Effective September 2026 | Version 1.0 | Last Reviewed: 2nd September 2026
Privacy Policy
01 - WHO WE ARE
This privacy policy explains how RED HORIZON CYBER GROUP LIMITED (company number 17447075), trading as Red Horizon Cyber Group ("Red Horizon", "we", "us" or "our"), collects, uses, shares and protects personal information when you visit our website, contact us, request a Cyber Risk Review, enquire about our services or otherwise interact with us before entering into a client agreement.
Our group brands and service lines include Apex Consultancy, Quadrant IT Services and Red Horizon Cyber Academy. Unless a separate notice says otherwise, RED HORIZON CYBER GROUP LIMITED is the controller of personal information collected through this website.
Registered office: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF
Privacy contact: enquiries@redhorizoncybergroup.com
02 - SCOPE OF THIS POLICY
This policy applies to the public Red Horizon website and pre-contract enquiries. Separate privacy information may apply when we deliver penetration testing, security assessments, managed services, IT services, training, recruitment, Red Horizon ONE or other contracted services. Where we process personal information solely on a client's instructions, that client may be the controller and Red Horizon may act as its processor. Our website and services are intended primarily for organisations and adult professional users. They are not directed at children.
03 - PERSONAL INFORMATION WE COLLECT
Information you provide:
- identity and professional information, such as your name, job title, employer and business sector;
- contact information, such as your business email address and telephone number;
- enquiry information, including messages, service interests, preferred contact method, meeting details and information you voluntarily provide about your organisation's technology, security concerns or training requirements;
- communications and records of our correspondence, calls or meetings;
- marketing preferences, where you choose to receive updates from us.
Information collected automatically:
Our hosting, security and network providers may automatically process limited technical information needed to deliver and protect the website, such as IP address, device and browser information, request timestamps, requested pages, diagnostic information, security events and server logs. We do not currently use advertising cookies or behavioural tracking on the public website.
Information from other sources:
We may receive professional contact information from a colleague who refers you, publicly available business sources, professional networking services, event organisers, suppliers or partners. We will handle it in accordance with this policy and provide additional information where required.
04 - HOW AND WHY WE USE PERSONAL INFORMATION
| Purpose | Information | Lawful Basis |
|---|---|---|
| Respond to enquiries and arrange a Cyber Risk Review | Identity, contact, professional and enquiry information | Legitimate interests in responding to business enquiries and developing our services; steps requested before entering a contract where applicable |
| Assess whether and how we can provide requested services | Identity, contact, professional, enquiry and communications information | Steps requested before entering a contract; legitimate interests in scoping and managing prospective engagements |
| Operate, secure, troubleshoot and improve the website | Technical logs, device, browser, request and security information | Legitimate interests in providing a reliable and secure website; legal obligation where applicable |
| Maintain business records and protect legal rights | Enquiry, communications, transaction and technical information | Legal obligation; legitimate interests in governance, fraud prevention, dispute resolution and the establishment, exercise or defence of legal claims |
| Send marketing communications | Identity, contact and preference information | Consent where required; otherwise legitimate interests where electronic marketing law permits |
05 - SENSITIVE AND SECURITY-RELATED INFORMATION
Please do not submit passwords, authentication secrets, exploit code, vulnerability details, special-category personal data or criminal-offence information through a general website form. If sensitive information is required for an authorised engagement or vulnerability disclosure, we will provide an appropriate secure channel and additional instructions.
If you disclose information about another person, you should ensure you are entitled to do so and, where appropriate, have made this policy available to them.
06 - SHARING PERSONAL INFORMATION
We may share personal information only where neccessary with:
- Authorised Red Horizon personnel and relevant service teams within Apex Consultancy, Quadrant IT Services or Red Horizon Cyber Academy;
- Website hosting, cloud, email, communications, CRM, scheduling, security, backup and professional-service suppliers acting under appropriate obligations;
- Professional advisers, insurers, auditors and prospective investors or purchasers where reasonably necessary and subject to confidentiality;
- Law-enforcement bodies, courts, regulators or other authorities where required by law or necessary to protect rights, security or the public;
- Another organisation as part of a merger, restructuring, acquisition or transfer of business, subject to appropriate safeguards.
We do not sell personal information.
07 - INTERNATIONAL TRANSFERS
Some suppliers may process personal information outside the United Kingdom. Where UK data-protection law requires it, we use an approved transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard. You may contact us for further information about relevant safeguards.
08 - RETENTION
We retain personal information only for as long as reasonably necessary for the purpose collected, including legal, regulatory, security, accounting and reporting requirements. Our indicative periods are:
- Unsuccessful or inactive general enquiries: normally up to 24 months after the last meaningful contact;
- Cyber Risk Review and prospective-client records: normally up to 24 months after the last meaningful contact, unless an engagement begins or a longer period is justified;
- Marketing records: until you unsubscribe or object, plus a minimal suppression record so we can respect your choice;
- Security and technical logs: normally up to 12 months, unless needed longer to investigate an incident, prevent abuse or meet legal obligations;
- Contract, financial and dispute records: for the applicable statutory limitation, tax or regulatory period, which is commonly up to six years after the relevant relationship ends.
We may retain information for longer where a legal claim, investigation, regulatory requirement or security incident requires it. We may anonymise information so it can no longer identify you and use that anonymised information indefinitely.
09 - SECURITY
We use proportionate technical and organisational measures designed to protect personal information, including access controls, least-privilege practices, secure configuration, encryption where appropriate, supplier review, logging, backup and incident-management procedures. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
10 - YOUR RIGHTS
Depending on the circumstances, UK data-protection law may give you the right to:
- Access your personal information;
- Correct inaccurate or incomplete information;
- Request deletion;
- Restrict processing;
- Object to processing based on legitimate interests or to direct marketing;
- Receive certain information in a portable format;
- Withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing;
- Ask for human review of a decision based solely on automated processing that has legal or similarly significant effects.
To exercise a right, email enquiries@redhorizoncybergroup.com. We may need to verify your identity. Rights are not absolute and exemptions may apply. We normally respond within one month, subject to lawful extensions.
11 - COMPLAINTS
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office (ICO). Current contact details are available at https://ico.org.uk/make-a-complaint/ or by calling 0303 123 1113. If you are outside the UK, you may also have the right to contact your local data-protection authority.
12 - MARKETING
You can opt out of marketing at any time by using the unsubscribe method in the message or contacting us. Service messages, responses to your enquiry and other non-marketing communications may still be sent where appropriate. We do not use information submitted through a Cyber Risk Review request to send unrelated electronic marketing unless permitted by law.
13 - THIRD-PARTY LINKS
Our website may link to third-party websites or services. Their privacy practices are outside our control, and you should read their privacy information before providing personal information.
14 - CHANGES TO THIS POLICY
We may update this policy to reflect changes in law, our website, services, suppliers or processing. We will publish the updated version with a revised effective date and, where appropriate, bring significant changes to your attention.
15 - CONTACT US
Email: enquiries@redhorizongroup.com
Post: 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF