Privacy Notice
How Negative Zero collects, processes, and protects your information across our website, commercial lead forms, interactive AI guidance tools, and certification workflows.
Last updated: September 2026 · Version 1.0 (Pre-Launch Edition)
Data Controller
Identity of the organization responsible for the processing of your personal data.
Negative Zero Ltd
Negative Zero Ltd is an IASME-approved Cyber Essentials Certification Body and cybersecurity advisory consultancy registered in England and Wales. We operate as the Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 for personal data processed through our website and digital services.
You can object to commercial follow-up at any time by emailing privacy@negativezero.com.
Data Collection & Purposes
The specific categories of personal data we collect, why we collect them, and the UK GDPR lawful basis for each activity.
1. B2B Enquiries & Lead Forms (Book Demo, Quote Engine, Contact Team)
Art 6(1)(f) Legitimate InterestsWhen you submit a request to book a live demo (/book-demo), request a fixed-price certification quote (/cyber-essentials/quote), or message our advisory team (/contact-team), we collect:
- Contact details: Full name, professional work email address, company or organisation name, professional role/job title, and telephone number (if provided).
- Scoping context: Organization size, current Cyber Essentials requirements, target compliance timeline, and custom requirements notes.
- Technical telemetry: We record the visitor's IP address and browser user-agent, and for the demo and quote forms timezone, screen resolution, and browser language.
Attachment & Retention: These technical telemetry items are attached to the enquiry record in our CRM and internal notification email and kept for the same period as the enquiry.
Purpose & Lawful Basis: We process this information to evaluate your certification or consulting needs, issue guaranteed fixed-price quotes, schedule discovery sessions with our Lead Assessor, and follow up with commercial information. Our lawful basis is our legitimate interest in conducting B2B commerce with business representatives (UK GDPR Art 6(1)(f)).
2. Cyber Essentials Readiness Reports (/api/ce-readiness-report)
Art 6(1)(f) Legitimate InterestsWhen you complete our self-assessment readiness check and request a bespoke Cyber Essentials preparation report in PDF or Excel format, we collect your name, business email, organization name, technical answers across the 5 Cyber Essentials control pillars, target deadline, and telephone number (if provided). We also record the visitor's IP address and browser user-agent, which are attached to the enquiry record in our CRM and internal notification email and kept for the same period as the enquiry.
Delivery & Processing: The readiness report is emailed to the visitor and to our sales inbox, the enquiry (with the assessment score) is recorded in HubSpot, and the chat transcript is sent to Google Gemini to write the executive summary. If you give the Cyber Essentials agent your name, organisation and work email in the chat and ask us to get in touch, those details, the certification level, deadline and concerns you mentioned are recorded in HubSpot, posted to our internal Teams channel, and a confirmation is emailed to you.
3. Security Telemetry & Rate Limiting
Art 6(1)(f) Legitimate InterestsTo protect our services against abusive traffic, automated script flooding, and volumetric request exhaustion, we use:
- Cloudflare Turnstile challenge tokens verified per request.
- Rate-limit counters keyed by IP address and session id held in Vercel KV for at most one day.
Lawful Basis: Legitimate interests (UK GDPR Art 6(1)(f)) in protecting application availability and infrastructure stability.
4. Event Photography & Community Media
Art 6(1)(f) Legitimate InterestsWe host community hackathons, tech workshops, and industry meetups (such as our August Hackathon documented on /events). Group photographs and general event imagery may be published to document community participation.
Your Choice: If you appear in any published event photograph and wish to have the image cropped, blurred, or removed, email privacy@negativezero.com and we will action your request promptly.
Cyber Essentials AI Assistant
Technical disclosures regarding conversational data processing, Google Gemini integration, transcript storage, and retention.
Interactive Guidance & Scoping Assistant
Our interactive Cyber Essentials Assistant (/cyber-essentials/agent) and readiness chat engines allow prospective applicants to ask questions about scoping, multi-factor authentication requirements, boundary firewalls, unsupported software fleets, and certification timelines.
Prompts are processed by Google's Gemini API in the United States under the Gemini API terms for the tier we use (details on request). Negative Zero does not use conversations to train models.
Session transcripts are stored in key-value storage (Vercel KV) for 30 days for quality and abuse monitoring before automatic deletion.
The assistant is designed for technical scheme advice. Please do not enter passwords, corporate API tokens, private encryption keys, banking details, or sensitive personal data into the chat. The assistant will reject attempts to collect passwords or bearer secrets.
Sub-Processors
Third-party cloud infrastructure and software providers authorized to process data on our behalf.
HubSpot, Inc.
United KingdomCustomer Relationship Management (CRM) & Lead Pipeline
Transfer Mechanism: Details on request
Google LLC
United StatesGenerative Reasoning Engine for Cyber Essentials AI Assistant
Transfer Mechanism: Details on request
Microsoft Corporation
United KingdomEnterprise service email delivery, transactional dispatch, and corporate communications
Transfer Mechanism: Details on request
Vercel Inc. / Upstash Inc.
United KingdomEdge web application hosting, transient KV cache and, with your consent, cookieless web analytics and performance measurement
Transfer Mechanism: Details on request
Cloudflare, Inc.
United StatesTurnstile bot verification
Transfer Mechanism: Details on request
n8n GmbH
United KingdomWorkflow automation that reads our quote mailbox and passes requests to OpenAI, HubSpot and Xero
Transfer Mechanism: Details on request
OpenAI
United StatesExtracts contact and organisation details from the quote email
Transfer Mechanism: Details on request
Xero Ltd
United StatesCreates a customer contact and draft quote for every quote request
Transfer Mechanism: Details on request
Blockmark Technologies Ltd
United KingdomCryptographic certificate verification widgets and badges
Transfer Mechanism: Details on request
Transfers & Retention
International transfer mechanisms and data retention schedules.
International Transfers
Where personal data leaves the UK we rely on the UK International Data Transfer Addendum or UK adequacy regulations. The mechanism for each provider is available upon request and is shown in the sub-processor list above.
Data Retention Schedule
| Data Category | Retention Period | Action at Expiry |
|---|---|---|
| AI Assistant Chat Transcripts | 30 days | Automated TTL purge from KV storage |
| Security & Rate Limiting Telemetry | up to 24 hours (rate-limit counters) | Expire automatically from Vercel KV |
| Request Reference Records (status lookup) | 90 days | Automated TTL purge from KV storage (holds request type, channel, email domain and CRM record ids only) |
| B2B CRM Leads & Enquiries | Details on request | Details on request |
| Formal Certification Audit Records | Details on request | Details on request |
Marketing
How we handle commercial follow-up and marketing communications.
Enquiry Follow-Up & Marketing Consent
We follow up on enquiries under legitimate interests. Business contacts who enquire through our forms or agent tools may also receive relevant marketing about our products, services and events under legitimate interests (corporate subscribers, PECR regulation 22); the contact-team form lets you decline at the point of submission, personal email addresses are never added to marketing without consent, and every marketing email carries an unsubscribe link. Either can be stopped at any time by emailing privacy@negativezero.com.
Your Rights
Your statutory rights under UK data protection legislation and how to exercise them with Negative Zero.
Under the UK GDPR and the Data Protection Act 2018, you possess specific legal rights regarding your personal information:
Right of Access (DSAR)
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete records.
Right to Erasure
Request deletion of your data where no overriding legal obligation exists.
Right to Restrict Processing
Request temporary suspension of data processing.
Right to Data Portability
Receive your submitted data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests, including an absolute right to halt direct marketing.
Right to Withdraw Consent
Withdraw any consent previously granted at any time without penalty.
Automated Decisions
We do not carry out automated decision-making or profiling with legal effect.
How to Exercise Your Rights
To exercise any of these rights, email our data protection team at privacy@negativezero.com. We will verify your identity and respond within one calendar month free of charge.
Right to Lodge a Complaint with the ICO
If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO) · Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 · Website: ico.org.uk
