HEXASEC
HomeAI Assurance GateAboutContact
Request a pilot
HexaSec/Legal/Privacy
Privacy

How HexaSec handles the limited personal data you share with us.

DocumentHXS-LEGAL-PRIV·Effective21 May 2026·StatusLive
Contents
  1. Who we are
  2. What personal data we may collect
  3. Why we use it
  4. Lawful basis for processing
  5. How long we keep enquiries
  6. Who we share it with
  7. How the contact form works
  8. Cookies & analytics
  9. Your rights
  10. Contact us
  11. How to complain

— 01Who we are

This notice is published by HexaSec Ltd(“HexaSec”, “we”, “us”), a company registered in England and Wales (company number 16225807), registered office 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. We build AI assurance and cyber security tooling for sensitive, regulated and defence-aligned environments.

HexaSec is the data controller for the personal data we collect through this website and our direct communication channels. You can contact us about this notice at info@hexasec.co.uk.

— 02What personal data we may collect

We aim to collect as little personal data as possible. The data we may collect includes:

  • Contact form submissions — your name, organisation, email address, the area of interest you selected, and the message you sent.
  • Direct correspondence — email exchanges, LinkedIn messages and any documents you choose to share with us.
  • Basic server logs — IP address, browser user-agent and request timestamps, generated by our hosting provider for security and reliability purposes.

We do not knowingly collect special category data through this website. Please do not send sensitive personal information through the contact form.

— 03Why we use it

We use the personal data above to:

  • Reply to your enquiry and discuss your needs.
  • Send you pilot packs, one-pagers or technical material at your request.
  • Maintain the security, integrity and availability of this website.
  • Meet legal, accounting and audit obligations where applicable.

— 04Lawful basis for processing

Where UK GDPR applies, we rely on the following lawful bases:

  • Legitimate interests — to respond to business enquiries you have initiated, to follow up about products and services you have asked about, and to keep our website secure.
  • Consent — where you have explicitly opted in to receive specific information.
  • Legal obligation — where we are required to retain records for tax, accounting or regulatory reasons.

— 05How long we keep enquiries

We keep contact enquiries only for as long as needed to respond and follow up, and to keep a light audit trail of who has contacted us. As a guide we currently retain enquiry correspondence for up to 24 months from last contact, after which it is deleted or anonymised unless we are required to retain it for legal reasons.

— 06Who we share it with

We do not sell personal data. We share it only with carefully selected service providers acting on our instructions, including:

  • Hosting and infrastructure providers for this website.
  • Resend (resend.com) — our email delivery provider, used to route contact form submissions to our inbox.
  • Cloudflare— their Turnstile service is used for spam and bot protection on the contact form. Cloudflare may process technical data such as IP address, browser signals and interaction signals to verify that the submission is not automated, in accordance with Cloudflare's own terms and privacy notices.
  • Email, calendar and document tooling we use to communicate with you.
  • Professional advisers (legal, accounting) where strictly required.
  • Regulators or law enforcement where we are legally required to disclose.

Where any provider is based outside the UK, we rely on appropriate safeguards such as UK-approved standard contractual clauses or equivalent transfer mechanisms.

— 07How the contact form works

When you submit the contact form, the following data is collected: your name, organisation (optional), email address, the area of interest you selected, and your message.

Your submission is routed to our inbox via Resend. HexaSec does not store contact form submissions in a database — the website processes the submission and forwards it by email only. Enquiry emails may be retained in our business correspondence for a reasonable period consistent with the retention period described above.

Cloudflare Turnstile is active on the form to prevent spam and automated submissions.

There is no marketing newsletter signup on this website. Submitting the contact form does not subscribe you to any mailing list unless you have explicitly opted in through a separate mechanism.

— 08Cookies & analytics

This website does not currently set marketing or advertising cookies. We may use a minimal set of functional or first-party analytics signals to understand basic site usage. If we introduce analytics tooling that processes personal data, we will update this notice and surface a clear cookie banner.

— 09Your rights

Under UK GDPR you have the right to:

  • Ask for a copy of the personal data we hold about you.
  • Ask us to correct inaccurate personal data.
  • Ask us to delete personal data we no longer need to hold.
  • Object to certain processing or ask us to restrict it.
  • Withdraw consent at any time, where consent was the basis for processing.

To exercise any of these rights, email info@hexasec.co.uk.

— 10Contact us

For any privacy questions, including data-subject requests, please contact us at info@hexasec.co.uk. We aim to respond to privacy enquiries within two working days.

— 11How to complain

If you are not satisfied with how we have handled your personal data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concern first, so please contact us before escalating where possible.

HEXASEC

A UK-based AI and cyber security company building local-first, evidence-led tools for sensitive, regulated and defence-aligned environments.

AAG pilot programme open
Product
  • AI Assurance Gate
  • Evidence model
  • How it works
  • Request a pilot
Company
  • About
  • Principles
  • Direction
  • Contact
Contact
  • info@hexasec.co.uk
  • LinkedIn
  • X / Twitter
© 2026 HEXASEC LTD — REGISTERED IN ENGLAND & WALES
Company number: 16225807  ·  Registered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
PrivacySecurityTermsResponsible disclosure