Cybrooke
ServicesTrainingInsightsAbout
ServicesTrainingInsightsAboutBook a meeting ↗
Book a meeting ↗

Legal information

Privacy notice

This notice explains how Cybrooke Ltd collects and uses personal information through this website, our content management system and the online services linked from it.

Last updated: 28 August 2026

1. Who we are

Cybrooke Ltd (“Cybrooke”, “we”, “us” or “our”) is the controller of the personal information described in this notice. For privacy enquiries or to exercise your rights, email info@cybrooke.com.

2. Information we collect

Depending on how you interact with us, we may collect:

  • your name, work email address, organisation, telephone number and anything you include in an enquiry or meeting request;
  • appointment information you provide through Microsoft Bookings;
  • technical and security information such as IP address, browser or device information, request timestamps, pages or endpoints requested, error details and security events;
  • for authorised content managers, Microsoft account identity information, including name and email address, sign-in and session information, and an audit history of administrative actions;
  • content, event details, files and image metadata uploaded by authorised content managers; and
  • records relating to proposals, contracts, service delivery, invoicing and our communications with you.

Please do not send special-category personal data, criminal-offence data or confidential security credentials through general website or booking fields unless we have specifically asked for them and agreed an appropriate secure method.

3. How we use information and our lawful bases

PurposeLawful basis
Responding to enquiries, arranging meetings and taking steps requested before entering a contractContract or steps at your request before contract; legitimate interests in operating and developing our business
Providing contracted services and managing client relationshipsContract; legitimate interests; legal obligation where applicable
Operating, securing, troubleshooting and improving the website, CMS and supporting systemsLegitimate interests in providing secure, reliable services and protecting our systems, users and business
Maintaining CMS access controls and administrative audit recordsLegitimate interests in accountability, fraud prevention and information security
Meeting tax, accounting, regulatory or legal requirements and handling legal claimsLegal obligation; legitimate interests in establishing, exercising or defending legal claims
Loading optional embedded Microsoft Bookings contentYour consent, requested before the embedded calendar is loaded

Where we rely on legitimate interests, we consider the necessity of the processing and its effect on your rights. You may object to processing based on legitimate interests as explained below.

4. Microsoft Bookings and linked services

Our booking page may link to or, only after you choose to load it, embed Microsoft Bookings. Information you enter into Microsoft Bookings is processed using Microsoft 365 services and is also subject to Microsoft’s applicable privacy information. Other external websites reached through links operate under their own privacy notices. We do not control their content or privacy practices.

5. Cookies and device storage

The public site does not intentionally use advertising cookies or browser-based analytics cookies. The restricted CMS uses a strictly necessary, secure authentication cookie to keep an authorised editor signed in and protect the service. It is configured to expire after 30 minutes. Optional Microsoft Bookings content is not loaded until you choose to load it; Microsoft may then store or access information on your device under its own practices.

If we introduce non-essential cookies or similar technologies, we will provide appropriate information and obtain consent before using them.

6. Who receives information

We disclose personal information only where necessary and proportionate for the purposes described in this notice. Recipients may include:

  • trusted technology providers that help us host, operate, secure, authenticate, monitor and support our website and business systems;
  • communications and scheduling providers when you contact us or ask to arrange a meeting;
  • professional advisers, auditors and insurers where they need the information to provide their services;
  • courts, regulators, law-enforcement bodies or other authorities where disclosure is required or permitted by law; and
  • a prospective buyer, investor or successor if our business or assets are reorganised or transferred, subject to appropriate confidentiality and data-protection safeguards.

Service providers may use personal information only for the agreed services and under appropriate contractual obligations. We do not sell personal information.

7. International transfers

Some suppliers may process information outside the United Kingdom. Where UK data-protection law requires a transfer safeguard, we use an applicable adequacy regulation or contractual safeguards such as the UK International Data Transfer Agreement or the UK Addendum to standard contractual clauses, together with supplementary measures where appropriate. Contact us if you would like more information about safeguards relevant to your information.

8. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. In particular:

  • CMS authentication sessions expire after 30 minutes;
  • application diagnostic logs are generally retained for 30 days;
  • general enquiries that do not lead to a client relationship are normally kept for no longer than 24 months after the last meaningful contact;
  • contract, transaction and related correspondence may normally be kept for up to six years after the relationship ends, or longer where law or an active claim requires it;
  • published content and associated media are kept until they are removed or replaced; and
  • CMS access and audit records are kept for as long as needed to protect the service, investigate changes and demonstrate accountability, with periodic review.

Backups and deletion-protection copies may remain for a limited period before automatic expiry.

9. Security

We use technical and organisational measures intended to protect personal information, including encrypted connections, access controls, short-lived CMS sessions, restricted editor allowlists, validation and sanitisation, audit logging, managed cloud identities and protected deployment processes. No internet service can be guaranteed completely secure, so please use an agreed secure channel for particularly sensitive information.

10. Your rights

Depending on the circumstances and lawful basis, you may have the right to ask us for access to your personal information, correction, deletion, restriction, portability, or to object to processing. Where processing relies on consent, you may withdraw that consent at any time without affecting earlier lawful processing.

Your right to object: where we process your information on the basis of legitimate interests, you may object on grounds relating to your situation. You have an absolute right to object to direct marketing.

To exercise a right, email info@cybrooke.com. We may need to verify your identity. Rights can be subject to legal conditions and exemptions.

11. Complaints

Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113.

12. Children

This website and our services are directed to organisations and professionals, not children. We do not knowingly use this site to collect personal information from children.

13. Changes to this notice

We may update this notice when our services, suppliers or legal obligations change. We will publish the updated version here and change the “last updated” date. Material changes will be brought to affected people’s attention where appropriate.

Cybrooke

Practical cyber resilience for organisations that refuse to stand still.

ExploreServicesTraining calendarInsights
ConnectBook a meetinginfo@cybrooke.comPrivacy notice
© 2026 Cybrooke Ltd. All rights reserved.Privacy · Cybersecurity · IT services · Capacity building