1. Who we are
Secure Cyber Future Ltd (“we”, “us”, “our”) provides cyber security services including penetration testing, vulnerability assessment, ransomware recovery and incident response. We operate through entities in the United Kingdom, the United States and India.
This policy explains what personal data we collect through our website and in the course of providing our services, and what we do with it.
2. Information we collect
Information you give us
- Name, work email address, telephone number and country code
- Company name, website or application URL
- Details of your environment, the service you need and its urgency
- Anything else you choose to include in a message, quote request or job application
Information collected automatically
- IP address, browser type, device type and operating system
- Pages visited, referring page and time spent on the site
Recruitment information
If you apply for a role or internship, we process your CV, cover letter, salary expectations and anything else you send us in support of your application.
3. How we use your information
- To respond to enquiries, scope engagements and provide quotes
- To deliver the services you have engaged us for
- To respond to emergency incidents where you have asked for our help
- To send service-related communications about work in progress
- To assess job and internship applications
- To meet legal, regulatory and accounting obligations
- To maintain and improve the security and performance of our website
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.
4. Lawful basis for processing
Where the UK GDPR and EU GDPR apply, we rely on the following bases:
- Contract — to provide the services you have engaged us for
- Legitimate interests — to respond to enquiries, run and secure our business, and assess applications
- Consent — where you have given it, for example for optional communications; you may withdraw it at any time
- Legal obligation — where we must retain records for tax, accounting or regulatory reasons
- Consent — for advertising and measurement cookies, where required by the law that applies to you
5. Client engagement data
Security testing generates sensitive material: vulnerability findings, system configurations, log extracts and, occasionally, incidental personal data belonging to your users. We treat this material as strictly confidential.
- Testing is carried out only within the written scope and rules of engagement agreed with you
- We do not exfiltrate production data; where proof of access is required, we capture the minimum evidence necessary
- Engagement data is stored encrypted and accessible only to the personnel assigned to your engagement
- On request, or at the end of the agreed retention period, engagement data is securely destroyed
- Where we process personal data on your behalf, we act as a processor and you remain the controller
6. Sharing your information
We share personal data only where necessary, and only with:
- Our own personnel and contractors bound by confidentiality obligations
- Service providers who support our operations, such as hosting, email and accounting providers, under written agreements
- Professional advisers such as lawyers, auditors and insurers
- Law enforcement or regulators where we are legally required to do so, or where you have asked us to assist with reporting an incident
7. International transfers
Because we operate across the UK, the US and India, your information may be transferred outside the country in which it was collected. Where personal data is transferred out of the UK or EEA, we use appropriate safeguards such as Standard Contractual Clauses. Clients with data residency requirements can request that engagement data is held in a specific region — tell us before the engagement begins.
8. How long we keep data
- Enquiries that do not become engagements — up to 24 months
- Engagement reports and findings — typically 12 months after delivery, or another period agreed with you in writing
- Contracts and financial records — as required by law, generally 6 years
- Unsuccessful job applications — 12 months, unless you ask us to delete them sooner
9. How we protect your data
- Encryption in transit and at rest for engagement material
- Access restricted to personnel who need it for the work in question
- Multi-factor authentication on internal systems
- Confidentiality agreements with all staff and contractors
- Regular review of our own security posture — we test ourselves as well as our clients
No system can be guaranteed completely secure, but we take these obligations seriously; it is the business we are in.
10. Your rights
Subject to the law that applies to you, you may have the right to:
- Access the personal data we hold about you
- Have inaccurate data corrected
- Request erasure of your data
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent where processing is based on it
To exercise any of these, email contact@securecyberfuture.com. We respond within one month.
11. Cookies, analytics and advertising
This website uses Google Ads conversion tracking (Google tag, ID AW-10994188633) supplied by Google LLC. It allows us to see how many people who click one of our adverts go on to contact us, so we can judge whether our advertising is working.
What this involves
- Cookies and similar identifiers may be set in your browser by Google
- Data collected can include your IP address, browser and device type, the pages you viewed, and whether you completed a form
- This data is processed by Google and may be transferred outside the UK and EEA under appropriate safeguards
- We do not use it to identify you personally, and we do not combine it with the details you submit through our forms
Your choices
- You can block or delete cookies in your browser settings at any time
- You can opt out of personalised Google advertising at adssettings.google.com
- Browser extensions such as Google’s own opt-out add-on will also prevent this tracking
- Blocking these cookies does not affect your ability to use this site or contact us
Google’s own privacy policy explains how it handles this data: policies.google.com/privacy.
12. Children
Our services are for businesses. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised. Material changes affecting how we use your data will be communicated to active clients directly.
14. Contact and complaints
Questions or concerns: contact@securecyberfuture.com.
If you are in the UK and are unhappy with how we have handled your data, you may complain to the Information Commissioner's Office (ICO). If you are in the EU, you may complain to your local supervisory authority. We would appreciate the chance to resolve it with you first.