Privacy Policy
Last updated: 6 April 2026
1. Who we are
Cyber-Defence Ltd (trading as SOC in a Box, SOC as a Saving, and Hedgehog Security) is the data controller for personal data collected through www.socinabox.co.uk and our related services.
If you have any questions about this policy, you can contact us at hello@cyber-defence.io.
2. What data we collect
We may collect the following personal data:
- Contact information — name and email address, when you submit a support ticket or download a resource.
- Usage data — pages visited, referring URL, browser type, and device information, collected automatically through server logs.
- Communication data — the content of any messages you send us via forms or email.
3. How we use your data
We use personal data to:
- Respond to support requests and enquiries.
- Deliver resources you have requested (e.g. downloadable guides).
- Improve our website and services.
- Comply with legal obligations.
We process your data under the lawful bases of legitimate interest (operating and improving our services) and consent (where you voluntarily provide information).
4. Cookies
This website uses only essential cookies required for the site to function (e.g. session management for the blog admin area and theme preference). We do not use third-party tracking cookies or advertising cookies.
5. Data sharing
We do not sell your personal data. We may share data with trusted service providers who assist in operating our website and services, subject to appropriate data processing agreements. We will disclose data if required by law.
6. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected or as required by law. Support ticket data and download records are retained for up to 24 months, after which they are securely deleted.
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict processing of your data.
- Data portability.
- Withdraw consent at any time.
To exercise any of these rights, contact us at hello@cyber-defence.io.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
9. Third-party links
Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies.
10. Changes to this policy
We may update this policy from time to time. Any changes will be posted on this page with an updated revision date.
11. Contact & complaints
If you have concerns about how we handle your data, please contact us at hello@cyber-defence.io. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).