Privacy Policy

This Privacy Policy describes how we collect, use, store and protect personal data in connection with our website and our consulting and R&D services. It also describes the data governance standards we apply when processing client data on behalf of our clients, and our contractual commitments to confidentiality.

Your Data, Our Responsibility

Cyanapse Limited takes the privacy of individuals and the confidentiality of client data with the utmost seriousness. This Privacy Policy sets out how Cyanapse Limited collects, uses and protects personal data in connection with our website and our consulting and R&D services. It also describes the data governance standards we apply when processing client data on behalf of our clients, including our technical and organisational security measures, our strict prohibition on processing client data through public AI systems or third-party platforms without prior written consent, and our commitment to returning or securely deleting all client data upon conclusion of an engagement. We treat data protection not as a compliance obligation but as a reflection of the same rigour and care we bring to every aspect of our work.

This Policy is governed by and construed in accordance with the laws of England and Wales, and complies with all applicable UK data protection legislation, including the UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 as amended.

Who We Are

Cyanapse Limited is a company incorporated in England and Wales (company number 10018003), whose registered office is at 66 Paul Street, London, EC2A 4NA. Our website address is www.cyanapse.com. This Privacy Policy describes how we collect, use, store and protect personal data in connection with our website and our consulting and R&D services. It complies with all applicable UK data protection legislation, including the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 as amended.

Data We Collect on This Website

When you visit this website, we may collect the following: your IP address and browser information for analytics and security purposes; information you provide via our contact form, including your name, email address and the content of your message; and technical data about your visit such as pages viewed, time spent and referring URL. We do not use third-party advertising trackers, and we do not sell or share your data with third parties for marketing purposes.

Comments

When visitors leave comments on this site, we collect the data shown in the comments form, along with the visitor's IP address and browser user agent string to assist with spam detection. An anonymised string derived from your email address may be provided to the Gravatar service to determine whether you are using it; Gravatar's privacy policy is available at https://automattic.com/privacy/. Upon approval, your profile picture may be visible to the public alongside your comment.

Media

If you upload images to this website, you should avoid including embedded location data (EXIF GPS) in those files. Visitors to the website may be able to download and extract any location data embedded in images you upload.

Cookies

This website uses cookies to make it function properly, to remember your preferences, and — with your consent — to help us understand how the site is used.

When you first visit, a cookie consent banner lets you accept, decline, or customise cookies by category. You can change your choices at any time via the Manage Consent link in the site footer. A small number of cookies are used purely to remember your consent choice; these are strictly necessary and are not covered by the categories below.

Functional cookies: These are used on the basis of necessity/legitimate interest and don't require separate consent. They enable core features of the site, including logging in and staying logged in, screen display preferences, remembering your details if you choose to when leaving a comment, editing or publishing content if you have an author account, embedded Google Maps content, the Google Fonts used for the site's typefaces, and Google reCAPTCHA, used to protect forms from spam and abuse. Some of these cookies (such as those used to check browser compatibility on login, or to temporarily track which post you're editing) contain no personal data.

Analytics cookies: With your consent, we use Google Analytics and our self-hosted Matomo installation to understand how visitors use the site (e.g. pages visited, time spent, referring sources), so we can improve it. Matomo is hosted on our own infrastructure within the EEA, and data collected through it is not shared with third parties.

Marketing cookies: We do not currently use any marketing or advertising cookies. If this changes, this policy will be updated and your consent requested before any such cookies are set.

International data transfers: Google Analytics, Google Maps, Google Fonts and Google reCAPTCHA may transfer data outside the European Economic Area, including to the United States. Where this occurs, it is done on the basis of appropriate safeguards, such as the European Commission's Standard Contractual Clauses.

Managing your preferences: You can review or change your consent for any non-essential cookie category at any time via the Manage Consent link in the site footer.

Embedded Content from Other Websites

Pages on this site may include embedded content such as videos, images or articles from third-party platforms. Embedded content behaves in precisely the same way as if you had visited those third-party websites directly. Those websites may collect data about you, use cookies, embed additional tracking, and monitor your interaction with their content — including if you have an account with them and are logged in.

How We Use Website Data

We use contact form submissions solely to respond to your enquiries and, where you have given explicit consent, to provide information about our services. We use website analytics data in aggregate to improve the usability and content of this website. We do not use your data for automated decision-making.

Client Data — Our Confidentiality Commitments

When engaged to process data on behalf of a client, we operate as a Data Processor under UK GDPR. Our commitments include: processing personal data only on the documented written instructions of the Data Controller; implementing encryption of personal data in transit and at rest; enforcing role-based access controls and least-privilege access; applying multi-factor authentication for administrative access where technically possible; and hosting data within the UK or EEA unless otherwise approved in writing. We maintain comprehensive access logs, notify Data Controllers of personal data breaches within 24 hours, and return or securely delete all client data upon termination of the engagement. We do not upload, transmit or process client data using public AI systems, LLMs or third-party analytics platforms without the prior written consent of the Data Controller.

Who We Share Your Data With

We do not sell, trade or transfer your personal data to third parties for commercial purposes. If you request a password reset, your IP address will be included in the reset email. Visitor comments may be checked through an automated spam detection service. Where we engage sub-processors in connection with client data engagements, we do so only with the prior written consent of the relevant Data Controller, under written agreements imposing equivalent data protection obligations.

How Long We Retain Your Data

Contact form submissions are retained for up to 24 months. If you leave a comment, the comment and its associated metadata are retained indefinitely to allow recognition and automatic approval of any follow-up comments. For registered users, personal information is stored in the user profile for as long as the account remains active; all users may view, edit or delete their personal information at any time, with the exception of their username. Website administrators may also view and edit this information. Client project data is retained in accordance with the relevant client agreement and deleted or returned upon termination of that agreement.

Your Rights

Under UK GDPR, you have the right to access the personal data we hold about you, to request its correction or deletion, to object to its processing, and to request its portability. If you have an account on this site or have left comments, you may request an exported file of the personal data we hold, or request that we erase it — except where we are obliged to retain it for administrative, legal or security purposes. To exercise any of these rights, please contact us at contact@cyanapse.com. We will respond within 30 days.

Where Your Data Is Sent

Visitor comments may be checked through an automated spam detection service. Data submitted via our contact form is processed and stored on servers located within the UK or EEA. We do not transfer personal data outside the EEA without the appropriate safeguards required by UK GDPR.

Contact for Data Protection Enquiries

For any enquiries regarding this Privacy Policy or our data protection practices, please contact us at privacy@cyanapse.com or write to us at Cyanapse Limited, 66 Paul Street, London, EC2A 4NA, United Kingdom.