1. Introduction
Thank you for visiting our website at www.alvearium.associates.
At Alvearium Associates Limited (“we”, “us”, “our”), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and safeguard your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Company Details:
- Company Name: Alvearium Associates Limited
- Registered in: England and Wales
- ICO Registration Reference: ZB811590
- Website: www.alvearium.associates
- Contact Email: privacy@alvearium.associates
- Data Protection Officer: Contactable via privacy@alvearium.associates
2. Who We Are and What We Do
Alvearium Associates Limited is a cyber and technology consulting business based in the United Kingdom. We provide consulting services including strategic advice, technical assessments, and fractional team delivery to enhance, augment, or challenge our clients’ internal teams.
We act as a data controller for information collected through our website and business operations, and may act as a data processor when handling personal data on behalf of our clients during consulting engagements.
3. Information We Collect
3.1 Information You Provide to Us
When you interact with us, we may collect:
- Contact Information: Name, email address, postal address, telephone number, job title, company name
- Correspondence: Information contained in emails, enquiries, or other communications you send to us
- Engagement Information: Details about your consulting requirements, project specifications, and related business information
- Professional Information: Job titles, roles, and professional details of stakeholders involved in consulting engagements
3.2 Information We Collect Automatically
When you visit our website, we may automatically collect:
- Technical Information: IP address, browser type and version, operating system, device information
- Usage Information: Pages visited, time spent on pages, navigation patterns, date and time of access
- Referral Information: The website or source that referred you to our site
3.3 Information Collected During Consulting Engagements
When providing consulting services, we may have access to:
- Client Stakeholder Information: Names, email addresses, job titles, and contact details of individuals involved in the engagement
- Business Information: General business data necessary to fulfil our consulting obligations
- Project Data: Information related to the scope and delivery of our services
We do not intentionally collect special category data (such as health data, biometric data, or information about criminal convictions) unless specifically required and agreed upon for a particular engagement.
4. How We Use Your Information
We process your personal data for the following purposes:
4.1 As a Data Controller
- Service Delivery: To respond to your enquiries, provide consultations, and deliver the services you have requested
- Contract Performance: To enter into and fulfil contractual obligations with clients
- Business Communication: To send you updates, information, or materials related to our services (with your consent where required)
- Website Operation: To maintain, improve, and analyse the functionality and user experience of our website
- Legal Compliance: To comply with legal and regulatory obligations
- Business Operations: To manage our business relationships, maintain records, and conduct internal administration
- Security: To protect our systems, detect and prevent fraud, and ensure the security of our operations
4.2 As a Data Processor
When acting as a data processor for client engagements, we process personal data strictly in accordance with documented instructions from our clients and pursuant to data processing agreements.
5. Legal Basis for Processing
We process personal data based on the following legal grounds under UK GDPR:
- Consent: Where you have given clear consent for us to process your personal data for specific purposes (e.g., marketing communications)
- Contract: Where processing is necessary to fulfil a contract with you or to take steps at your request before entering into a contract
- Legal Obligation: Where we must process your data to comply with legal or regulatory requirements
- Legitimate Interests: Where processing is necessary for our legitimate business interests, such as:
- Operating and improving our website
- Providing and improving our consulting services
- Managing business relationships
- Protecting our business and systems from security threats
- Direct marketing (where we have an existing business relationship)
We will always balance our legitimate interests against your rights and freedoms, and you have the right to object to processing based on legitimate interests.
6. Cookies and Similar Technologies
6.1 What Cookies We Use
Our website uses essential/functional cookies only. These cookies are strictly necessary for the operation of our website and do not track your browsing behaviour across other websites.
Essential cookies enable core functionality such as:
- Session management
- Security features
- Basic site navigation
- Remembering your privacy preferences
6.2 Managing Cookies
You can control and delete cookies through your browser settings. Please note that disabling essential cookies may affect the functionality of our website. For more information about cookies, visit www.aboutcookies.org or www.allaboutcookies.org.
7. How We Share Your Information
7.1 Service Providers and Subcontractors
We may share your information with trusted third parties who assist us in operating our business and delivering our services, including:
- Subcontractors and Consultants: Carefully selected professionals who support our consulting engagements and are bound by confidentiality obligations
- IT Service Providers: Microsoft Corporation (for Microsoft 365 services including email, file storage, and collaboration tools)
- Professional Advisers: Lawyers, accountants, and other professional advisers where necessary
All third parties are required to:
- Maintain appropriate security measures
- Process data only as instructed by us
- Comply with applicable data protection laws
- Maintain confidentiality
7.2 Legal Requirements
We may disclose your information where required or permitted by law, including:
- To comply with legal obligations or court orders
- To protect our rights, property, or safety, or that of others
- In connection with legal proceedings or investigations
- To enforce our terms of service or other agreements
7.3 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred to the relevant third party, subject to appropriate safeguards.
8. International Data Transfers
We do not transfer personal data outside the United Kingdom or European Economic Area (EEA).
Our infrastructure and service providers (Microsoft 365) are UK-based. Should our business practices change to require international transfers, we will:
- Notify you of any such transfers
- Implement appropriate safeguards such as Standard Contractual Clauses
- Update this Privacy Policy accordingly
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
9.1 Retention Periods
- Enquiry Data: Retained for up to 2 years after the last contact, unless you become a client
- Client Data: Retained for the duration of the engagement plus 7 years (in line with accounting and legal requirements)
- Website Usage Data: Retained for up to 12 months for analytical purposes
- Marketing Consent Records: Retained until consent is withdrawn, then archived for regulatory compliance purposes
- Engagement Records: Retained for 7 years after completion to comply with professional indemnity insurance requirements and potential legal claims
When personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention and disposal procedures.
10. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
10.1 Right of Access
You have the right to request a copy of the personal data we hold about you.
10.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
10.3 Right to Erasure (“Right to be Forgotten”)
You have the right to request deletion of your personal data in certain circumstances, such as when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where consent is the legal basis)
- You object to processing based on legitimate interests and there are no overriding legitimate grounds
- The data has been unlawfully processed
10.4 Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain circumstances.
10.5 Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format.
10.6 Right to Object
You have the right to object to:
- Processing based on legitimate interests
- Direct marketing (including profiling)
- Processing for research or statistical purposes
10.7 Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
10.8 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
10.9 Exercising Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@alvearium.associates
- Subject Line: “Data Protection Rights Request”
We will respond to your request within one month, though this may be extended by up to two months for complex requests. We will keep you informed of any such extension.
Verification: To protect your privacy, we may need to verify your identity before fulfilling your request.
No Fee: You will not normally have to pay a fee to exercise your rights. However, we may charge a reasonable fee or refuse to comply with your request if it is clearly unfounded, repetitive, or excessive.
11. Security
We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, or destruction.
Our security measures include:
- Access Controls: Restricted access to personal data on a need-to-know basis
- Encryption: Data encryption in transit and at rest where appropriate
- Secure Infrastructure: Use of Microsoft 365’s enterprise-grade security features
- Staff Training: Regular training for staff and subcontractors on data protection obligations
- Confidentiality Agreements: All staff and subcontractors are bound by confidentiality obligations
- Incident Response: Procedures to detect, report, and investigate security incidents
While we implement robust security measures, please be aware that no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data to the best of our ability.
11.1 Data Breaches
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner’s Office (ICO) within 72 hours where feasible
- Notify affected individuals without undue delay where the breach poses a high risk
- Take immediate steps to contain and remedy the breach
12. Third-Party Links
Our website may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
13. Children’s Privacy
Our services are not directed at children under the age of 16, and we do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete it as soon as possible.
14. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or other factors.
Any changes will be:
- Posted on this page with an updated “Last Updated” date
- Effective immediately upon posting, unless otherwise stated
- Notified to you via email or prominent website notice if the changes are material
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.
15. Your Right to Complain
If you are unhappy with how we have handled your personal data or wish to raise a concern about our privacy practices, please contact us first at privacy@alvearium.associates. We will investigate and respond to your complaint.
You also have the right to lodge a complaint with the supervisory authority:
Information Commissioner’s Office (ICO)
- Website: www.ico.org.uk
- Telephone: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
Data Protection Officer
- Email: privacy@alvearium.associates
- Website: www.alvearium.associates/privacy
Company Details:
- Company Name: Alvearium Associates Limited
- Registered in: England and Wales
We aim to respond to all enquiries within 5 working days.
17. Consent
By using our website, engaging our services, or providing us with your personal information, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein, where consent is the applicable legal basis for processing.
You have the right to withdraw your consent at any time by contacting us at privacy@alvearium.associates.
This Privacy Policy was last updated in April 2026.
