CAIRNCYBER ADVISORY

Privacy notice

Last updated 16 September 2026

Who we are

Cairn Cyber Advisory Ltd, registered in Scotland, company number SC902675, is the data controller for personal data described here. Registered office: 49 Bonaly Wester, Edinburgh,EH13 0RQ.

Registered with the Information Commissioner's Office, reference CSN0579447.

Questions about this notice: privacy@cairncyberadvisory.co.uk.

This website sets no cookies

We use no cookies, no local storage and no third-party analytics or advertising scripts. There is nothing to consent to, which is why you have not been asked.

Aggregate visit statistics are collected by our hosting provider, Cloudflare, without cookies and without tracking individuals across sites. We cannot identify you from them.

The enquiry form loads Cloudflare Turnstile, a privacy-preserving alternative to reCAPTCHA. It is used solely to distinguish people from automated submissions and does not build an advertising profile.

What we collect, and why

Enquiries

When you use the enquiry form we collect your name, email address, organisation if given, and your message. We use them only to respond to you and, if it leads somewhere, to manage the resulting engagement.

Lawful basis: legitimate interests, responding to a business enquiry you initiated. You can object at any time.

Enquiries are not stored on this website. There is no database. The form relays your message to our email and nothing is retained by the site.

Engagements

During an engagement we process business contact details of client personnel to deliver the work. Lawful basis: performance of a contract, or legitimate interests where the contract is with your employer.

Who we share it with

  • Cloudflare, for website hosting, bot protection and network security.
  • Microsoft, for email and business productivity (Microsoft 365).
  • Our email delivery provider, to relay enquiry notifications.
  • Our accountant, where a record forms part of the company's financial records.

We do not sell personal data and we do not share it for marketing. Some providers process data outside the UK; where they do, transfers rely on UK adequacy regulations or International Data Transfer Agreements.

How long we keep it

  • Enquiries that do not proceed: up to 12 months, then deleted.
  • Engagement records: six years after the engagement ends, to meet statutory accounting and limitation requirements.

Your rights

Under UK GDPR you may request access to your personal data, ask for it to be corrected or erased, restrict or object to its processing, or request it in a portable format. Contact privacy@cairncyberadvisory.co.uk and we will respond within one month.

You may also complain to the Information Commissioner's Office at ico.org.uk, though we would appreciate the chance to resolve it first.

Security

Given what we do, it would be poor form not to secure our own site. It is served as static content over TLS with a restrictive content security policy, strict transport security, and DNS and email authentication configured to reject spoofed mail. Vulnerability reports are welcome, see security.txt.

Changes

Material changes will be reflected in the date at the top of this page.