Home/Privacy Policy
Legal
Privacy Policy
How Cybernalyst collects, uses and protects personal data — on this website, through our onboarding process, and in the security services we operate. Written to be read, not to be scrolled past.
Last updated 29 August 2026/Applies to cybernalyst.com
On this page
Who is responsible for your data
This website is operated by Cybernalyst, the cyber security, data analytics and forensics division of Definitive Concept Ltd, a company incorporated in Mauritius. Definitive Concept Ltd is the data controller for the personal data described in this notice, except where we are handling data inside a client's own systems — see section 06.
- Business registration number C16139207 (company number 139207, VAT 27442782)
- Registered address 15 Issackhan Street, Coromandel, Mauritius
- Data protection contact hello@definitiveconcept.com or +230 5251 8311
What we collect, and where it comes from
We collect what we need to answer you, to scope work properly, and to run the services you have asked us to run. Nothing on this site profiles you or follows you around the web.
| Source | What it contains |
|---|---|
| Enquiry form | Name, organisation, work email, phone (optional), sector, what you need, your message, and the record of your consent. |
| Onboarding form | Organisation details (registered and trading name, business registration and VAT numbers, billing address, sector, headcount); named primary and technical contacts with role, email and phone; environment details (user accounts, servers, sites, current endpoint protection, current backup arrangement, incumbent IT provider); Microsoft 365 tenant domain, licensing and seat counts; regulatory obligations, timelines and free-text notes; and the record of your two consents. |
| Incident line | Whatever you tell us when you call, and the number you call from. |
| Client portal | The credentials we issue to named individuals, and sign-in records. |
| Server and firewall logs | IP address, browser user agent, requested URL and timestamp. Generated automatically and kept for security, not for analytics. |
| Direct correspondence | Email, calls and meeting notes over the course of a relationship. |
Please do not send special category data through these forms. Health data, biometric data, records of criminal offences and similar material need a channel built for them. If an engagement requires it, ask us and we will set one up before you send anything.
Why we process it, and on what basis
Every purpose below maps to a lawful basis in section 28 of the Data Protection Act 2017.
| Purpose | Lawful basis |
|---|---|
| Replying to an enquiry | Your consent, and steps taken at your request before entering a contract |
| Scoping, quoting and onboarding | Steps taken at your request before entering a contract |
| Delivering the services you have contracted | Performance of a contract |
| Placing Acronis, Microsoft 365 and hardware orders on your behalf | Performance of a contract |
| Keeping this website and our own systems secure | Our legitimate interests in defending the systems we operate |
| Invoicing, accounting, tax and statutory records | Compliance with a legal obligation |
| Sending advisories and service notices to clients | Our legitimate interests; you can opt out at any time |
We do not sell personal data, we do not share it for anyone else's marketing, and we do not make automated decisions about you that produce legal effects.
Cookies and what this site loads
This site carries no analytics, advertising or tracking cookies. It sets cookies only where a function needs them — signing in to the client portal, or remembering a preference while you are on the site. Two things do reach outside our servers, and it is fair that you know about them:
- Typefaces are served by Google Fonts. Your browser requests them from
fonts.googleapis.comandfonts.gstatic.com, which means Google receives your IP address as part of that request. - Static assets are served through our hosting provider's content delivery network, and request metadata is inspected by our web application firewall so it can block attacks before they reach the site.
Who we share it with
We do not sell or rent personal data. We share it only with the parties we need to in order to do the job:
- Our hosting and email providers, which store the site and carry our correspondence.
- Our web application firewall provider, which inspects traffic to this site.
- Acronis, where you are licensed or protected on Acronis Cyber Protect Cloud.
- Microsoft and our Microsoft distribution channel, where we place licences or hardware for you.
- Professional advisers — accountants, auditors, insurers and lawyers — under professional confidentiality.
- A regulator, court or law-enforcement authority, where we are legally required to. We will tell you unless we are prohibited from doing so.
Each of these is bound by contract to process personal data only on our instructions and to protect it to a standard at least equal to our own.
Client data we handle as a processor
This is the part most privacy notices skip, and it matters most here. Running managed protection, backup, disaster recovery, forensics or analytics means we handle data that lives inside your systems — mailboxes, endpoints, event logs, backup sets, forensic images. That data very often contains personal data about your staff, your customers and third parties.
For that data you remain the controller and we act as your processor. What we may do with it, who may touch it, where it is stored and when it is destroyed are set by the written agreement and data processing terms between us — not by this notice. Forensic and investigative material is handled under separate evidence-handling terms, because its chain of custody may have to stand up in front of a court.
Transfers outside Mauritius
Some of the providers above operate outside Mauritius. Where personal data leaves the country we rely on one or more of the grounds in section 36 of the Data Protection Act 2017: appropriate contractual safeguards with the receiving party, necessity for the performance of a contract with you, or your explicit and informed consent. We remain responsible for how our processors handle your data wherever they hold it.
How long we keep it
We keep personal data only as long as it is doing work. Our standard periods are:
- Enquiries that do not lead to an engagement — 24 months from the last contact, so we can pick up a conversation where it stopped.
- Onboarding submissions that do not lead to an engagement — 12 months from submission.
- Client records — for the term of the engagement and then seven years, to meet company and tax record-keeping requirements in Mauritius.
- Forensic and investigative material — under the retention and disposal schedule set in the engagement, which may be dictated by litigation or a regulator rather than by us.
- Website server and firewall logs — 12 months.
At the end of a period the data is deleted or irreversibly anonymised. Where a legal hold, a live dispute or a regulator's instruction requires us to keep something longer, we keep only what that requires.
How we protect it
We sell security, so it would be poor form to run our own house loosely. Among other controls:
- Multi-factor authentication on administrative access, least-privilege roles, and periodic review of who holds what.
- Encryption in transit across the site and our platforms; encryption at rest for backups and forensic stores.
- Immutable backups, so a record cannot be silently altered or erased.
- A web application firewall and managed patching on this website itself.
- Confidentiality obligations on every member of staff and every subcontractor, surviving the end of their engagement.
No system is perfectly secure and we will not claim otherwise. What we commit to is holding our own environment to the standard we ask our clients to meet.
Your rights
Under sections 37 to 41 of the Data Protection Act 2017 you have the right to ask us for:
- Access — confirmation of whether we hold data about you, and a copy of it.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion where the data is no longer necessary or the processing was unlawful.
- Restriction — a pause on processing while something is disputed or under investigation.
- Objection — to processing based on legitimate interests, and to direct marketing at any time.
- Withdrawal of consent — at any time, without affecting processing already carried out lawfully.
To exercise any of these, email hello@definitiveconcept.com. We respond within one month. If a request is complex we may extend that by a further month, and we will tell you before the first month is out. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity first — that check protects you, not us.
Where we hold the data as a processor for one of our clients, we will pass your request to that client and support them in answering it, because the decision is theirs to make.
If something goes wrong
Where a personal data breach occurs we notify the Data Protection Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, as sections 25 and 26 of the Act require. Where a breach is likely to result in a high risk to the people affected, we tell them directly as well — plainly, and without waiting for the investigation to close.
Complaints
If you are unhappy with how we have handled your data, tell us first at hello@definitiveconcept.com — we would rather fix it than have you chase us. You also have the right to complain to the supervisory authority at any time:
- Data Protection Office, Mauritius
- Email dpo@govmu.org
- Telephone +230 460 0251
- Web dataprotection.govmu.org
Changes to this notice
We update this notice when what we do with data changes. The date at the top of the page is the date of the current version. Where a change materially affects you we will say so on the site rather than quietly reissuing the page. This version takes effect on 29 August 2026.