Negative Zero
UK GDPR & Data Protection Act 2018

Privacy Notice

How Negative Zero collects, processes, and protects your information across our website, commercial lead forms, interactive AI guidance tools, and certification workflows.

Last updated: September 2026 · Version 1.0 (Pre-Launch Edition)

Data Controller

Identity of the organization responsible for the processing of your personal data.

Negative Zero Ltd

Negative Zero Ltd is an IASME-approved Cyber Essentials Certification Body and cybersecurity advisory consultancy registered in England and Wales. We operate as the Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 for personal data processed through our website and digital services.

You can object to commercial follow-up at any time by emailing privacy@negativezero.com.

Company Number15412959
ICO RegistrationZC087225
Registered Office3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
Vulnerability Disclosuressecurity@negativezero.com

Data Collection & Purposes

The specific categories of personal data we collect, why we collect them, and the UK GDPR lawful basis for each activity.

1. B2B Enquiries & Lead Forms (Book Demo, Quote Engine, Contact Team)

Art 6(1)(f) Legitimate Interests

When you submit a request to book a live demo (/book-demo), request a fixed-price certification quote (/cyber-essentials/quote), or message our advisory team (/contact-team), we collect:

  • Contact details: Full name, professional work email address, company or organisation name, professional role/job title, and telephone number (if provided).
  • Scoping context: Organization size, current Cyber Essentials requirements, target compliance timeline, and custom requirements notes.
  • Technical telemetry: We record the visitor's IP address and browser user-agent, and for the demo and quote forms timezone, screen resolution, and browser language.

Attachment & Retention: These technical telemetry items are attached to the enquiry record in our CRM and internal notification email and kept for the same period as the enquiry.

Purpose & Lawful Basis: We process this information to evaluate your certification or consulting needs, issue guaranteed fixed-price quotes, schedule discovery sessions with our Lead Assessor, and follow up with commercial information. Our lawful basis is our legitimate interest in conducting B2B commerce with business representatives (UK GDPR Art 6(1)(f)).

2. Cyber Essentials Readiness Reports (/api/ce-readiness-report)

Art 6(1)(f) Legitimate Interests

When you complete our self-assessment readiness check and request a bespoke Cyber Essentials preparation report in PDF or Excel format, we collect your name, business email, organization name, technical answers across the 5 Cyber Essentials control pillars, target deadline, and telephone number (if provided). We also record the visitor's IP address and browser user-agent, which are attached to the enquiry record in our CRM and internal notification email and kept for the same period as the enquiry.

Delivery & Processing: The readiness report is emailed to the visitor and to our sales inbox, the enquiry (with the assessment score) is recorded in HubSpot, and the chat transcript is sent to Google Gemini to write the executive summary. If you give the Cyber Essentials agent your name, organisation and work email in the chat and ask us to get in touch, those details, the certification level, deadline and concerns you mentioned are recorded in HubSpot, posted to our internal Teams channel, and a confirmation is emailed to you.

3. Security Telemetry & Rate Limiting

Art 6(1)(f) Legitimate Interests

To protect our services against abusive traffic, automated script flooding, and volumetric request exhaustion, we use:

  • Cloudflare Turnstile challenge tokens verified per request.
  • Rate-limit counters keyed by IP address and session id held in Vercel KV for at most one day.

Lawful Basis: Legitimate interests (UK GDPR Art 6(1)(f)) in protecting application availability and infrastructure stability.

4. Event Photography & Community Media

Art 6(1)(f) Legitimate Interests

We host community hackathons, tech workshops, and industry meetups (such as our August Hackathon documented on /events). Group photographs and general event imagery may be published to document community participation.

Your Choice: If you appear in any published event photograph and wish to have the image cropped, blurred, or removed, email privacy@negativezero.com and we will action your request promptly.

Cyber Essentials AI Assistant

Technical disclosures regarding conversational data processing, Google Gemini integration, transcript storage, and retention.

Interactive Guidance & Scoping Assistant

Our interactive Cyber Essentials Assistant (/cyber-essentials/agent) and readiness chat engines allow prospective applicants to ask questions about scoping, multi-factor authentication requirements, boundary firewalls, unsupported software fleets, and certification timelines.

Google Gemini Processing

Prompts are processed by Google's Gemini API in the United States under the Gemini API terms for the tier we use (details on request). Negative Zero does not use conversations to train models.

30-Day Transcript Retention

Session transcripts are stored in key-value storage (Vercel KV) for 30 days for quality and abuse monitoring before automatic deletion.

Important Usage Guidance: Do Not Submit Secrets or PII

The assistant is designed for technical scheme advice. Please do not enter passwords, corporate API tokens, private encryption keys, banking details, or sensitive personal data into the chat. The assistant will reject attempts to collect passwords or bearer secrets.

Sub-Processors

Third-party cloud infrastructure and software providers authorized to process data on our behalf.

HubSpot, Inc.

United Kingdom

Customer Relationship Management (CRM) & Lead Pipeline

Transfer Mechanism: Details on request

Google LLC

United States

Generative Reasoning Engine for Cyber Essentials AI Assistant

Transfer Mechanism: Details on request

Microsoft Corporation

United Kingdom

Enterprise service email delivery, transactional dispatch, and corporate communications

Transfer Mechanism: Details on request

Vercel Inc. / Upstash Inc.

United Kingdom

Edge web application hosting, transient KV cache and, with your consent, cookieless web analytics and performance measurement

Transfer Mechanism: Details on request

Cloudflare, Inc.

United States

Turnstile bot verification

Transfer Mechanism: Details on request

n8n GmbH

United Kingdom

Workflow automation that reads our quote mailbox and passes requests to OpenAI, HubSpot and Xero

Transfer Mechanism: Details on request

OpenAI

United States

Extracts contact and organisation details from the quote email

Transfer Mechanism: Details on request

Xero Ltd

United States

Creates a customer contact and draft quote for every quote request

Transfer Mechanism: Details on request

Blockmark Technologies Ltd

United Kingdom

Cryptographic certificate verification widgets and badges

Transfer Mechanism: Details on request

Transfers & Retention

International transfer mechanisms and data retention schedules.

International Transfers

Where personal data leaves the UK we rely on the UK International Data Transfer Addendum or UK adequacy regulations. The mechanism for each provider is available upon request and is shown in the sub-processor list above.

Data Retention Schedule

Data CategoryRetention PeriodAction at Expiry
AI Assistant Chat Transcripts30 daysAutomated TTL purge from KV storage
Security & Rate Limiting Telemetryup to 24 hours (rate-limit counters)Expire automatically from Vercel KV
Request Reference Records (status lookup)90 daysAutomated TTL purge from KV storage (holds request type, channel, email domain and CRM record ids only)
B2B CRM Leads & EnquiriesDetails on requestDetails on request
Formal Certification Audit RecordsDetails on requestDetails on request

Cookies & Tracking

Optional analytics, asked for up front, and privacy-preserving challenge verification.

Nothing Loads Until You Say Yes

No cookie is set and no analytics script is loaded until you accept. If you decline, or simply ignore the banner, nothing is stored on your device and no request is made to Google. You can change your mind at any time with the Cookie settings link in the footer.

No Advertising or Cross-Site Tracking

With your consent we use Google Analytics 4 to count visits and see which pages are read, and Vercel Web Analytics and Speed Insights, our hosting provider’s cookieless, first-party page-view and performance measurement. Advertising storage, ad personalisation and Google Signals are switched off, so your visit is not used to build an advertising profile. There are no advertising pixels, no session replay and no cross-site tracking. The Cloudflare Turnstile challenge runs without tracking cookies.

What Is Stored

Your choice is recorded in your browser’s local storage, not in a cookie, so declining leaves nothing in the cookie jar. If you accept, Google Analytics sets _ga and _ga_<stream>, which expire after 13 months and are deleted immediately if you withdraw consent. Vercel Web Analytics stores nothing on your device: it recognises a returning visitor for a single day from a hash of request headers held on Vercel’s servers, so withdrawing consent simply stops it reporting.

Marketing

How we handle commercial follow-up and marketing communications.

Enquiry Follow-Up & Marketing Consent

We follow up on enquiries under legitimate interests. Business contacts who enquire through our forms or agent tools may also receive relevant marketing about our products, services and events under legitimate interests (corporate subscribers, PECR regulation 22); the contact-team form lets you decline at the point of submission, personal email addresses are never added to marketing without consent, and every marketing email carries an unsubscribe link. Either can be stopped at any time by emailing privacy@negativezero.com.

Your Rights

Your statutory rights under UK data protection legislation and how to exercise them with Negative Zero.

Under the UK GDPR and the Data Protection Act 2018, you possess specific legal rights regarding your personal information:

Right of Access (DSAR)

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete records.

Right to Erasure

Request deletion of your data where no overriding legal obligation exists.

Right to Restrict Processing

Request temporary suspension of data processing.

Right to Data Portability

Receive your submitted data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests, including an absolute right to halt direct marketing.

Right to Withdraw Consent

Withdraw any consent previously granted at any time without penalty.

Automated Decisions

We do not carry out automated decision-making or profiling with legal effect.

How to Exercise Your Rights

To exercise any of these rights, email our data protection team at privacy@negativezero.com. We will verify your identity and respond within one calendar month free of charge.

Right to Lodge a Complaint with the ICO

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with the UK supervisory authority:

Information Commissioner's Office (ICO) · Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 · Website: ico.org.uk