Privacy Policy
Version 1.0 · Last updated 26 August 2026
djinn six ltd
Company number: 16614427
Registered office: 66 Paul Street, London, England, EC2A 4NA
ICO registration: ZC021402
Data protection contact: compliance@djinnsix.com
1. Who we are
djinn six ltd ("djinn six", "we", "us") is a cybersecurity consultancy registered in England and Wales. We are the controller of the personal data described in this policy. This policy explains what personal data we collect through our website and in the course of providing our services, why we collect it and what rights you have.
Questions about this policy or our use of your data should be sent to compliance@djinnsix.com.
2. Personal data we collect
Website enquiries. When you contact us through the forms on our website we collect the details you provide, typically your name, business email address, company name and the content of your message.
Marketing and correspondence. If you subscribe to updates or correspond with us we collect your contact details and a record of the correspondence, including whether you open or click our emails. Privacy preferences you record, such as a do-not-sell opt-out or an unsubscribe, are also stored against your contact record so they can be honoured.
Clients and prospective clients. In the course of scoping and delivering engagements we collect business contact details of client personnel, records of meetings and correspondence and information needed for invoicing and credit control.
Technical data. When you visit our website we collect limited technical data such as IP address, browser type and pages visited. Aggregated, cookieless usage statistics are collected through Umami analytics with your consent, and marketing tracking operates through ActiveCampaign with your consent, as described in our cookie policy.
Service data. Deliverables and findings may incidentally contain personal data present in the systems or materials a client provides to us. We process such data on the client's instructions; where we do so as a processor the client's engagement terms govern that processing and this policy does not apply to it.
We do not knowingly collect personal data from children and our website and services are directed at businesses.
3. How we use personal data and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and providing quotes | Legitimate interests (responding to a business enquiry you made) |
| Delivering engagements, including sharing with associates under our terms | Performance of a contract, or legitimate interests where the contract is with your employer |
| Invoicing, credit control and recovering debts | Performance of a contract and legitimate interests |
| Sending marketing about our services to business contacts | Legitimate interests, or consent where required; every message includes an unsubscribe link |
| Operating, securing and improving our website | Legitimate interests, and consent for non-essential cookies |
| Complying with legal obligations, including tax and accounting | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
| Recording and honouring your privacy preferences, including a do-not-sell opt-out stored against your contact record | Legal obligation where a privacy law requires it, otherwise legitimate interests in reliably honouring your stated preference |
We do not currently sell personal information. You can record a standing opt-out from any future sale or sharing at any time through the do-not-sell control in our cookie preferences. If you share your details with us while that opt-out is on, the opt-out itself is stored against your contact record in our customer relationship management platform so it can be honoured across devices and if our position ever changes. You can also record an opt-out by emailing contact@djinnsix.com. Only an explicit opt-out is recorded; the absence of a signal is never treated as consent. We do not use personal data for automated decision-making that produces legal or similarly significant effects.
4. Who we share personal data with
We share personal data only as needed:
- Service providers. Suppliers who host our website, provide email, document storage, website analytics (currently Umami, which is cookieless) and our customer relationship management platform (currently ActiveCampaign) and other business tools, each acting on our instructions under contract.
- Associates. Trusted associates and subcontractors who help deliver engagements, bound by written confidentiality and data protection obligations.
- Professional advisers. Accountants, insurers, solicitors and debt recovery agents where needed.
- Authorities. Regulators, courts and law enforcement where disclosure is required by law.
We do not share personal data with third parties for their own marketing.
5. International transfers
Some of our service providers, including ActiveCampaign, process data outside the UK, including in the United States. Where personal data leaves the UK we ensure an adequate level of protection through UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the provider's own safeguards. Details of the safeguards for a specific transfer are available on request.
6. How long we keep personal data
We keep personal data only as long as needed for the purposes above:
- Enquiries that do not become engagements: 24 months from last contact.
- Client engagement records and deliverables: 6 years from the end of the engagement, reflecting limitation periods.
- Accounting and tax records: 6 years from the end of the financial year to which they relate, as required by tax law.
- Marketing contacts: until you unsubscribe or 24 months of inactivity, whichever is sooner. Unsubscribe requests themselves are kept on a suppression list so they are honoured.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, least-privilege administration and vetting of the suppliers and associates we share data with. No system is completely secure and transmission over the internet is at your own risk, though we work to protect data once received.
8. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected and incomplete data completed;
- have your data erased in certain circumstances;
- restrict or object to processing, including an absolute right to object to direct marketing;
- receive data you provided to us in a portable format in certain circumstances;
- withdraw consent at any time where processing is based on consent.
To exercise any right contact compliance@djinnsix.com. We respond within one month. We may need to verify your identity first.
If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would welcome the chance to address your concern first.
9. Cookies
Our website uses cookies and similar technologies. These are described in our cookie policy, which also explains how to give, refuse and withdraw consent.
10. Changes to this policy
We may update this policy from time to time. The current version is always available on our website with its last updated date. Material changes affecting how we use your data will be notified where practicable.
