Privacy Policy
Introduction
Tarian Cyber Security Ltd (“we”, “us”, “our”) provides cybersecurity consulting and penetration testing services to business clients.
We are committed to protecting and respecting privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This Privacy Policy explains how we collect, use, store, and protect personal data.
Tarian Cyber Security Ltd is the Data Controller for the purposes of UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Scope of This Policy
This policy applies to:
- Visitors to our website
- Clients and prospective clients
- Individuals whose data is processed during security testing engagements (e.g. employees, users, system accounts, or logs)
Definitions
For the purposes of this Privacy Policy:
- “Client” means any organisation that engages Tarian Cyber Security Ltd for penetration testing or cybersecurity services.
- “Personal Data” means any information relating to an identified or identifiable natural person as defined under UK GDPR.
- “Engagement” means a contracted penetration testing or cybersecurity assessment carried out under a Master Services Agreement (MSA) or Statement of Work (SoW).
- “Testing Data” means any technical data collected or generated during an authorised security assessment, including logs, vulnerability data, screenshots, and system outputs.
Data We Collect
Client Contact Data
- Name
- Job title
- Business email address
- Business telephone number
- Company name
Service Delivery Data (Penetration Testing Data)
Depending on the engagement, we may process:
- IP addresses
- Hostnames and domain information
- System logs
- Application data
- Authentication credentials (where explicitly authorised)
- Network architecture information
- Vulnerability data and exploitation evidence
- Screenshots, recordings, and technical outputs from testing tools
Website Usage Data
- IP address
- Browser type and version
- Pages visited
- Time and date of access
- Referring website
(Collected via analytics tools, where consent has been provided)
Data Source
In most cases, personal data processed during penetration testing engagements is not collected directly from individuals.
Instead, data is:
- Provided by the Client, or
- Accessed within Client systems during authorised testing activities conducted under contract.
We do not intentionally collect personal data from individuals unless explicitly required for the delivery of agreed services.
How We Use Your Data
We process personal data for the following purposes:
- Delivering penetration testing and cybersecurity services
- Scoping and planning engagements
- Identifying vulnerabilities and producing security reports
- Communicating with clients
- Meeting legal and regulatory obligations
- Improving service quality and methodologies
- Website administration and security monitoring
- Ensuring data minimisation and secure handling of information during authorised security testing activities
Legal Basis for Processing
We rely on the following lawful bases under UK GDPR:
- Contract: Processing necessary for the performance of a contract with our clients for cybersecurity services.
- Legal obligation: Processing required to comply with applicable UK law, regulatory requirements, or lawful requests.
- Legitimate interests: Processing necessary for the operation, security, and improvement of our services, including secure delivery of penetration testing engagements.
- Consent: Where explicitly required, such as for marketing communications or optional website analytics features.
Data Sharing
We do not sell personal data.
We may share data only in the following circumstances:
- With the client organisation commissioning the work
- With authorised subcontractors (if applicable and under NDA)
- With legal or regulatory authorities where required by law
- With professional advisers (e.g. accountants, legal counsel)
All third parties are required to respect confidentiality and data protection obligations.
Data Security
We implement appropriate technical and organisational measures to protect data, including:
- Encryption of data in transit and at rest where applicable
- Access control and least-privilege principles
- Secure storage of client materials
- Use of secure file transfer mechanisms
- Restricted access to testing environments and reports
Security controls are defined in our internal Information Security Policy and are regularly reviewed and aligned with recognised information security best practices, including principles of ISO 27001.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected.
Typical retention periods are as follows:
| Data Type | Retention Period |
|---|---|
| Client contact data | Up to 3 years for legal, contractual, and accounting purposes |
| Penetration testing reports | 2–6 months depending on contractual requirements |
| Raw testing data (logs, scan results, evidence) | 30–90 days unless otherwise agreed in writing |
| Authentication credentials | Deleted immediately after completion of the engagement |
After retention periods expire, data is securely deleted or anonymised in accordance with industry best practice.
International Transfers
Where data is transferred outside the UK, we ensure appropriate safeguards are in place, such as:
- UK adequacy decisions, or
- Standard Contractual Clauses (SCCs)
Your Rights
Under UK GDPR, individuals have the right to:
- Access personal data we hold about them
- Request correction of inaccurate data
- Request deletion of personal data (where applicable)
- Object to processing
- Request restriction of processing
- Data portability (where applicable)
Requests can be made to: admin@tariancybersecurity.com
Automated Decision Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals.
Security Testing Disclaimer
During authorised penetration testing engagements:
- We may temporarily process sensitive system data as required to complete testing
- All activities are performed under strict contractual authorisation (MSA / Statement of Work / Rules of Engagement)
- We do not access personal data beyond what is necessary to identify security vulnerabilities
Cookies
Our website uses cookies and similar technologies to improve user experience and analyse website traffic. For full details of the cookies we use, please refer to our Cookie Policy.
Where required by law, we obtain consent before placing non-essential cookies on your device.
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be published on our website.
Contact Us
If you have any questions about this Privacy Policy or your data, contact:
Tarian Cyber Security Ltd
Email: admin@tariancybersecurity.com
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at https://ico.org.uk/