the right to:

  • Request information about how your personal data is processed, and to request a copy of that personal data
  • Request that any inaccuracies in your personal data are rectified without delay
  • Request that any incomplete personal data is completed, including by means of a supplementary statement
  • Request that your personal data is erased if there is no longer a justification for it to be processed
  • In certain circumstances (for example, where accuracy is contested) request that the processing of your personal data is restricted
  • Object to the processing of your personal data
  • Withdraw your consent at any time by contacting privacy@cyjax.com

A full list of your rights under the General Data Protection Regulation (GDPR) is available on the Information Commissioner’s Office (ICO) website.

We will handle all requests in accordance with applicable law. However, depending on the right you wish to exercise, and the nature of the personal information involved, there may be legal reasons why we cannot grant your request. If this is the case, we will write to you to explain the reasons why.

9 Access to your personal information

To request a copy of the personal information Cyjax holds about you, please email our Data protection Officer at privacy@cyjax.com.

Requests will be acknowledged within three working days, with the final response and disclosure of information (subject to exemptions) within 30 calendar days.

10 Rectifying, restricting, objecting to processing of, or erasure of your personal information

To exercise your right to rectify, restrict, object to processing of, or erase the personal information Cyjax holds about you, please contact us at privacy@cyjax.com.

A ‘cease processing request’ from an individual will be acknowledged immediately with an automatic email response stating that Cyjax intends to comply with the request.

For information on the Privacy and Electronic Communications (EC Directive) Regulations 2003, General Data Protection Regulation (GDPR), Data Protection Act 2018 and the Information Commissioner’s Office, please follow this link: https://ico.org.uk/.

11  Cookie Policy

11.1  How cookies are used by Cyjax

Cyjax uses Google Analytics software to help us improve the usability of our website.

11.2  Website

The type of information gathered relates to the amount of time spent on the website and the pages visited. No personal information is held and cookies cannot be used to identify you.

When you view our website for the first time from a new device, you will see the following message pop up:

“This website uses cookies for analytics and to ensure that you get the best experience on our website. Learn more.”

In order to consent you are required to click the ‘Accept’ button.

Cookies are used to improve services for you. For example by:

  • Enabling a service to recognise your device so you do not have to give the same information several times during one task
  • Measuring how many people are using services to make them easier to use and to ensure there is enough capacity for them to function quickly
  • Analysing data to help us understand how you use our services so we can improve them.

Cookies are stored in the computer’s memory only during your browsing session and are automatically deleted from your computer when the browser is closed.

These cookies usually store a session ID that is not personally identifiable to users, allowing you to move from page to page without having to log in repeatedly.

Session cookies are never written on the hard drive and they do not collect any information from your computer. Session cookies expire at the end of your browser session and are no longer accessible after the session has been inactive for a specified length of time, usually 20 minutes.

11.3  Google Analytics

As mentioned above we only collect Google Analytics cookies. For example:

Cookie Name: _utma

Typical content: randomly generated number

Cookie Expires: 2 years

Cookie Name: _utmb

Typical content: randomly generated number

Cookie Expires: 30 minutes

 

Name: _utmc

Typical content: randomly generated number

Expires: when user exits browser

Cookie Name: _utmz

Typical content: randomly generated number and information about how the page was reached (eg directly or via a link, organic search or paid search)

 

Cookie Expires: 6 months

Cookie Name: __utmmobile

Typical content: randomly generated number

Cookie Expires: 2 years

For further details on the cookies set by Google Analytics, see the link below.

11.4  How to opt out of cookies

Our website works better with cookies enabled. Our cookies do not give us or anyone else access to your personal data. We advise you to keep cookies enabled. However, you can choose to reject them.

You can use your browser to delete and reject cookies. Please see the links below for instructions on how to delete cookies and how to control cookies.

11.5  Disclaimer

As far as is reasonably possible, Cyjax will ensure that information provided on this website is accurate. We cannot accept any liability whatsoever for omission or error. Equally, as we regularly virus-check materials, we cannot accept any responsibility for any disruption or damage that may occur during use of this website.

Links to other websites included on this website do not imply any endorsement, validation or responsibility by Cyjax as to the content or privacy policies of such sites. We cannot guarantee that these links will work all of the time and we have no control over the availability of the linked pages.

12  How to contact us

Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to privacy@cyjax.com.