Cybelle.
AboutServicesIntelligenceGet Started
HomeAboutServicesIntelligenceContact

CYBELLE / LEGAL INTELLIGENCE

DOC-REF // CYB-LEG-01

Privacy Policy

VERSION 1.0LAST UPDATED: August 17, 2026STATUS: ACTIVE

Cybelle is committed to the responsible stewardship of your data. This policy governs how we collect, process, and protect personal information across our enterprise technology platform and consultancy services, in accordance with applicable data protection legislation.

01Scope & Data Philosophy02Information Collected03Processing Operations04Data Architecture & Security05Third-Party Ecosystem & Subprocessors06International Transfers & Sovereignty07Data Retention & Life Cycle08Data Subject Rights09Children's Privacy10Amendments & Governance11Contact & Privacy Office

Contents

01Scope & Data Philosophy02Information Collected03Processing Operations04Data Architecture & Security05Third-Party Ecosystem & Subprocessors06International Transfers & Sovereignty07Data Retention & Life Cycle08Data Subject Rights09Children's Privacy10Amendments & Governance11Contact & Privacy Office
DOC-REFCYB-LEG-01
01

Scope & Data Philosophy

This Privacy Policy applies to all services, platforms, and consultancy engagements operated by [Cybelle Legal Entity Name] ("Cybelle", "we", "us", or "our"), a registered enterprise technology and cybersecurity consultancy incorporated under the laws of [Jurisdiction].

Cybelle treats data protection not as a compliance obligation but as an engineering standard. Our privacy architecture is built on the same Zero Trust principles that underpin our cybersecurity practice: least-privilege access, continuous verification, and defensible data minimisation at every layer.

This policy applies to individuals who engage with our website, request consultancy services, participate in our intelligence platform, or interact with our Threat IQ simulation environment. It does not apply to the internal data practices of our enterprise clients, who retain independent data controller status under applicable law.

This policy is governed by the General Data Protection Regulation (GDPR), the UK GDPR, and any applicable data protection legislation in [Jurisdiction]. Where stricter local requirements apply, we adhere to those obligations.

02

Information Collected

Information You Provide Directly

When you engage with Cybelle — whether submitting a contact enquiry, registering for our intelligence platform, or entering a consultancy engagement — we may collect:

  • Full name, professional title, and employing organisation
  • Corporate email address and telephone number
  • Details of your technology environment, security requirements, or business objectives shared during engagement intake
  • Communications sent to us via email, form submissions, or scheduled consultation calls
  • Billing and contractual information processed for commercial engagements

Automated Telemetry & Analytics

When you access our digital properties, our infrastructure may automatically collect:

  • IP address, browser type, operating system, and device identifiers
  • Pages visited, session duration, scroll depth, and navigation paths
  • Referral sources and search query parameters
  • Aggregated behavioural telemetry processed by privacy-respecting analytics tooling

Machine & Security Identifiers

For access to authenticated areas of our platform, including the Threat IQ simulation environment, we process session tokens, authentication credentials (in hashed form), and security event logs. These identifiers are treated as sensitive data and handled under our Zero Trust security architecture.

03

Processing Operations

We process personal data only where we have a lawful basis to do so under applicable data protection law. Our processing activities include:

  • Service Provision — Delivering consultancy engagements, providing access to the Cybelle Intelligence Hub, and operating the Threat IQ simulation platform
  • Communication — Responding to enquiries, issuing project updates, and sending intelligence briefings to subscribed contacts
  • Platform Security — Monitoring for unauthorised access, detecting anomalous behaviour, and maintaining the integrity of our systems under continuous threat assessment
  • Legal & Regulatory Compliance — Fulfilling obligations under data protection, financial, and sector-specific regulatory frameworks
  • Platform Improvement — Analysing aggregated usage patterns to improve service quality, content relevance, and infrastructure performance
  • Contractual Obligations — Executing and administering commercial service agreements with enterprise clients

We do not sell, rent, or commercially exploit personal data. We do not use personal data to train third-party AI models without explicit, separately obtained consent.

04

Data Architecture & Security

Cybelle's data security architecture is designed in accordance with the same enterprise standards we deliver for our clients. Our security controls include:

  • Encryption — All data is encrypted at rest using AES-256 and in transit using TLS 1.3 or higher
  • Zero Trust Access — Access to personal data is governed by identity-based controls, continuous authentication, and least-privilege principles — no implicit trust is granted based on network location
  • Cloud Security — Our infrastructure operates across ISO 27001-certified cloud environments (AWS, Azure, and/or GCP) with enforced security baselines, audit logging, and automated threat detection
  • Access Controls — Personal data is accessible only to personnel with a documented operational need. Access rights are reviewed on a defined schedule and revoked immediately upon role change or departure
  • Incident Response — We maintain a documented breach response procedure aligned to regulatory notification timelines. In the event of a personal data breach affecting your rights, we will notify you and relevant supervisory authorities within the legally required window

No system is absolutely secure. While we invest substantially in security controls, we cannot guarantee that unauthorised parties will never circumvent our measures. We will notify you promptly in the event that your personal data is compromised.

05

Third-Party Ecosystem & Subprocessors

We engage a limited number of third-party subprocessors to deliver our services. All subprocessors are bound by data processing agreements requiring equivalent data protection standards.

CategoryPurposeTransfer Mechanism
Cloud InfrastructurePlatform hosting, storage, and compute servicesStandard Contractual Clauses / Adequacy decision
AnalyticsAggregated behavioural telemetry for platform improvementPrivacy-preserving processing; no individual profiling
CommunicationEmail delivery for service communications and intelligence briefingsStandard Contractual Clauses
AuthenticationSecure access management for platform-authenticated usersData processed within jurisdiction or under SCCs

We do not permit subprocessors to use personal data for their own commercial purposes. A current list of active subprocessors is available upon written request to legal@cybelle.io.

06

International Transfers & Sovereignty

Cybelle operates with a Pan-African and global delivery capability. Where personal data is transferred outside the European Economic Area (EEA), the United Kingdom, or other jurisdictions with adequacy decisions, we apply appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions recognising equivalent data protection standards
  • Binding Corporate Rules where applicable within our supplier ecosystem

For clients with data sovereignty requirements — particularly those in regulated sectors or operating across African jurisdictions — we offer data residency configurations that constrain processing to specified geographic boundaries. Speak to your account contact to configure jurisdiction-specific data handling.

07

Data Retention & Life Cycle

We retain personal data only for as long as necessary to fulfil the purposes described in this policy or to satisfy legal obligations. Our default retention schedules are:

Data CategoryRetention PeriodBasis
Client engagement records7 years from contract endLegal and contractual obligation
Contact and enquiry data2 years from last interactionLegitimate interest
Platform analytics14 months (aggregated thereafter)Legitimate interest
Security event logs12 monthsLegal and security obligation
Authentication credentialsDuration of account plus 90 daysSecurity and account management

At the end of the applicable retention period, personal data is securely deleted or irreversibly anonymised in accordance with our data destruction procedures.

08

Data Subject Rights

Under applicable data protection law, you have the following rights in relation to your personal data:

  • Right of Access — Request a copy of the personal data we hold about you, together with information on how it is processed. We will respond within 30 days of a valid request.
  • Right to Rectification — Request correction of inaccurate or incomplete personal data.
  • Right to Erasure — Request deletion of your personal data where we no longer have a legitimate basis to retain it. Note that certain legal obligations may require us to retain specific records.
  • Right to Portability — Receive your personal data in a structured, machine-readable format and transfer it to another controller, where technically feasible.
  • Right to Restriction — Request that we restrict processing of your data in specified circumstances, such as while a dispute regarding accuracy is resolved.
  • Right to Object — Object to processing based on legitimate interests, including direct marketing. Objections to marketing will be honoured immediately.
  • Right to Withdraw Consent — Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, submit a written request to legal@cybelle.io. We may be required to verify your identity before processing your request. You also have the right to lodge a complaint with your relevant supervisory authority.

09

Children's Privacy

Cybelle is a business-to-business enterprise technology and cybersecurity consultancy. Our services are intended exclusively for organisations and professional individuals who are 18 years of age or older.

We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us immediately at legal@cybelle.io and we will act to delete the information without undue delay.

10

Amendments & Governance

We may update this Privacy Policy periodically to reflect changes in our processing activities, applicable law, or regulatory guidance. Material changes — those affecting your rights or the basis on which we process your data — will be communicated to known contacts with a minimum of 30 days' notice via email or a prominent notice on our website.

Non-material changes (such as editorial corrections or the addition of subprocessors under existing categories) may be made without prior notice. The version number and "Last Updated" date at the top of this document will always reflect the current version.

Continued use of our services after the effective date of an updated policy constitutes acceptance of the revised terms. If you do not agree, please discontinue use and contact us to discuss your options.

Historical versions of this policy are available upon written request.

11

Contact & Privacy Office

For all data protection enquiries, rights requests, or concerns regarding our privacy practices, please contact our Privacy Office:

[Cybelle Legal Entity Name]
Privacy Office / Data Protection
Email: legal@cybelle.io
Registered Address: [Registered Address], [Jurisdiction]
Response Time: We aim to acknowledge all enquiries within 5 business days and resolve them within 30 days.

If you are located in the European Economic Area, you have the right to contact your local data protection supervisory authority. A list of national authorities is maintained by the European Data Protection Board at edpb.europa.eu.

Cybelle.

Secure technology. Thoughtful solutions. Creative by nature. Built to evolve with what’s next.

Explore

  • Home
  • About
  • Services
  • Intelligence
  • Contact

© 2026 Cybelle. All rights reserved.

Privacy PolicyTerms of ServiceCookie Policy