Privacy Policy
Privacy Policy
Last updated: 29 September 2026
Versa Cyber respects your privacy and is committed to protecting your personal information.
This Privacy Policy explains how personal information is collected, used, stored and protected when you visit the Versa Cyber website, contact us, make an enquiry or use our services.
1. Who we are
Versa Cyber is the trading name of Aaron James, a sole trader based in the United Kingdom, providing cybersecurity consultancy, security assessments, risk assessments and related advisory services.
For the purposes of UK data protection law, the data controller is:
Aaron James trading as Versa Cyber
Email: [your contact/privacy email]
Website: [your website address]
References in this policy to “Versa Cyber”, “we”, “us” or “our” refer to Aaron James trading as Versa Cyber.
2. Information we collect
The information we collect depends on how you interact with us.
Information you provide to us
When you contact us, request a consultation, submit an enquiry or engage our services, we may collect information such as:
your name;
business or organisation name;
job title;
email address;
telephone number;
information contained within your enquiry or correspondence;
information about your organisation, IT environment or cybersecurity requirements;
billing and transaction information; and
other information you voluntarily provide.
Please do not send passwords, private keys, authentication tokens or other sensitive security credentials through our general website contact forms.
Where sensitive information is required to provide an agreed service, we will arrange an appropriate method for providing that information.
Information collected automatically
When you visit our website, certain technical information may be collected automatically.
Depending on the technologies enabled on the website, this may include:
IP address;
browser type;
device type;
operating system;
pages visited;
referring website;
approximate location derived from an IP address;
date and time of visits; and
website interaction and performance information.
Some of this information may be collected using cookies and similar technologies.
3. How we use your information
We may use personal information to:
respond to enquiries;
arrange consultations;
prepare quotations and proposals;
communicate with prospective and existing clients;
provide cybersecurity assessments and consultancy services;
manage our relationship with clients;
administer contracts and engagements;
maintain appropriate business and financial records;
issue invoices and process payments;
maintain the security of our website, systems and services;
detect, prevent or investigate fraud, misuse or security incidents;
improve our website and services;
comply with legal, tax and regulatory obligations; and
send relevant business-to-business marketing communications where permitted by law.
We will not use personal information for purposes incompatible with those for which it was collected unless permitted or required by law.
4. Our lawful bases for processing
UK data protection law requires us to have a lawful basis for processing personal information.
Depending on the circumstances, we may rely on:
Contract
We may process personal information where necessary to take steps at your request before entering into a contract or to perform a contract with you.
Legitimate interests
We may process information where necessary for our legitimate business interests, provided those interests are not overridden by your rights and interests.
Our legitimate interests may include:
responding to business enquiries;
managing relationships with clients and prospective clients;
operating and improving Versa Cyber;
protecting our systems and services;
preventing fraud and misuse;
maintaining appropriate business records;
establishing, exercising or defending legal claims; and
marketing our services to relevant business contacts where permitted by law.
Legal obligation
We may process information where necessary to comply with legal, regulatory, accounting or tax obligations.
Consent
Where required, we may process information based on your consent.
Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that lawfully took place before consent was withdrawn.
5. Cybersecurity assessments and client information
Due to the nature of our services, Versa Cyber may encounter personal information while carrying out authorised cybersecurity assessments.
This may include information contained within:
user accounts;
system and security logs;
directories;
business email addresses;
endpoint and device information;
security alerts;
Microsoft 365 and cloud environments;
network infrastructure; and
other systems included within an authorised assessment.
We aim to access and process only information reasonably necessary to perform the agreed services.
Where we process personal information on behalf of a client, our processing may also be governed by the applicable client agreement, Statement of Work and, where appropriate, a Data Processing Agreement.
6. Marketing communications
We may contact relevant business contacts regarding Versa Cyber's services where permitted by applicable data protection and electronic marketing laws.
Where consent is legally required, we will obtain consent before sending such communications.
You may ask us to stop sending marketing communications at any time by contacting us or by using an unsubscribe mechanism where one is provided.
Where you opt out, we may retain limited information necessary to record your preference and ensure that your marketing request continues to be respected.
7. Sharing your information
We do not sell your personal information.
We may share personal information with trusted service providers where reasonably necessary to operate Versa Cyber or provide our services.
Depending on the circumstances, these may include:
website and hosting providers;
email and communications providers;
cloud service providers;
payment providers;
accounting services;
professional advisers such as accountants, insurers and solicitors;
cybersecurity tools or service providers used as part of an authorised engagement; and
government, regulatory, law enforcement or other authorities where required by law.
Where another organisation processes personal information on our behalf, we take reasonable steps to ensure appropriate contractual and security protections are in place.
8. International transfers
Some of the technology and service providers used by Versa Cyber may process or store information outside the United Kingdom.
Where personal information is transferred internationally, we will take appropriate measures to ensure that the transfer complies with applicable UK data protection law.
Depending on the circumstances, this may include reliance on UK adequacy regulations or appropriate contractual safeguards.
You may contact us if you would like further information about safeguards applicable to your personal information.
9. How long we keep information
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, accounting, security and reporting requirements.
The appropriate retention period depends upon the nature of the information and our relationship with you.
For example:
general enquiries that do not result in an engagement may be retained for a reasonable period for follow-up and record-keeping;
client and contractual records may be retained throughout the client relationship and for an appropriate period afterwards;
invoices and relevant financial records may be retained for the period required by applicable tax and accounting requirements;
information obtained during cybersecurity assessments will be retained only for as long as reasonably required for the engagement and associated obligations; and
limited marketing suppression information may be retained where necessary to ensure an opt-out request continues to be respected.
When information is no longer required, we will delete, anonymise or securely dispose of it as appropriate.
10. How we protect your information
We take appropriate technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, loss or destruction.
Depending on the information and systems involved, these measures may include:
access controls;
multi-factor authentication;
encryption;
secure credential management;
endpoint security;
system monitoring;
data minimisation;
restricted access to client information; and
secure retention and deletion procedures.
While we take information security seriously, no internet transmission, computer system or method of electronic storage can be guaranteed to be completely secure.
11. Cookies
Our website may use cookies and similar technologies.
Some cookies are strictly necessary for the website to function.
Other technologies, including certain analytics or advertising cookies, may require your consent before they can be used.
Where consent is required, these technologies will only be used after you have made the appropriate choice through our cookie controls.
You can change your cookie preferences using the controls provided on our website.
Further information about the cookies used by the website, including their purpose and duration where applicable, should be available through our Cookie Policy or cookie settings.
12. Your data protection rights
Depending on the circumstances, UK data protection law provides rights regarding your personal information.
These may include the right to:
request access to personal information we hold about you;
request correction of inaccurate or incomplete information;
request deletion of your information in certain circumstances;
request restriction of processing in certain circumstances;
object to certain processing;
request transfer of certain information to you or another organisation;
withdraw consent where processing relies upon consent; and
raise concerns about how your information is being used.
These rights are not absolute and do not apply in every circumstance.
If you wish to exercise a data protection right, please contact us using the details provided in this policy.
We may need to verify your identity before fulfilling a request.
Your right to object
Where we process your personal information on the basis of legitimate interests, you may have the right to object to that processing.
You have the right to object to the use of your personal information for direct marketing at any time.
13. Complaints
If you have concerns about how we handle your personal information, please contact us so that we have an opportunity to address your concerns.
You also have the right to make a complaint to the UK's data protection regulator, the Information Commissioner's Office (ICO).
Further information about making a complaint is available from the ICO.
14. Third-party websites
Our website may contain links to websites or services operated by third parties.
We are not responsible for the privacy practices of those third parties. We recommend reviewing the relevant privacy information before providing personal information to another organisation.
15. Automated decision-making
Versa Cyber does not currently use personal information to make solely automated decisions that produce legal or similarly significant effects on individuals.
If this changes, we will update this policy and provide the information required by applicable data protection law.
16. Children's information
Versa Cyber provides business-to-business cybersecurity services.
Our website and services are not intended for children, and we do not knowingly collect personal information from children through the website for commercial or marketing purposes.
17. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our business, website, services, suppliers or legal obligations.
The current version will be published on our website and the “Last updated” date will be revised where appropriate.
Where a change materially affects how we use personal information, we will take appropriate steps to bring that change to the attention of affected individuals.
18. Contact us
If you have questions about this Privacy Policy, wish to exercise your data protection rights or have concerns about how your information is handled, please contact:
Aaron James trading as Versa Cyber
Email: privacy@versacyber.co.uk
Website: versacyber.co.uk