Legal
Privacy notice
This notice explains what personal data we collect when you use this website or contact us, why we hold it, how long we keep it, and what you can ask us to do about it.
Who we are
Axolotl Cyber Security Limited is the data controller for personal data processed through this website. We are registered in England and Wales under company number 16701259.
- Registered office
- Suite A James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE
- Data protection contact
- privacy@axolotlcs.com
We are not required to appoint a statutory Data Protection Officer. Enquiries about this notice are handled by the contact above.
What personal data we collect
We collect only what we need in order to respond to you and to keep the website working. In practice this is limited to the following.
Information you give us
- Your name, and the organisation you represent.
- Your email address and, if you provide one, your telephone number.
- The content of your enquiry, and anything else you choose to include in it.
- Any correspondence that follows, including emails and meeting notes.
Information collected automatically
- Standard server or platform logs generated by our hosting provider, which may include your IP address, the pages requested and the time of the request.
- Your cookie preferences, if you set any. These are stored in your browser and are not transmitted to us.
We do not use tracking pixels, advertising networks, social media tracking scripts or third-party analytics on this website. We do not buy personal data from third parties and we do not build marketing profiles.
How we use personal data
- To reply to enquiries and to provide the information you have asked for.
- To provide services under a contract, and to administer that contract.
- To keep records required for accounting, tax and audit purposes.
- To keep the website secure, available and free from abuse.
- To meet our legal and regulatory obligations.
We do not use automated decision-making or profiling that produces legal effects, or similarly significant effects, for any individual.
Our lawful bases
UK data protection law requires us to identify a lawful basis for each purpose. Ours are as follows.
- Responding to enquiries
- Legitimate interests — it is in the interests of both parties that we reply to a message you have chosen to send us.
- Delivering services
- Performance of a contract, or steps taken at your request before entering one.
- Financial and statutory records
- Legal obligation.
- Website security and availability
- Legitimate interests — protecting our systems and our visitors.
- Optional cookies, if ever introduced
- Consent, given freely and withdrawable at any time.
How long we keep it
We keep personal data only for as long as we need it, then delete it. Our standard periods are:
| Record | Retention period | Reason |
|---|---|---|
| Enquiries that do not lead to work | 12 months | To answer follow-up questions |
| Client contract records | 6 years after the contract ends | Limitation period and audit |
| Financial records | 6 years from the end of the accounting period | Statutory requirement |
| Recruitment records for unsuccessful applicants | 6 months | To handle queries and complaints |
| Hosting platform logs | As set by the provider, typically under 90 days | Security and diagnostics |
International transfers
We host this website and store our business records within the United Kingdom or the European Economic Area wherever possible. Where a supplier processes data outside those areas, we rely on UK adequacy regulations or on the International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, together with any additional safeguards the transfer requires.
How we protect data
- All traffic to this website is encrypted in transit using HTTPS.
- Access to systems holding personal data is restricted to named individuals who need it, and is reviewed periodically.
- Multi-factor authentication is required on all business accounts.
- Devices are encrypted, patched and centrally managed.
- We keep a record of security incidents and will notify the Information Commissioner's Office within 72 hours where a breach is reportable.
Your rights
Under UK data protection law you have the right to:
- be told how your personal data is used;
- ask for a copy of the personal data we hold about you;
- ask us to correct information that is inaccurate or incomplete;
- ask us to delete personal data where we no longer have a reason to hold it;
- ask us to restrict how we use it while a concern is investigated;
- object to processing carried out on the basis of legitimate interests;
- ask us to transfer data you gave us to another organisation, where that applies;
- withdraw consent at any time, where we rely on consent.
To exercise any of these, email privacy@axolotlcs.com. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are not satisfied with our response you may complain to the Information Commissioner's Office at ico.org.uk. We would ask that you raise it with us first so that we have the opportunity to put it right.
Children
This website is intended for business audiences and is not directed at children. We do not knowingly collect personal data relating to children. If you believe we hold such data, contact us and we will delete it.
Changes to this notice
We review this notice at least annually and whenever our processing changes. The version number and review dates are shown at the top of this page. Material changes will be highlighted on the website for a reasonable period.
How to contact us
- privacy@axolotlcs.com
- General enquiries
- info@axolotlcs.com
- Post
- Suite A James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE