Privacy policy
Last updated 2 October 2026.
Cyber Ascent Consultancy is committed to protecting the privacy and security of the personal data we collect in the course of providing cyber security consultancy. This policy explains how we collect, use, store and protect personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Cyber Ascent Consultancy is a sole consultancy based in the United Kingdom. Solaris Loop is a trading name of Cyber Ascent Consultancy. For the purposes of data protection law, Jason Kelly, Principal Consultant, is the data controller responsible for your personal data.
Email: info@cyberascentconsultancy.com
2. Personal data we collect
- Identity and contact data: name, job title, email address, phone number and postal address when you contact us or engage our services.
- Business-related data: information provided in the course of our consulting services, such as project details or professional correspondence.
- Website data: technical data such as IP addresses and browser information, processed by our hosting provider to deliver and secure this website (see section 7).
- Marketing data: your preferences for receiving marketing communications, if you opt in.
We do not collect special categories of personal data (for example health, race or religion) unless explicitly required for a specific project and with your consent.
3. How we collect personal data
- Directly from you, when you contact us, engage our services or provide information during projects.
- Through our website, when you use the contact form.
- From third parties, such as clients or professional contacts, where you have consented to the sharing of your data.
4. How we use your personal data
- To provide services: to deliver our consulting services, manage client relationships and fulfil contracts. Legal basis: contract.
- To communicate: to respond to enquiries, provide updates or send project-related information. Legal basis: legitimate interests.
- For marketing: to send promotional material or newsletters, only where you have opted in. Legal basis: consent.
- To keep our website secure: to protect the site and contact form from abuse and spam. Legal basis: legitimate interests.
- To comply with legal obligations: for example tax and accounting requirements. Legal basis: legal obligation.
5. Sharing your personal data
As a sole consultancy, we keep data sharing to a minimum. We may share your personal data with:
- Service providers who process data on our behalf under data protection agreements, including:
- Cloudflare, for website hosting, security and the spam check on our contact form (Cloudflare Turnstile)
- Resend, to deliver contact form submissions to our inbox
- our email, accounting and IT service providers
- Legal authorities, if required by law or to protect our legal rights.
- Business partners, only with your consent, for collaborative projects.
We do not sell or rent your personal data.
6. Data security
We take appropriate technical and organisational measures to protect your personal data, including:
- secure storage of physical and digital records, using encrypted devices and access-controlled systems
- use of reputable, secure third-party platforms for data processing
- regular review of our security practices to prevent unauthorised access, loss or disclosure
7. Cookies and website analytics
This website does not use analytics, advertising or tracking cookies, so we do not show a cookie banner. Our contact form uses Cloudflare Turnstile to block automated spam. Turnstile processes technical signals from your browser for that security check only, and does not track you across other websites.
8. Data retention
We keep personal data only for as long as necessary:
- Client data: for the duration of our contract and up to 7 years afterwards, to meet tax and legal obligations.
- Enquiry data: for 12 months, unless it leads to further engagement.
- Marketing data: until you unsubscribe or withdraw consent.
Data is securely deleted or anonymised when no longer needed.
9. Your rights
Under UK GDPR, you have the right to:
- access a copy of your data
- rectification of inaccurate data
- erasure of your data, where applicable
- restrict how we process your data
- object to processing based on legitimate interests or for marketing
- portability, receiving your data in a transferable format
- withdraw consent, where processing is based on consent
To exercise these rights, email info@cyberascentconsultancy.com. We will respond within one month, free of charge, unless a request is manifestly unfounded or excessive.
10. International data transfers
Some of our service providers may process data outside the UK. Where they do, we ensure appropriate safeguards are in place, such as UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
11. Complaints
If you have concerns about how we handle your data, please contact us first at info@cyberascentconsultancy.com. You also have the right to complain to the Information Commissioner's Office (ICO):
- Online: ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
12. Changes to this policy
We may update this policy to reflect changes in our practices or legal requirements. Updates will be posted on this page with the revised date.