Legal
Privacy Policy
Last updated: 16 July 2026
This policy explains how Cyber5 Internet Ltd collects, uses, and protects your personal data when you visit cyber5.io, get in touch with us, or receive communications from us. We keep it plain and we keep it honest.
1. Who we are
Cyber5 Internet Ltd (“Cyber5”, “we”, “us”, “our”) is a company registered in England and Wales under company number 11651669, with its registered office at 35 Brookes Close, Gloucester, GL2 2JQ, United Kingdom.
We are the “data controller” responsible for your personal data under the UK GDPR and the Data Protection Act 2018. If you have any questions about this policy or how we handle your information, contact us at hello@cyber5.io, or by phone on +44 1452 947420 or +44 7436 227723 (UK), or +1 2544 772525 (US).
2. The information we collect
We collect personal data in the following ways:
- Information you give us. When you use our contact form we collect your name, email address, the topic you select, and the content of your message. If you subscribe to our newsletter we collect your email address. If you engage us as a client or supplier, we collect the contact and business details needed to work together and keep in touch.
- Information we collect automatically. When you visit the site, our servers record technical data such as your IP address, browser and device type (user agent), the pages you view, and the date and time of your visit. This is standard server-log data used to run and secure the site.
- Communications data. When we call you, when you call us, or when we send you a transactional text message, we and our telephony provider process your phone number and the associated call or message metadata (such as time and duration).
3. Cookies, analytics, and fonts
- Essential cookies. We use a small number of strictly necessary cookies to run the site and remember choices you make — for example, keeping items in your shopping cart and remembering whether you have chosen light or dark mode. These do not track you and cannot be switched off, because the site relies on them. We do not use advertising cookies.
- Analytics (opt-out). We use PostHog, a first-party, privacy-focused analytics tool, to understand in aggregate how the site is used — such as which pages are viewed and how far people scroll — so we can improve it. It is anonymous: we cannot identify you from it, and we never use it for advertising or profiling. Because it is used solely to measure and improve our own site, we rely on our legitimate interests and the statistical exemption under PECR rather than on your consent. You can opt out at any time using the cookie settings link in the footer.
- Fonts. Our pages load typefaces from Google Fonts. As part of serving those fonts, Google may receive your IP address. If you would prefer not to share this, you can block third-party font loading in your browser.
4. How we use your information
We only use your personal data where the law allows us to. The table below sets out what we do and the lawful basis we rely on under the UK GDPR.
| What we do | Data involved | Lawful basis |
|---|---|---|
| Respond to enquiries and quotes | Name, email, message, phone | Legitimate interests; steps prior to a contract |
| Provide services to clients and suppliers | Contact and business details, correspondence | Performance of a contract |
| Make service calls and send transactional text messages | Phone number, call/message metadata | Legitimate interests; performance of a contract |
| Provide customer support (via Intercom) | Support conversation content, identifiers | Legitimate interests; performance of a contract |
| Send newsletters and marketing emails | Email address | Consent (you can unsubscribe at any time) |
| Measure and improve the website | Anonymous, aggregated usage data | Legitimate interests (PECR statistical exemption) |
| Operate, secure, and troubleshoot the site | IP address, log and device data | Legitimate interests |
| Meet legal, tax, and accounting obligations | Transaction and correspondence records | Legal obligation |
5. Who we share your information with
We do not sell your personal data. We share it only with the service providers who help us run our business, and only as far as they need it to provide their service to us. These include:
- Email delivery — Postmark, Twilio SendGrid, and ZeptoMail (Zoho), which send transactional and other emails on our behalf.
- Telephony and text messaging — Twilio, which handles our voice calls and transactional SMS.
- Customer support — Intercom, which powers our support messenger.
- Analytics — PostHog and Mixpanel, which help us understand site usage.
- Fonts — Google, which serves the typefaces used on the site.
- Customer relationship management (CRM) — the system we use to keep track of enquiries and client relationships.
- Newsletter — the email platform we use to manage subscriptions and send updates.
- Hosting — our website runs on servers located within the European Union (Germany).
We may also disclose personal data where we are legally required to do so, or to establish, exercise, or defend our legal rights.
6. International data transfers
Our website is hosted within the European Union (Germany). Some of the service providers listed above are based outside the United Kingdom — including in the United States and elsewhere. Where your personal data is transferred outside the UK, we make sure it is protected by appropriate safeguards, such as the UK’s International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), or a UK adequacy decision such as the UK Extension to the EU–US Data Privacy Framework.
7. How long we keep your information
- Contact enquiries: up to 24 months after our last contact, unless a business relationship develops.
- Client and supplier records: for the duration of our relationship, and for as long afterwards as we need to meet legal and accounting obligations (typically up to 6 years).
- Newsletter subscriptions: until you unsubscribe.
- Server logs: for a short period for security and troubleshooting, then deleted or anonymised.
8. How we protect your information
We use appropriate technical and organisational measures to keep your personal data safe. This includes encryption in transit (all traffic to cyber5.io is served over HTTPS), access controls that limit who can see your data, hosting within the EU, and choosing reputable providers who are contractually bound to protect it.
9. Your rights
Under the UK GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to how we use your data;
- receive your data in a portable format; and
- withdraw consent at any time, where we rely on it.
We do not make decisions about you based solely on automated processing. To exercise any of these rights, email us at hello@cyber5.io and we will respond within the timeframes required by law.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would appreciate the chance to help first, so please do get in touch with us before you do.
10. Children’s privacy
Our website and services are intended for a business audience and are not directed at children. We do not knowingly collect personal data from anyone under the age of 16.
11. Changes to this policy
We may update this policy from time to time. When we do, we will revise the “last updated” date at the top of this page, and — where the changes are significant — take reasonable steps to let you know.
12. Contact us
Cyber5 Internet Ltd
35 Brookes Close, Gloucester, GL2 2JQ, United Kingdom
Email: hello@cyber5.io
Phone (UK): +44 1452 947420, +44 7436 227723
Phone (US): +1 2544 772525