Privacy Notice
Last updated: 27 July 2026
1. Who we are
Samaryam Tech Ltd is a cyber security consultancy providing services to businesses and other organisations.
Samaryam Tech Ltd is a UK Limited Company registered in Scotland under company number SC887438.
Registered office:
Office 1605,
3 Fitzroy Place,
Glasgow
Email: contact@samaryam.co.uk
Telephone: +44 (0)141 474 9012
For data protection purposes, Samaryam Tech Ltd is the controller of the personal information described in this Privacy Notice.
References to “Samaryam Tech”, “we”, “us” or “our” mean Samaryam Tech Ltd.
2. Who this notice applies to
This Privacy Notice applies to personal information relating to:
visitors to our website;
people who contact us or make an enquiry;
prospective and existing clients;
client employees and representatives;
suppliers and professional advisers;
business partners and professional contacts; and
other people who communicate with us.
Where we process personal information solely on behalf of a client while delivering an agreed service, the client may be the controller and Samaryam Tech may act as its processor. That processing will be governed by the relevant client agreement and any applicable data-processing terms.
3. Personal information we collect
The information we collect depends on how you interact with us.
It may include:
your name;
your job title and organisation;
your business or correspondence address;
your email address and telephone number;
information contained in an enquiry or email;
records of meetings, calls and correspondence;
information needed to prepare a quotation or proposal;
information required to deliver an agreed service;
contract and invoicing information;
payment and transaction records;
feedback, complaints and information-rights requests;
your communication preferences; and
technical information generated when you use our website.
We do not currently collect payment-card information through our website.
Please do not send highly sensitive personal information, passwords, credentials or security-critical information through ordinary email unless we have agreed an appropriate method for sending it securely.
4. How we collect personal information
We may collect personal information:
directly from you when you contact us;
through email correspondence;
during meetings or Microsoft Teams calls;
when preparing or delivering services;
from your employer or organisation;
through a professional introduction or referral;
at networking events or professional meetings;
from publicly available business sources, such as company websites or professional directories; and
automatically when you visit our website.
We will only use information obtained from another source where we have a lawful reason to do so and the use is reasonable and proportionate.
5. Why we use your information
We use personal information to operate our business, respond to enquiries and provide our services. This includes replying to requests for information, arranging introductory meetings, preparing quotations, proposals and Statements of Work, managing client relationships, delivering agreed services and communicating with client representatives. Where these activities relate to a potential or existing engagement, we normally rely on taking steps before entering into a contract, performing a contract or our legitimate interests in responding to enquiries and managing professional relationships.
We also use personal information to issue and manage invoices, process payments, maintain financial and business records, work with suppliers and professional advisers, protect our website, systems and information, prevent fraud or misuse, manage complaints and legal claims, improve our services and meet legal, regulatory, insurance and professional obligations. Depending on the circumstances, we rely on our contractual obligations, legal obligations or legitimate interests.
Our legitimate interests include operating and protecting our business, responding to prospective clients, delivering professional services, maintaining client and supplier relationships, preventing misuse and improving our services. Where we rely on legitimate interests, we consider whether the use of your information is necessary and proportionate and whether your rights and interests override our own.
6. Email enquiries
Our website may provide an email link allowing you to contact us directly.
When you email us, we may collect:
your name;
your email address;
your organisation and job title;
your telephone number, where provided; and
any other information included in your message.
We use this information to respond to your enquiry, discuss your requirements and, where appropriate, prepare a proposal or take steps towards entering into a contract.
Sending us an enquiry does not create a contract between you and Samaryam Tech.
7. Website analytics and cookies
Our website is hosted by Squarespace.
Squarespace may use necessary cookies and similar technologies to operate, secure and display the website. Necessary cookies may support functions such as website security, fraud prevention, error detection and remembering privacy preferences.
We also use Squarespace Analytics to understand how visitors use our website. Squarespace Analytics may provide information such as:
pages viewed;
approximate geographical area;
website traffic sources;
browser and device information;
visit dates and times;
new and returning visitor numbers; and
general website activity.
We use this information to understand website performance, identify useful content and improve the visitor experience. We do not use website analytics information for targeted advertising.
Squarespace confirms that its analytics platform provides reports including page views, visitor behaviour, traffic sources and other website-performance information.
Where consent is required, optional analytics cookies will be restricted until you have made a choice through our cookie banner. You may accept or reject optional cookies and change your preferences through the Cookie Settings link on our website.
Squarespace provides controls that allow non-essential cookies to be restricted through its cookie and privacy settings.
Cookie consent must be freely given, informed and indicated through a positive action. Merely mentioning cookies in a Privacy Notice is not sufficient where consent is legally required.
8. Meetings and cloud storage
We expect to use Microsoft 365 services, including:
Microsoft Teams for online meetings; and
OneDrive for storing and managing business documents.
When you attend a Microsoft Teams meeting, Microsoft may process information such as:
your name and contact details;
meeting attendance information;
technical connection information; and
messages or files shared during the meeting.
Documents associated with enquiries, proposals, services and client relationships may be stored within OneDrive.
Microsoft provides contractual privacy and data-protection commitments for its commercial cloud services.
9. Invoices and payments
Where you purchase services from us, we may collect and retain:
your name and organisation;
billing and correspondence addresses;
contact information;
quotation and contract information;
invoice details;
amounts charged and paid;
payment dates;
bank transaction references; and
records relating to overdue or disputed payments.
Invoices may be issued electronically or on paper.
Payments are currently made directly by bank transfer. We do not collect or store payment-card details through our website.
Banks involved in processing a payment will receive the information required to complete and record the transaction.
Financial and transaction records will normally be retained for up to six years where required for tax, accounting or legal purposes. UK government guidance requires relevant company tax and accounting records to be retained for specified periods and, in many circumstances, for six years.
10. Who we share information with
Where reasonably necessary, we may share personal information with:
Squarespace, as our website and analytics provider;
Microsoft, through Microsoft Teams, OneDrive and related Microsoft 365 services;
our email and telecommunications providers;
our bank and other financial-service providers;
accountants, insurers, solicitors and other professional advisers;
consultants, associates or delivery partners involved in an agreed engagement;
IT and cyber security service providers;
organisations involved in recovering unpaid debts;
regulators, courts, law-enforcement agencies or public authorities where legally required; and
advisers or potential purchasers involved in a sale, investment or restructuring of the business.
We only share information that is reasonably necessary for the relevant purpose.
Service providers acting on our behalf must handle personal information appropriately and in accordance with the applicable contractual and legal requirements.
We do not sell personal information.
11. International transfers
Some of our technology providers may process or store information outside the United Kingdom.
Where this involves a restricted international transfer, we will use an appropriate safeguard required by UK data protection law. This may include:
transferring information to a country covered by UK adequacy regulations;
using approved contractual safeguards; or
relying on another legally recognised transfer mechanism.
Further information about the safeguards used for a particular service may be requested by emailing contact@samaryam.co.uk.
12. How long we retain information
We retain personal information only for as long as it is reasonably required.
Our normal retention periods are:
general enquiries that do not lead to work: up to 18 months after the last meaningful contact;
unsuccessful quotations and proposals: up to two years after they expire or are declined;
client contracts and service records: normally up to six years after the relationship ends;
invoices, transaction information and accounting records: normally up to six years;
routine business correspondence: for as long as it remains relevant;
website analytics information: according to our provider settings and operational requirements;
website and security logs: normally up to 12 months, unless required for an investigation;
complaints and data protection records: normally up to three years after closure; and
information required for legal proceedings: until the matter and any applicable limitation period have concluded.
Information may be kept for longer where necessary to comply with a legal obligation, respond to a regulatory enquiry, meet insurance requirements or establish or defend a legal claim.
13. How we protect your information
We use proportionate technical and organisational measures intended to protect personal information from:
unauthorised access;
accidental loss;
alteration;
inappropriate disclosure;
misuse; or
destruction.
These measures may include:
access controls;
multi-factor authentication;
secure business devices and systems;
encryption where appropriate;
backups and recovery arrangements;
restricted document sharing;
supplier due diligence;
confidentiality requirements; and
secure deletion or disposal.
No electronic transmission or storage system can be guaranteed to be completely secure.
Please contact us before sending particularly sensitive or security-critical information so that an appropriate transfer method can be agreed.
14. Marketing communications
We do not currently operate an email newsletter or routinely send promotional or direct-marketing emails.
We may contact you in connection with:
an enquiry you have made;
a proposal or existing engagement;
an ongoing business relationship;
an agreed follow-up; or
another relevant professional matter.
If we introduce newsletters or broader direct-marketing activity in the future, we will update this Privacy Notice and provide an appropriate way to unsubscribe or object.
You may ask us not to send you marketing communications at any time by emailing contact@samaryam.co.uk.
15. Your data protection rights
Depending on the circumstances, you may have the right to:
request access to your personal information;
ask us to correct inaccurate or incomplete information;
ask us to erase your information;
ask us to restrict how your information is used;
object to particular uses of your information;
receive certain information in a portable format;
withdraw consent where we rely on consent; and
complain about how your personal information has been handled.
These rights are not absolute. We may sometimes need to retain or continue using information to comply with a legal obligation or establish, exercise or defend a legal claim.
To exercise a right, email contact@samaryam.co.uk.
We may request reasonable information to confirm your identity before responding.
We do not currently use personal information to make decisions based solely on automated processing that have legal or similarly significant effects.
16. Data protection complaints
Questions or complaints about our use of personal information should be sent to: contact@samaryam.co.uk
Please include enough information for us to understand and investigate your concern.
We will:
provide a clear way to raise a complaint;
acknowledge a data protection complaint within 30 days;
investigate it appropriately;
keep you informed where necessary; and
communicate the outcome.
UK organisations are now required to provide a complaints process, acknowledge data protection complaints within 30 days, investigate them and communicate the outcome.
You also have the right to complain to the Information Commissioner’s Office, the UK regulator for data protection.
The ICO generally recommends contacting the organisation first so that it has an opportunity to investigate and respond.
17. Changes to this Privacy Notice
We may update this Privacy Notice where our:
services change;
website functionality changes;
suppliers or systems change;
marketing activity changes; or
legal and regulatory obligations change.
The latest version will be published on our website with its revision date.
We will review this notice regularly and update it before introducing material new uses of personal information, such as a newsletter, online booking platform, payment processor or additional analytics technology.