Cyberbridge Services Ltd Privacy Policy
This Policy applies between you, the User of this website, and Cyberbridge Services Ltd, the owner and provider of this website. It outlines how we collect, use, and protect your data when you use our website and any services or systems contained therein.
1. Important Information
1.1 Our website is not intended for children, and we do not knowingly collect data relating to children.
1.2 This Privacy Policy supplements other policies (including our Terms of Use) and does not override them.
1.3 Cyberbridge Services Ltd is the controller responsible for your personal data ("we", "us", or "our").
1.4 See Part 5 of Schedule 1 for a glossary of terms, examples of data collected, purposes, lawful bases, and your rights.
1.5 We have appointed a Data Privacy Manager (DPM). For questions or rights requests, contact:
- Email: [email protected]
- Post: Cyberbridge Services Ltd., 20 Wenlock Road, London, N1 7GU
1.6 You can also contact the ICO at www.ico.org.uk. However, we’d appreciate a chance to address your concerns first.
1.7 Please ensure that your data is accurate and current by informing us of any changes.
1.8 Our website may include third-party links or plug-ins. We are not responsible for their privacy policies — you should review those separately.
2. The Data We Collect About You
2.1 See Part 1 of Schedule 1 for the types of personal data we may collect, use, store, and transfer.
2.2 We also collect and use aggregated data, which does not identify you unless combined with personal data.
2.3 We do not collect special categories of personal data.
2.4 If required by law or contract to collect data and you do not provide it, we may not be able to offer you services.
3. How We Collect Personal Data
We collect data in the following ways:
| Method |
Details |
| Direct Interactions |
Completing forms, requesting services, subscribing, or contacting us |
| Automated Technologies |
Cookies, server logs, and similar technologies |
| Public Sources |
e.g., Companies House, credit reference agencies |
| Third Parties |
e.g., analytics providers (Google), payment processors, IT support |
4. How We Use Your Personal Data
4.1 We only use your data when permitted by law, typically to:
- Perform a contract
- Comply with legal obligations
- Pursue legitimate interests (yours or ours)
4.2 See Part 2 of Schedule 1 for specific uses and legal bases.
4.3 We generally rely on consent only for email/SMS marketing, which can be withdrawn at any time.
4.4 Marketing:
- You’ll receive marketing if you’ve consented, requested information, or purchased from us (and not opted out).
- We will get your opt-in consent before sharing your data with third parties for marketing.
- You can unsubscribe at any time via email link or by contacting our DPM.
4.5 We may use your data for purposes other than those originally stated if compatible with the original purpose.
4.6 If we need to use your data for a different purpose, we’ll notify you and explain the legal basis.
4.7 We may process your data without your consent if required by law.
5. Disclosure of Your Personal Data
5.1 We may share your data with third parties (see Part 4 of Schedule 1), but:
- They must respect data security and privacy laws
- They may not use your data for their own purposes
- They may only act on our instructions
6. International Transfers
6.1 We do not transfer your personal data outside the EEA.
7. Data Security
7.1 We apply appropriate security to protect your data from unauthorized access, loss, or misuse. Only authorized personnel may access your data.
7.2 We have procedures in place for suspected breaches and will notify you and relevant regulators if legally required.
8. Data Retention
8.1 We keep your personal data only as long as necessary, including for legal, accounting, and reporting purposes.
8.2 We retain basic customer data (contact, identity, financial, transaction) for six years after the customer relationship ends (for tax purposes).
8.3 We may anonymize data for research/statistics and use it indefinitely.
9. Your Legal Rights
9.1 You have rights under data protection laws (see Part 3 of Schedule 1) and may:
- Access your data
- Correct inaccurate data
- Request deletion (under certain conditions)
- Object to processing (esp. for marketing)
- Request restriction of processing
- Request data transfer to you or a third party
- Withdraw consent at any time
9.2 Generally, we won’t charge a fee unless your request is repetitive, excessive, or unfounded.
9.3 We may need to confirm your identity before processing your request.
9.4 We aim to respond within one month, but will notify you if more time is needed.
Schedule 1: Personal Data
Part 1: Types of personal data
| Contact data |
Billing address, delivery address, email address and telephone number |
| Financial data |
Bank account and payment card details |
| Identity data |
First name, last name, username or similar identifier, title and gender identity |
| Marketing and Communication data |
Your preferences in receiving marketing from us and our third parties and your communication preferences |
| Profile data |
Your username and password, purchases or orders made by you, preferences, feedback and survey responses |
| Technical data |
Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website |
| Transaction data |
Details about payments to and from you and other details of products and services you have purchased from us |
Part 2: Lawful basis for processing and processing activities
The lawful basis upon which we may rely on to process your personal data are:
| Consent |
You have given your express consent for us to process your personal data for a specific purpose |
| Contract |
The processing is necessary for us to perform our contractual obligations with you under our contract, or because you have asked us to take specific steps before entering into a contract with you |
| Legal Obligation |
The processing is necessary for us to comply with legal or regulatory obligation |
| Legitimate Interests |
The processing is necessary for our or a third party’s legitimate interest (e.g. in order for us to provide the best service to you via our website). Before we process your personal data on this basis, we make sure we consider and balance any potential impact on you, and we will not use your personal data on this basis where such impact outweighs our interest |
Set out below are specific details of the processing activities we undertake with your personal data and the lawful basis for doing this.
| Purpose |
Data Used |
Legal Basis |
| Register as customer |
Identity, Contact |
Contract |
| Process/deliver order |
Identity, Contact, Financial, Transaction, Marketing |
Contract; Legitimate Interest (debt recovery) |
| Manage relationship |
Identity, Contact, Profile, Marketing |
Contract; Legal Obligation; Legitimate Interests |
| Administer website/business |
Identity, Contact, Technical |
Legal Obligation; Legitimate Interests |
| Ads/content relevance |
Identity, Contact, Profile, Usage, Marketing, Technical |
Legitimate Interests |
| Analytics |
Technical, Usage |
Legitimate Interests |
| Recommendations |
Identity, Contact, Technical, Usage, Profile |
Legitimate Interests |
Part 3: Your legal rights
You have the following legal rights in relation to your personal data:
| Access your data |
You can ask for access to and a copy of your personal data and can check we are lawfully processing it.
|
| Correction |
You can ask us to correct any incomplete or inaccurate personal data we hold about you.
|
| Erasure |
You can ask us to delete or remove your personal data where:
(a) there is no good reason for us continuing to process it;
(b) you have successfully exercised your right to object (see below);
(c) we may have processed your information unlawfully; or
(d) we are required to erase your personal data to comply with local law.
(e) We may not always be able to comply with your request for specific legal reasons, which will be notified to you at the time of your request.
|
| Object |
You can object to the processing of your personal data where:
(a) we are relying on our legitimate interest (or those of a third party) and you feel it impacts your fundamental rights and freedoms;
(b) we are processing your personal data for direct marketing purposes;
(c) in some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms. In such circumstances, we can continue to process your personal data for those purposes.
|
| Restrict processing |
You can ask us to suspend or restrict the processing of your personal data if:
(a) you want us to establish the accuracy of your personal data;
(b) our use of your personal data is unlawful, but you do not want us to erase it;
(c) you need us to hold your personal data (where we no longer require it) as you need it to establish, exercise or defend legal claims; or
(d) you have objected to our use of your personal data, but we need to verify whether we have overriding legitimate grounds to use it.
|
| Request a transfer |
You can request a transfer of your personal data which is held in an automated manner and which you provided your consent for us to process, or which we need to process to perform our contract with you, to you or a third party. We will provide your personal data in a structured, commonly used, machine-readable format.
|
| Withdraw your consent |
You can withdraw your consent at any time (where we are relying on consent to process your personal data). This does not affect the lawfulness of any processing carried out before you withdraw your consent.
|
Part 4: Third Parties
| Service Providers |
Acting as processors or controllers based in the EEA but also around the world who provide web hosting, professional services and IT and system administration services.
|
| Professional Advisors |
Acting as processors or joint controllers including lawyers, bankers, auditors and insurers based in the United Kingdom who provide consultancy, banking, legal, insurance and accounting services.
|
| HM Revenue & Customs, Regulators and other Authorities |
Acting as processors or joint controllers based in the EEA who require reporting of processing activities in certain circumstances.
|
| Third Parties |
Third parties whom we may choose to sell, transfer, or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Privacy Policy.
|
Part 5: Glossary
- Aggregated Data: Statistical data not identifying individuals
- Controller: Entity deciding how and why data is processed
- Data Subject: You — the individual identified by the data
- Personal Data: Data identifying you directly or indirectly
- Processor: Entity processing data on the controller's behalf
- Special Categories: Sensitive data like health, ethnicity, etc.
- ICO: UK’s Information Commissioner’s Office
10. Changes to This Policy
10.1 We may update this Privacy Policy periodically. Any changes will be posted on this website. Continued use of our services indicates your acceptance of these changes.