Privacy Policy
CyberKarl Ltd ("CyberKarl", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal data when you interact with us, in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
CyberKarl is a UK based Cyber and AI Governance consultancy providing advisory, assurance, and consulting services to public and private sector organisations.
Data Controller: CyberKarl Ltd
Registered address: C/O Rotherside Court, Rotherside Road, Eckington, Sheffield, S21 4HL
Email contact: hello@cyberkarl.co.uk
CyberKarl acts primarily as a Data Controller in respect of personal data processed for our own business purposes. In limited circumstances, we may act as a Data Processor when delivering services on behalf of a client under contract.
2. Personal Data We Collect
We may collect and process the following categories of personal data:
a) Business Contacts & Clients
- Name, job title, organisation
- Business contact details (email, telephone)
- Contractual information
- Communications and correspondence
b) Website Visitors
- IP address
- Browser and device information
- Usage data (pages visited, links clicked)
- Cookie preferences
c) Marketing & Communications
- Contact details for newsletters and thought leadership -communications
- Communication preferences
d) Recruitment & Associates
- CVs, employment history, qualifications
- Right to- -work and vetting information (where applicable)
We do not knowingly collect data relating to children.
3. How We Use Personal Data
We process personal data only where there is a lawful basis to do so. These purposes include:
- Providing and managing our consultancy services
- Managing client relationships and contracts
- Responding to enquiries
- Business administration, invoicing, and record-keeping
- Sending newsletters and thought leadership- communications (where permitted)
- Recruiting employees and engaging contractors
- Improving our website and services
4. Lawful Bases for Processing
Under UK GDPR, the lawful bases we rely on include:
- Contract – where processing is necessary to deliver services
- Legitimate interests – for business development and relationship management
- Legal obligation – compliance with laws and regulations
- Consent – for newsletters and certain marketing communications
Where Legitimate Interests are relied upon, we ensure this does not override your rights and freedoms. You can opt out of marketing communications at any time.
5. How We Share Personal Data
We may share personal data with:
- Trusted service providers (e.g. IT, accounting, legal, and cloud service providers)
- Professional advisers
- Public authorities, regulators, or law enforcement where required by law
- Clients, where necessary for service delivery
All third parties are required to handle personal data securely and in accordance with applicable data protection law.
6. International Transfers
Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- UK International Data Transfer Agreement (IDTA)
- UK GDPR adequacy decisions
- Contractual safeguards
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including legal, regulatory, and contractual requirements.
Retention periods are defined in our internal Data Retention & Disposal Policy.
8. Data Security
CyberKarl implements appropriate technical and organisational measures to protect personal data, including:
- Access controls and authentication
- Secure systems and devices
- Encryption where appropriate
- Staff and contractor confidentiality obligations
9. Your Rights
Under UK GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request erasure (where applicable)
- Restrict or object to processing
- Data portability
- Withdraw consent (where processing is based on consent)
Requests can be made by contacting us at hello@cyberkarl.co.uk
10. Cookies
Our website currently uses essential cookies only. These cookies are required for the website to function correctly and cannot be switched off.
Further details are provided in our Cookie Policy.
11. Data Breaches
If a personal data breach occurs that is likely to result in a risk to individuals’ rights and freedoms, we will notify the Information Commissioner’s Office (ICO) and affected individuals in accordance with legal requirements.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legislation or our processing activities.
The latest version will always be available on our website.
13. Contact & Complaints
If you have any questions or concerns about this Privacy Policy or how we handle personal data, please contact us at hello@cyberkarl.co.uk
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk
- Helpline: 0303 123 1113
Need Help Securing Your Business?
Got questions or need cybersecurity help? Reach out to CyberKarl today. We’re here to protect your digital world with trusted, simple, and effective solutions.
Contact