Privacy policy
Last updated 10 October 2026
Who is responsible for your information?
Hyrarx Ltd (company number 17195667, registered in England and Wales) is the controller of personal information used to operate this website and respond to enquiries.
For privacy questions or to exercise your rights, email kasimali@hyrarx.com.
This notice covers visitors to this website and people who contact us through the email address published here. UK data protection law applies to our processing. The EU GDPR also applies where our activities fall within its scope.
What information is used, and why?
Visiting the website
When your browser requests a page, our hosting and security provider, Cloudflare, processes technical information. This can include your IP address, the page requested, the time of the request, your browser and device information, and security signals.
This information is used to deliver pages, maintain reliable service, diagnose faults and protect the website against malicious traffic. Our lawful basis is legitimate interests: providing a working, secure website and protecting visitors and our business. We limit the use of information to what is necessary for those purposes.
Contacting us by email
If you choose to email us, we receive your email address, any name you provide, the contents of your message and any attachments. We use that information to respond to you and manage the enquiry. Our lawful basis is legitimate interests in communicating with people who contact us. Where your enquiry asks us to take steps towards a contract with you, the relevant basis is taking those steps at your request. Where we must retain information to meet a legal duty, we rely on that legal obligation.
You do not have to email us or provide a name to browse the website. We need a working reply address and sufficient information to respond to an email enquiry. Please avoid sending health information or other sensitive personal information that is unnecessary for your enquiry.
Cookies, tracking and automated decisions
This website does not include advertising, analytics tools, tracking pixels, contact forms, user accounts or third-party embeds. Its own code does not set cookies or use browser storage. Pointer and touch positions are used temporarily on your device to render the interactive logo, eclipse and subtle background sheen; they are not logged, saved or transmitted. Cloudflare may use security cookies when its protection features require them; see our cookie policy.
We do not use visitor information for marketing profiles or automated decisions that produce legal or similarly significant effects. Automated security checks may be used by the hosting provider to identify and block malicious traffic.
Who receives the information?
Access is limited to people who need it to handle enquiries or operate the website, and service providers supporting those activities. These include Cloudflare for hosting and security, and our email provider if you contact us by email. Providers may use authorised subprocessors to deliver their services.
We may disclose relevant information to professional advisers or public authorities where necessary to meet a legal obligation, establish or defend legal rights, or address a security incident. We do not sell your personal information.
For information about Cloudflare’s processing, see its privacy policy.
Processing outside the UK or EEA
Cloudflare operates a global network. Technical information may be processed in countries outside the UK or European Economic Area, including the United States. When a transfer requires protection under applicable data protection law, the appropriate mechanism is an applicable adequacy decision or approved contractual safeguards, with additional measures where needed.
Cloudflare’s data processing addendum describes its contractual transfer arrangements, including EU Standard Contractual Clauses and the UK Addendum where applicable. You can ask us for details of the safeguards relevant to your information at kasimali@hyrarx.com.
How long is information kept?
We keep enquiry correspondence only for as long as it is needed to respond, complete any follow-up and maintain a necessary record of the exchange. The period depends on whether the enquiry is ongoing, whether it leads to an agreement, and any legal record-keeping requirement or unresolved dispute. When it is no longer needed, it is deleted.
Technical records processed by Cloudflare follow the retention periods associated with the relevant hosting and security service. Their retention is determined by the type of record, the service in use, and the need to provide security, resolve incidents or meet legal obligations. We do not operate a separate visitor database or enable website analytics as part of this website.
Your right to object
You can object to our use of your personal information where we rely on legitimate interests. Email kasimali@hyrarx.com and explain your request. We will stop the relevant processing unless we have compelling legitimate grounds that override your interests, rights and freedoms, or need the information for legal claims.
Your other data protection rights
Depending on the circumstances and applicable law, you can ask to access your information, correct inaccurate information, erase it, restrict its use, or receive information you have provided in a portable format where the portability conditions are met. Where processing relies on consent, you can withdraw that consent at any time without affecting earlier lawful processing. The website activities described above do not rely on consent.
Send requests to kasimali@hyrarx.com. We may need reasonable information to verify your identity. We normally respond within one month. A lawful extension may apply to complex or multiple requests, and we will tell you if this is necessary. Rights are subject to the conditions and exceptions in applicable law.
Complaints
You can raise a concern with us using the email address above. You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint or telephone 0303 123 1113.
If the EU GDPR applies, you may lodge a complaint with a supervisory authority in the EU, particularly in the country where you live or work, or where the alleged infringement occurred. The European Data Protection Board lists these authorities.
Updates to this notice
We may update this notice when the website or our processing changes. The date at the top identifies the current version. Any new purpose for processing will be explained before that processing begins where the law requires it.