Legal
Last updated: 6 August 2026 · Applies to viktrixcyber.co.uk and related services
Viktrix Cyber Limited ("Viktrix", "we", "us") is committed to protecting personal data. This policy explains what we collect, why, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data controller
Viktrix Cyber Limited, 8 Craig Place, Aberdeen, AB11 9AH. Company No. SC887749.
Contact: info@viktrixcyber.co.uk
We are the data controller for personal data collected via this website. Where we process personal data on behalf of our customers (for example endpoint telemetry), we act as a data processor under the terms of a Data Processing Agreement.
1. Data we collect
Website visitors: contact details you submit (name, work email, company, phone), and technical data (IP address, browser type, pages visited) via cookies, see our Cookie Policy.
Customers and prospects: account details, billing information (processed by our payment provider; we do not store card numbers), and support correspondence.
Platform telemetry (on behalf of customers): the Vindex platform processes security event data from customer endpoints. This may incidentally include personal data (usernames, IP addresses, hostnames). For this data we act as a processor and the customer is the controller; processing is governed by our Data Processing Agreement.
2. How the platform protects personal data by design
3. Purposes and lawful bases
Purpose
Lawful basis
Responding to enquiries and demos
Legitimate interests
Providing and securing the service
Contract
Billing and accounting
Legal obligation / contract
Service updates and marketing (opt-in)
Consent
Detecting threats to customer systems
Contract (as processor on customer instruction)
We do not use your data for automated decision-making or profiling in ways that produce legal or similarly significant effects.
4. Sharing and sub-processors
We do not sell personal data. We share data only with sub-processors necessary to run the service (cloud hosting, payment processing, email) under written agreements. Our current sub-processor list is available on request from info@viktrixcyber.co.uk.
Where data leaves the UK, we rely on adequacy regulations or International Data Transfer Agreements.
5. Retention
We retain personal data only for as long as necessary for the purposes described above, or as required by law.
6. Your rights
You have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and to withdraw consent at any time.
To exercise any right, email info@viktrixcyber.co.uk. We will respond within one month.
7. Security
We apply the same discipline to our own data that we sell to customers: encryption in transit and at rest, least-privilege access, logging of administrative actions, and regular review.
No system is perfectly secure; we maintain an incident response process and will notify affected parties and the ICO where legally required. If you believe your data has been compromised, contact us immediately at info@viktrixcyber.co.uk.
8. Changes
We will post any changes here and update the date above. Material changes affecting customers will be notified directly.
Contact and complaints
For data protection queries: info@viktrixcyber.co.uk
If you are not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO):
Information Commissioner's Office