Snapshot 57656
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Quorum Cyber + Ontinue to combine forces with unrivaled Microsoft-first MXDR agentic SOC Privacy Policy Privacy Policy Home Privacy Policy 1. Important information and who we are 1.1 Purpose of this privacy policy Quorum Cyber Security Limited respects your privacy and is committed to protecting your personal data. This privacy statement explains how we collect and process your personal data, tells you about your privacy rights, and explains how the law protects you when you: visit any website operated by us, including quorumcyber.com and clarity.quorumcyber.com (“Websites”); use any online tools or services available through our websites or sign up to our newsletter or email alerts; purchase any products or services from us as a customer (“Services”); attend any of our events (in person or online); or• interact with us through our social media pages, including on LinkedIn and other platforms. This statement also explains our obligations under the Privacy and Electronic Communications Regulations 2003 (“PECR”) as amended by the Data (Use and Access) Act 2025 (“DUAA”), which govern how we may contact you electronically and how we use cookies and similar technologies on our websites. 1.2 Controller Quorum Cyber Security Limited, company number SC510322, with registered office at 1st Floor Suite (West Wing) Verdant, 2 Redheughs Rigg, South Gyle, Edinburgh, EH12 9DQ, is the controller responsible for your personal data (referred to as “we”, “us” or “our” throughout this statement). We have a designated compliance team responsible for overseeing questions in relation to this privacy statement and for acting as our Senior Responsible Owner (“SRO”) for data protection matters. 1.3 Contact details If you have any questions about this privacy statement, our privacy practices, or wish to exercise your legal rights or to make a complaint, please contact our Compliance Team: Email: [email protected] Post: 1st Floor Suite (West Wing) Verdant, 2 Redheughs Rigg, South Gyle, Edinburgh, EH12 9DQ You have the right to make a complaint at any time to the Information Commissioner’s Office (“ICO”), the UK regulator for data protection issues (www.ico.org.uk). We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please contact us in the first instance. With effect from 19 June 2026, we are required under the DUAA 2025 to operate a formal data protection complaints procedure. You may submit a complaint to us regarding any alleged failure to comply with the UK GDPR or Part 3 of the Data Protection Act 2018. We will acknowledge all complaints regardless of how they are submitted (including via social media or email) and will respond in writing. If your complaint is not resolved to your satisfaction, you retain the right to escalate to the ICO. 1.4 Changes to this privacy statement We keep this privacy statement under regular review in line with ICO guidance and changes in data protection law. This version was last updated on 23 July 2026 and replaces the version dated 23 March 2023. We will notify you of material changes to this statement where we are required to do so by law or where we consider it appropriate. It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes. 1.5 Third-party links Our websites may include links to third-party websites, plug-ins or applications. Clicking on those links may allow third parties to collect or share data about you. We do not control third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy statement of every website you visit. 2.0 The data we collect about you Personal data means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). We may collect, use, store and transfer different kinds of personal data about you, grouped as follows: Identity Data: name, username or similar identifier, title. Contact Data: address, email address and telephone numbers. Technical Data: IP address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our websites. Profile Data: username and password, Services purchased or used, interests, preferences, feedback and survey responses, and support tickets. Transaction Data: details about Services you access from us and payment details (if applicable). Security Event Data: information security event data from corporate customers’ SIEM systems, including names, usernames, email addresses, locations, IP addresses, URLs accessed, files accessed, and actions taken. Usage Data: information about how you use our websites, products and services. Marketing and Communications Data: your preferences for receiving marketing from us and third parties, and your communication preferences. We also collect, use and share Aggregated Data (statistical or demographic data) for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as it will not directly or indirectly reveal your identity. We do not knowingly collect any Special Categories of Personal Data about you (including details about race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health information, or genetic and biometric data), nor do we collect information about criminal convictions and offences. 3.0 How is your personal data collected? We use different methods to collect data from and about you, including: Direct Interactions: You may give us your Identity, Contact and Marketing and Communications Data by filling in forms, completing surveys, corresponding with us by post, phone, email or social media, or attending events (in person or online). Automated Technologies or Interactions: As you interact with our websites, we automatically collect Technical Data and Usage Data about your equipment, browsing actions and patterns. We collect this data using cookies and similar technologies. Please see Section 7 (Cookies and PECR) and our Cookie Policy for further details. Joint Events: We sometimes participate in joint events with third parties. Where you have opted in to a joint event by providing your registration details (name, email and company), we may share this information with the third-party co-host and vice versa, to send you information about their services and products. You may opt out at any time by contacting us. To stop communications from the joint partner, you should contact that third party directly. Providing Cyber Security Services: In the course of providing cyber security products and services to our corporate customers, we collect Security Event Data from their SIEM systems. System Monitoring or Support Tickets: To ensure our systems operate effectively, we carry out regular monitoring when providing Services and may collect Technical Data and Usage Data. If you submit a support ticket, we will collect Identity, Contact, Technical and Usage Data to enable us to respond. 4.0 How we use your personal data We will only use your personal data when the law allows us to. Under the UK GDPR as amended by the DUAA 2025, the lawful bases for processing are: Performance of a contract with you, or steps taken at your request prior to entering a contract. Compliance with a legal obligation. Legitimate interests (or those of a third party), where your interests and fundamental rights do not override those interests. Recognised Legitimate Interests (“RLI”) – a new basis introduced by the DUAA 2025 for specific activities such as crime prevention, safeguarding vulnerable individuals, responding to emergencies, safeguarding national security, or assisting public interest tasks sanctioned by law. No balancing test is required but we will document necessity. Consent – required for certain activities, including sending unsolicited electronic direct marketing communications under PECR (see Section 7). You have the right to withdraw consent at any time. 4.1 Purposes for Which We Will Use Your Personal Data The table below describes how we plan to use your personal data and the lawful basis we rely on. Where we rely on legitimate interests, we carry out a balancing test to ensure our interests are not overridden by your rights and freedoms. As part of delivering our managed and professional security services — including Managed SOC, Managed Detection & Response (MDR), Extended Detection & Response (XDR), Cyber Incident Response, Brand & Credential Monitoring, Continuous Threat Exposure Management (CTEM), Penetration Testing, and Threat Analysis & Cyber Threat Intelligence (TAC/CETI) — Quorum Cyber uses artificial intelligence and machine learning tools, primarily through the Microsoft security ecosystem (including Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Security Copilot). This use of AI and machine learning tools is reflected in the table below; artificial intelligence is a means by which we process data, not a lawful basis in itself. Purpose/Activity Type of data Lawful Basis (UK GDPR / DUAA 2025) Respond to contact form enquiries Identity; Contact Legitimate interests (running our business and providing services) Manage our relationship with you (notifying you of policy changes; surveys) Identity; Contact; Marketing & Communications Performance of contract; Legal obligation; Legitimate interests (keeping records updated) Administer and protect our business and website Identity; Contact; Technical Legitimate interests (IT services, network security, fraud prevention); Legal obligation Deliver relevant website content and measure advertising effectiveness Identity; Contact; Usage; Marketing & Communications; Technical Legitimate interests (understanding customers, developing services, growing our business) Data analytics to improve website, products/services and marketing Technical; Usage Legitimate interests (keeping website updated and relevant, business development) Make suggestions and recommendations to you about relevant goods or services Identity; Contact; Technical; Usage; Marketing & Communications Legitimate interests (developing products/services and growing our business) Provide cyber security products and services to corporate customers Identity; Contact; Technical; Security Event Performance of contract with our corporate customers Electronic direct marketing by email or SMS (PECR compliance) Identity; Contact; Marketing & Communications Consent (required under PECR Reg. 22 for unsolicited email/SMS); or soft opt-in (existing customers within PECR Reg. 22(3)) Handling formal data protection complaints (from 19 June 2026) Identity; Contact Legal obligation (DUAA 2025 s.77 complaint procedure); Legitimate interests Use of AI and machine learning tools to deliver managed security services Security Event; Technical Legitimate interests (effective and efficient delivery of security services); Performance of contract with our corporate customers Note: We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on. 5.0 Marketing We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. You may receive marketing communications from us if you: have requested email alerts or marketing communications from us; have provided explicit consent to receive marketing communications from us; or have purchased services from us and we rely on the “soft opt-in” exemption under PECR Regulation 22(3) (see Section 7.2), meaning you did not opt out when your contact details were collected, the communications relate to our similar products or services, and we provide a clear opt-out mechanism in every message. If we rely on legitimate interests for postal marketing, we will always balance our interests against any impact on you. We will not send any marketing communications to you if you have asked us to stop or opted out. 5.1 Third-party marketing We will obtain your express opt-in consent before we share your personal data with any third party for their marketing purposes. 5.2 Opting out You can ask us or third parties to stop sending you marketing messages at any time by following the opt-out or unsubscribe link in any marketing message sent to you, or by contacting us directly. We will process opt-out requests promptly and in any event within ten (10) business days. 6.0 Disclosures of your personal data We may share your personal data with the parties set out below for the purposes described in this privacy statement: Third party Detail External service providers Technical and software services (software companies and consulting firms supporting delivery of Services, metrics and analytics); marketing services; professional services (lawyers, auditors, accountants, insurers). Corporate partners / Successors Third parties to whom we may sell, transfer or merge parts of our business or assets. New owners may use your personal data in the same way as set out in this statement. AI and language model service providers Providers of artificial intelligence and machine learning tooling used in delivering our managed and professional security services (for example, Microsoft, through Microsoft Sentinel, Microsoft Defender XDR and Microsoft Security Copilot). We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not permit our third-party service providers to use your personal data for their own purposes. Please contact us for a list of sub-processors we have engaged. 7.0 Electronic Communications and Cookies (PECR Compliance) This section explains how we comply with the Privacy and Electronic Communications Regulations 2003 (“PECR”) as amended by the Data (Use and Access) Act 2025. 7.1 Electronic Direct Marketing PECR Regulation 22 prohibits sending unsolicited direct marketing communications by electronic means (email, SMS or similar) to individuals without their prior consent, subject to the “soft opt-in” exemption described below. We rely on the following bases for electronic marketing: Consent: Where you have positively opted in to receive marketing from us (for example, by ticking a consent box or completing a sign-up form). Consent must be freely given, specific, informed and unambiguous. Soft opt-in (PECR Reg. 22(3)): We may contact existing customers or enquirers by email or SMS about our own similar products or services, provided that: (a) we obtained contact details in the course of a sale or negotiation of a sale; (b) the communications relate only to our similar products or services; (c) we gave you a clear opportunity to opt out when we first collected your details; and (d) we include an easy, free opt-out mechanism in every subsequent message. We do not send electronic marketing to businesses or individuals who are registered with the Telephone Preference Service (TPS) or Corporate Telephone Preference Service (CTPS), unless you have given us your specific prior consent to do so. 7.2 Unsubscribe Mechanism Every electronic marketing communication we send will include a clear, easy and free mechanism to opt out of future communications. Opt-out requests will be honoured within ten (10) business days. If you unsubscribe, we will add you to our suppression list to ensure you are not contacted again. 7.3 Cookies and Similar Technologies Cookies are small data files placed on your device when you visit our websites. PECR Regulation 6 requires us to obtain informed consent before placing non-essential cookies on your device. The DUAA 2025 (Schedule 12) introduced limited exemptions to this consent requirement for: Statistical cookies used solely to understand how users interact with our website (analytics), provided we give users a clear and prominent right to opt out and do not use the data for any further purpose such as marketing or targeted advertising. Functional cookies used solely to enhance the appearance or usability of the website, subject to the same opt-out right and non-repurposing conditions. Strictly necessary cookies remain exempt from consent requirements, as previously. All other cookies (including advertising and tracking cookies) continue to require prior, freely given, specific, informed and unambiguous consent. You can set your browser to refuse all or some cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, some parts of our websites may become inaccessible or not function properly. You may also use our cookie preference centre to manage your choices at any time. For full details of the cookies we use, the purposes for which they are used, and your opt-out rights, please see our Cookie Policy at https://www.quorumcyber.com/cookie-policy/ 8.0 International transfers Some of our external third parties are based outside the UK, so their processing of your personal data will involve a transfer of data outside the UK. Whenever we transfer your personal data out of the UK, we ensure a similar degree of protection is afforded to it by relying on one or more of the following safeguards: Transfers to countries which the Secretary of State has determined provide an adequate level of protection for personal data (UK adequacy regulations). Use of the ICO’s International Data Transfer Agreement (“IDTA”) or the Addendum to the EU Standard Contractual Clauses (“Addendum”), which provide contractual protections for personal data transferred outside the UK. Binding corporate rules approved by the ICO where applicable. Please contact us if you want further information on the specific mechanism used when transferring your personal data out of the UK. 9.0 Data security We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Access to your personal data is limited to employees, agents, contractors and other third parties who have a business need to know. They process your personal data only on our instructions and are subject to a duty of confidentiality. We have procedures in place to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. As a cyber security company, we apply industry-leading technical standards and controls to protect personal data we process on behalf of our clients. 10.0 Data retention We will only retain your personal data for as long as reasonably necessary to fulfil the purposes for which we collected it, including any legal, regulatory, tax, accounting or reporting requirements. We maintain a documented data retention schedule which is reviewed annually. As a general guide, we apply the following retention periods (subject to applicable law and our documented retention schedule): Category of Data Typical Retention Period Rational Customer contract and transaction records 7 years from contract end Tax / accounting obligations Website enquiry / contact form data 2 years from last interaction Legitimate interests / sales follow-up Marketing preferences and opt-in records 3 years from last contact, or until withdrawal of consent PECR / UK GDPR accountability Security Event Data (SIEM) As specified in customer contract, typically 12 months Contractual obligation; security necessity Technical / Usage Data (website logs) 12 months Legitimate interests (security and analytics) We may retain your personal data for a longer period in the event of a complaint, or if we reasonably believe there is a prospect of litigation in respect of our relationship with you. In determining the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether we can achieve those purposes through other means. 11.0 Children’s Data Our Websites and Services are not directed at children under the age of 13 and we do not knowingly collect personal data from children. The DUAA 2025 has amended Article 25 of the UK GDPR to expressly require that organisations providing online services likely to be accessed by children implement data protection by design and by default, taking into account children’s limited awareness of data risks and their evolving needs. We apply the ICO’s Children’s Code (Age-Appropriate Design Code) where our services may be accessed by minors. If you believe we have inadvertently collected personal data from a child under 13, please contact us immediately at [email protected] and we will take steps to delete that information as soon as practicable. 12.0 Automated Decision-Making and Profiling The DUAA 2025 has amended Article 22 of the UK GDPR to ease restrictions on automated decision-making (“ADM”), allowing it to be used in a broader range of circumstances, provided transparency, meaningful human intervention, and an accessible mechanism to challenge outcomes are maintained. We may use automated processing to analyse your data and, in certain circumstances, make decisions about you (for example, in assessing service eligibility or configuring automated security alerts). Where we make decisions by automated means that produce legal or similarly significant effects on you: We will inform you that automated processing is taking place; We will explain the logic involved and the significance and envisaged consequences for you; We will provide a means for you to request human review of the decision; and We will provide a clear, accessible mechanism to challenge the outcome. Automated decisions involving special category data (such as health information or biometric data) are only made with your explicit consent or where required by substantial public interest as defined by UK law. 13.0 Your legal rights Under UK data protection law, you have the following rights in relation to your personal data: Right of Access: You may request a copy of the personal data we hold about you (a “Data Subject Access Request” or DSAR). We will respond within one month, or notify you if we need up to two additional months for complex or multiple requests. Right to Rectification: You may request correction of inaccurate or incomplete personal data we hold about you. Right to Erasure (“Right to be Forgotten”): You may ask us to delete or remove personal data where there is no good reason for us to continue processing it, where you have withdrawn consent, or where we have processed your information unlawfully. Note that we may not always be able to comply for specific legal reasons, which we will notify you of at the time. Right to Object: You may object to processing based on our legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Right to Restrict Processing: You may ask us to suspend processing of your personal data in certain circumstances – for example, if you contest its accuracy, if our use of it is unlawful, or if you need us to retain it for a legal claim. Right to Data Portability: You may request that we provide your personal data to you (or a third party you nominate) in a structured, commonly used and machine-readable format, where we process it by automated means on the basis of your consent or a contract. Right to Review by Independent Authority: You always have the right to lodge a complaint with the ICO (www.ico.org.uk) or, from 19 June 2026, through our formal complaint’s procedure described in Section 1.3. Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time. Withdrawal will not affect the lawfulness of processing based on consent before withdrawal. Rights in Relation to Automated Decision-Making: You have the right to request human review of any significant automated decision made about you, to express your point of view, and to challenge the decision. See Section 12 for further details. No fee is usually required to exercise these rights. We may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. We may also refuse to comply in such circumstances. To exercise any of these rights, please contact us at [email protected]. We will need to verify your identity before processing your request. We aim to respond to all legitimate requests within one month. If your request is complex or we receive multiple requests from you, it may take us up to three months in total; in such a case we will notify you within one month and keep you updated. Want to know more? Get in touch to speak to our experts Ready to talk?