1. Introduction and Scope
This Privacy Policy explains how YOUZSE LTD ("YOUZSE", "we", "us" or "our") collects, uses, stores, shares and otherwise processes personal data in connection with our website at youzse.fit, our professional services, and related communications. YOUZSE LTD is a company operating from 66 Paul Street, LONDON, EC2A 4NA United Kingdom, providing cybersecurity services, computer systems design, cloud computing solutions, software development, enterprise infrastructure, data processing, content delivery networks, streaming platform solutions, artificial intelligence solutions, DevOps and automation, digital platform development, web hosting services, API development, database management and related technology consultancy.
We are committed to processing personal data lawfully, fairly and transparently in accordance with the United Kingdom General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR) where applicable, and other relevant United Kingdom data protection and privacy laws. This Policy is intended to provide a clear and comprehensive statement of our practices for individuals who visit our website, enquire about our services, enter into contractual relationships with us, or otherwise interact with our business.
This Policy applies to personal data processed by YOUZSE LTD as a controller in respect of our own business operations, marketing, website administration and client relationship management. Where we process personal data on behalf of a client as a processor under a written contract, the terms of that contract and the client's own privacy notices will govern the processing in question, and this Policy should be read alongside those arrangements.
By using our website or engaging our services, you acknowledge that you have read this Privacy Policy. Where we rely on consent for specific processing activities, we will seek that consent separately and clearly. Where processing is necessary for a contract, a legal obligation, or our legitimate interests, we will explain the relevant basis in the sections below.
If you do not agree with the practices described in this Policy, you should not use our website or provide personal data to us except where provision is required by law or necessary to perform a contract you have requested.
2. Data Controller and Contact Details
The data controller responsible for the personal data described in this Policy is YOUZSE LTD, with its principal place of business at 66 Paul Street, LONDON, EC2A 4NA United Kingdom. For data protection enquiries, including requests to exercise your rights under UK GDPR and the Data Protection Act 2018, please contact us by email at tech@youzse.fit or by telephone on +44 7127 995133, or in writing to the address above.
We recommend that privacy-related correspondence is marked clearly as a data protection matter so that it can be routed promptly to the appropriate internal function. We aim to acknowledge substantive data protection requests without undue delay and to respond within the statutory timeframes set out in UK GDPR, subject to any lawful extensions where requests are complex or numerous.
Our website domain is youzse.fit. References in this Policy to "our website" mean the public-facing website operated by YOUZSE LTD at that domain and any related subdomains or microsites that expressly incorporate this Policy by reference.
If you are located outside the United Kingdom and interact with us, this Policy still describes how we process personal data under United Kingdom law. Additional local laws may apply to you, and we will take those into account where they impose additional obligations on us in relation to your data.
3. Definitions and Interpretative Principles
For the purposes of this Policy, "personal data" means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Processing" means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Special category data" means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation. YOUZSE LTD does not seek to collect special category data through its website. If such data is incidentally provided to us, we will handle it with heightened care and only where a lawful basis and a special category condition under UK GDPR Articles 6 and 9 (as retained and applied in UK law) apply.
"Controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data. "Processor" means a natural or legal person which processes personal data on behalf of the controller.
Headings in this Policy are for convenience only and do not affect interpretation. Words importing the singular include the plural and vice versa. References to legislation include that legislation as amended, extended, re-enacted or replaced from time to time, and any subordinate legislation made under it.
4. Categories of Individuals Whose Data We Process
We may process personal data relating to the following categories of individuals: visitors to youzse.fit; individuals who submit enquiries, verification requests or contact forms; prospective clients and their authorised representatives; existing clients and their employees, contractors and technical contacts; suppliers, subcontractors and professional advisers; job applicants and candidates who contact us regarding opportunities; attendees at meetings, workshops or remote verification sessions; and individuals whose personal data appears in systems, logs or documentation that we are asked to review, design, secure or operate in the course of a professional engagement.
Where we receive personal data about individuals from a corporate client (for example, names and contact details of technical stakeholders, or personal data contained within systems under assessment), we expect the client to have a lawful basis for providing that data to us and to have provided appropriate privacy information to the individuals concerned, except where an exemption applies.
We do not knowingly market to or collect personal data from children under the age of sixteen through our website. Our services are directed to businesses and professional organisations. If you believe we have inadvertently collected personal data relating to a child, please contact us at tech@youzse.fit so that we can take appropriate steps.
5. Personal Data We Collect
5.1 Identity and contact data
This may include full name, job title, employer or organisation name, business address, email address, telephone number, and preferred method of contact. We collect this data when you enquire about our services, request a verification desk response, enter into a contract, or otherwise communicate with us.
5.2 Professional and commercial data
This may include information about your organisation's technology estate, cybersecurity posture, cloud architecture, software development needs, hosting requirements, data processing activities, CDN and streaming infrastructure, AI initiatives, DevOps practices, and project objectives. Such information is typically provided by you or your organisation in the course of scoping, proposal and delivery activities. Where this information does not identify an individual, it may not constitute personal data; where it does, this Policy applies.
5.3 Technical and usage data
When you visit youzse.fit, we may collect technical data such as Internet Protocol (IP) address, browser type and version, device type, operating system, referring URL, pages viewed, time and date of visit, time spent on pages, and similar diagnostic information. Some of this data is collected through cookies and similar technologies, which are described further in our Cookie Policy available at cookie-policy.html.
5.4 Communication and correspondence data
We retain records of emails, telephone notes, meeting notes, proposals, statements of work, change requests, support tickets and related correspondence necessary to manage our relationship with you and to evidence the services provided.
5.5 Billing and financial data
Where relevant to a contract, we may process billing contact details, purchase order numbers, invoicing addresses, payment status information and related accounting records. We do not typically store full payment card details on our systems; where payments are processed by third-party providers, those providers act under their own terms and privacy notices.
5.6 Security and access data
In the course of cybersecurity, hosting, cloud, API, DevOps or platform engagements, we may process authentication identifiers, access logs, system event logs, configuration metadata, vulnerability findings, and similar operational data. Where such data relates to identifiable individuals (for example, usernames linked to employees), it is treated as personal data and handled under appropriate confidentiality and security controls.
5.7 Recruitment data
If you apply for a role or submit a curriculum vitae, we may process employment history, qualifications, skills, references and any other information you choose to provide. We will use this data solely for recruitment and related legitimate purposes unless you agree otherwise.
6. Sources of Personal Data
We collect personal data directly from you when you complete forms on youzse.fit, send email to tech@youzse.fit, call +44 7127 995133, meet with our personnel, or otherwise communicate with us. We also collect personal data automatically through website technologies as described in our Cookie Policy.
We may receive personal data from your organisation if you are designated as a contact for a project or contract. We may also receive personal data from professional advisers, subcontractors working under our direction, publicly available business sources (such as company websites or professional networking profiles used for legitimate business contact purposes), and, where lawful, from referrals by existing clients.
In service engagements involving systems design, cloud computing, software development, infrastructure, data processing, CDN, streaming platforms, AI solutions or DevOps, we may receive personal data that is already present within client systems or datasets that we are authorised to access. In such cases we act in accordance with the client contract, instructions and applicable data processing terms.
7. Purposes of Processing and Lawful Bases
Under UK GDPR, we process personal data only where a lawful basis applies. The principal purposes and corresponding bases are set out below.
7.1 Website operation and security
We process technical and usage data to operate, secure and improve youzse.fit, to prevent fraud and abuse, to diagnose faults, and to maintain the integrity of our digital presence. Lawful bases: legitimate interests (Article 6(1)(f)) in operating a secure and effective website; and, where strictly necessary for a service you request, contractual necessity (Article 6(1)(b)).
7.2 Responding to enquiries and verification requests
We process identity, contact and enquiry data to respond to requests submitted via our website or by email or telephone, to schedule discussions, and to provide information about our services. Lawful bases: legitimate interests in responding to business enquiries; and contractual necessity where the enquiry leads to steps prior to entering a contract.
7.3 Client onboarding and contract performance
We process personal data necessary to negotiate, enter into and perform contracts for cybersecurity services, computer systems design, cloud computing, software development, infrastructure, hosting, data processing, CDN, streaming platforms, AI solutions, DevOps, digital platform development and related services. This includes project management, delivery, support, reporting and invoicing. Lawful basis: contractual necessity (Article 6(1)(b)); and legitimate interests where processing relates to associated business administration.
7.4 Professional service delivery involving client systems
Where personal data is processed within client environments under our engagement, we typically act as a processor and process such data only on documented instructions. Where we determine purposes and means for any subset of processing, we will identify ourselves as controller or joint controller as appropriate. Lawful bases for controller processing: contractual necessity and legitimate interests in delivering professional services securely and effectively.
7.5 Compliance with legal obligations
We may process personal data to comply with legal, regulatory, accounting, tax, audit and law enforcement obligations applicable in the United Kingdom, including obligations under companies legislation, tax law, and data protection law itself. Lawful basis: legal obligation (Article 6(1)(c)).
7.6 Marketing and business development
Where permitted by PECR and UK GDPR, we may send business-to-business communications about our services to corporate contacts. We will respect opt-out requests. Where consent is required, we will obtain it. Lawful bases: legitimate interests in promoting our services to relevant business audiences, or consent where required.
7.7 Establishing, exercising or defending legal claims
We may process and retain personal data where necessary for the establishment, exercise or defence of legal claims, or for related insurance and risk management purposes. Lawful basis: legitimate interests (Article 6(1)(f)).
7.8 Recruitment
We process candidate data to assess suitability for roles, communicate with applicants and maintain recruitment records. Lawful bases: legitimate interests in recruiting personnel; contractual necessity for steps prior to employment contracts; and consent where we retain applications for future opportunities beyond the immediate process.
8. Legitimate Interests Assessment
Where we rely on legitimate interests, we balance our interests against your interests, fundamental rights and freedoms. Our legitimate interests include: operating a professional cybersecurity and technology services business; securing our website, systems and premises; communicating with business contacts about relevant services; improving service quality; preventing fraud and misuse; and managing commercial relationships.
We consider the nature of the data (typically business contact and professional information), the reasonable expectations of individuals interacting with a B2B technology provider, the limited sensitivity of most data we process as controller, and the safeguards we apply, including access controls, retention limits and easy opt-out for marketing.
You may object to processing based on legitimate interests. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims.
9. Cookies and Similar Technologies
Our website uses cookies and similar technologies to support essential site functions and, where applicable, analytics or preference settings. Detailed information about the cookies we use, their purposes, durations and how you can manage your preferences is set out in our Cookie Policy at cookie-policy.html. That Cookie Policy forms part of our privacy framework and should be read together with this Privacy Policy.
Where non-essential cookies require consent under PECR, we will not set those cookies until appropriate consent has been obtained. Essential cookies necessary for the operation of the website or to provide a service you have expressly requested may be used without consent where the law permits.
10. Disclosure of Personal Data to Recipients
We do not sell personal data. We may disclose personal data to the following categories of recipients where necessary and lawful:
- Service providers acting as processors on our behalf, including hosting providers, cloud infrastructure suppliers, email and collaboration platforms, customer relationship management tools, accounting and invoicing systems, and IT support providers, bound by written data processing terms where required.
- Professional advisers, including solicitors, accountants, auditors and insurers, under confidentiality obligations.
- Subcontractors and specialist consultants engaged to deliver parts of a client project, under appropriate confidentiality and data protection terms.
- Regulatory authorities, courts, law enforcement or other public bodies where required by law or necessary to protect our rights, property or safety, or that of others.
- A prospective buyer or investor in connection with a corporate transaction involving YOUZSE LTD, subject to appropriate confidentiality protections and, where required, notice to affected individuals.
- Other parties with your consent or at your direction.
Where we engage processors, we require that they process personal data only on our documented instructions, implement appropriate technical and organisational measures, and do not engage sub-processors without authorisation and equivalent protections.
International transfers are addressed in Section 11 below.
11. International Transfers
YOUZSE LTD is established in the United Kingdom. Personal data that we control is primarily processed within the United Kingdom or in jurisdictions that the United Kingdom has deemed to provide an adequate level of protection, where such adequacy regulations apply.
If we transfer personal data to a third country or international organisation that is not covered by UK adequacy regulations, we will implement an appropriate transfer mechanism under UK GDPR Chapter V, which may include the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, binding corporate rules where applicable, or another lawful mechanism. We will also assess transfer risks and apply supplementary measures where necessary.
Clients who instruct us to process data in specific regions as part of cloud, CDN, streaming or hosting architectures should ensure that such instructions are documented in the relevant contract or statement of work. We will follow documented client instructions for processor activities, subject to mandatory law.
12. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, reporting and dispute-resolution requirements. Retention periods vary according to the nature of the data and the context of processing.
As a general guide: enquiry data that does not convert into a client relationship is typically retained for up to twenty-four months unless a longer period is justified; client contract and project records are typically retained for the duration of the relationship and for up to six years thereafter to align with limitation periods for contractual claims under English law, unless a longer period is required; financial and tax records are retained in accordance with applicable UK statutory periods; website logs and technical diagnostics are retained for shorter operational periods unless needed for security investigations; recruitment records for unsuccessful candidates are typically retained for up to twelve months unless you consent to longer retention.
Where we act as a processor, retention is determined by the client's instructions and the contract. Upon termination of processor services, we will delete or return personal data in accordance with the contract, except where United Kingdom law requires storage.
When retention periods expire, we will securely delete or irreversibly anonymise personal data, unless an exemption applies.
13. Security Measures
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. Measures are selected taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to individuals.
Such measures may include: access control and least-privilege principles; authentication controls; encryption in transit and at rest where appropriate; network security controls; vulnerability management; secure software development practices for systems we build or operate; logging and monitoring; staff confidentiality obligations and awareness; physical security for premises where applicable; vendor due diligence; and incident response procedures.
Given our industry focus on cybersecurity services and infrastructure, we apply heightened professional standards to the security of systems under our control. However, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we commit to maintaining measures appropriate to the risks involved.
If we become aware of a personal data breach affecting data we control, we will assess the risk to individuals and, where required by UK GDPR, notify the Information Commissioner's Office without undue delay and, where required, notify affected individuals. Where we act as a processor, we will notify the relevant controller without undue delay after becoming aware of a breach.
14. Processing in Cybersecurity and Infrastructure Engagements
When YOUZSE LTD provides cybersecurity assessment, penetration testing coordination, security architecture, cloud design, hosting, DevOps automation, API development, database management, CDN configuration, streaming platform solutions, AI solutions or digital platform development, engagements may involve access to environments containing personal data.
Before such access, we seek clear scoping, authorisation and, where we act as processor, a data processing agreement meeting UK GDPR Article 28 requirements. Clients remain responsible for ensuring they have authority to grant access and for informing relevant individuals where required.
Findings, reports and artefacts produced in cybersecurity and infrastructure work may contain personal data (for example, usernames in logs). We treat such materials as confidential, limit internal access to personnel with a need to know, and retain them in accordance with the engagement terms and this Policy.
We do not use personal data obtained solely as a processor for our own independent purposes, including marketing, except where anonymised or aggregated in a manner that no longer constitutes personal data, or where the client expressly authorises a different use in writing.
15. Artificial Intelligence and Automated Processing
Where we design, deploy or advise on artificial intelligence solutions, we consider data protection by design and by default. If an AI system processes personal data, we will work with the client to identify purposes, lawful bases, transparency obligations, and risks of bias or inaccurate outputs affecting individuals.
YOUZSE LTD does not, as a routine practice, make solely automated decisions about individuals that produce legal or similarly significant effects within the meaning of UK GDPR Article 22 in connection with website visitors. If any such processing is introduced, we will provide meaningful information about the logic involved and the significance and envisaged consequences, and we will implement appropriate safeguards including the right to obtain human intervention.
Clients instructing AI-related work remain responsible for their own compliance obligations in respect of training data, deployment contexts and end-user transparency, except to the extent those obligations are expressly assumed by YOUZSE LTD in writing.
16. Your Rights Under UK GDPR
Subject to conditions and exemptions under UK GDPR and the Data Protection Act 2018, you have the following rights:
- Right of access: to obtain confirmation as to whether we process your personal data and, if so, access to that data and certain information about the processing.
- Right to rectification: to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure: to request deletion of personal data in certain circumstances, including where the data is no longer necessary or you withdraw consent and no other lawful basis applies.
- Right to restriction: to request that we restrict processing in certain circumstances, such as while accuracy is contested.
- Right to data portability: where processing is based on consent or contract and carried out by automated means, to receive personal data you provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible.
- Right to object: to object to processing based on legitimate interests, and to object at any time to processing for direct marketing.
- Rights related to automated decision-making: as described in Section 15.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact us at tech@youzse.fit or write to YOUZSE LTD, 66 Paul Street, LONDON, EC2A 4NA United Kingdom. We may need to verify your identity before fulfilling a request. We will respond within one month of receipt, extendable by two further months where necessary taking into account complexity and number of requests, in which case we will inform you of the extension and reasons.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Further information is available from the ICO. We would appreciate the opportunity to address your concerns before you approach the ICO.
17. Third-Party Websites and Services
Our website may contain links to third-party websites, platforms or resources. Those third parties operate under their own privacy practices. YOUZSE LTD is not responsible for the content or privacy practices of third-party sites. We encourage you to read the privacy notices of any third-party services you use.
If our services integrate with third-party APIs, cloud platforms, CDN providers, streaming vendors or AI tools at a client's instruction, the processing of personal data by those third parties will be governed by the client's relationship with those providers and any applicable data processing terms.
18. Confidentiality and Professional Obligations
In addition to data protection obligations, YOUZSE LTD observes professional confidentiality in respect of client information obtained during engagements. Personnel and subcontractors are subject to confidentiality duties. These obligations complement, and do not replace, the requirements of UK GDPR and the Data Protection Act 2018.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, our services or our processing activities. The updated version will be published on youzse.fit with a revised effective date. Material changes will be highlighted on the website or communicated to active clients where appropriate. We encourage you to review this Policy periodically.
Continued use of our website after changes take effect constitutes acknowledgement of the updated Policy, except where consent is required for a new processing activity, in which case we will seek consent as required by law.
20. Governing Law and Further Information
This Privacy Policy is governed by the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction over disputes arising out of or in connection with this Policy, without prejudice to any mandatory rights you may have under applicable consumer or data protection law.
For questions about this Privacy Policy, our processing of personal data, or to exercise your rights, please contact YOUZSE LTD at tech@youzse.fit, telephone +44 7127 995133, or by post at 66 Paul Street, LONDON, EC2A 4NA United Kingdom. Further information about our services is available on our website at youzse.fit and on related pages including about.html, services.html, portfolio.html and contact.html.
This Privacy Policy should be read together with our Cookie Policy, Terms of Service and Terms and Conditions, available via the legal navigation on this page.
21. Detailed Processing Activities by Service Line
21.1 Cybersecurity services
In cybersecurity engagements we may process contact data of security stakeholders, system identifiers linked to users, vulnerability reports containing usernames or email addresses, incident timelines, and evidence artefacts. Purposes include assessment, remediation planning, reporting and follow-up verification. Lawful bases include contractual necessity and legitimate interests in delivering secure professional services. Retention follows project and limitation periods described above.
21.2 Cloud computing and infrastructure
Cloud and infrastructure projects may involve processing of administrator identities, access keys metadata (but not unnecessary secret material), configuration inventories, monitoring alerts linked to operators, and change-management records. We process such data to design, migrate, operate or harden environments under client instruction. Clients should minimise personal data in non-production datasets shared with us.
21.3 Software development and API services
Software and API development may involve processing of developer contact details, repository collaborator identities, issue tracker comments, user acceptance testing feedback, and production support identities. Where application user personal data is processed in test or production, we follow processor instructions and environment segregation practices.
21.4 Data processing and database management
Data processing and database engagements may involve schemas, sample records, migration logs and query performance data that include personal data. We apply need-to-know access, environment controls and agreed deletion of temporary extracts. Clients remain controllers of source datasets unless otherwise agreed in writing.
21.5 CDN and streaming platforms
CDN and streaming work may involve processing of viewer or subscriber identifiers present in logs, geolocation approximations derived from IP addresses, content access records and edge configuration contacts. Processing is limited to delivery optimisation, security (including abuse mitigation) and operational reporting as scoped.
21.6 Artificial intelligence solutions
AI engagements may involve processing of training or evaluation datasets supplied by the client, prompt logs, model output samples and operator identities. We do not use client personal data to train independent YOUZSE models unless expressly agreed. Data protection impact assessments may be recommended for high-risk AI processing.
21.7 DevOps, automation and digital platforms
DevOps and platform work may process CI/CD user identities, deployment approvals, runbook ownership records and operational chat or ticket data. Such processing supports reliable release management, incident response and continuous improvement under the engagement terms.
21.8 Web hosting services
Hosting services may involve processing of account holder details, authorised user lists, support tickets, billing contacts and server logs. We process this data to provide, secure and support the hosting service and to meet legal obligations.
22. Record Keeping, Accountability and Governance
YOUZSE LTD maintains records of processing activities as required by UK GDPR Article 30 where applicable to our organisation. We implement data protection by design and by default when determining means of processing and when designing systems for ourselves or for clients where we influence design decisions.
We provide appropriate training and guidance to personnel who handle personal data. We conduct vendor assessments for processors that handle personal data on our behalf. We review this Policy and related procedures periodically to ensure ongoing compliance and effectiveness.
Where a processing activity is likely to result in a high risk to the rights and freedoms of individuals, we will carry out a data protection impact assessment and consult the ICO where required by law.
Accountability is a core principle of UK GDPR. We are prepared to demonstrate compliance through documentation, contracts, policies, technical measures and responses to regulatory or individual requests.
23. Marketing Preferences and Electronic Communications
If you are a corporate contact and we send electronic marketing about YOUZSE LTD services, you may opt out at any time by contacting tech@youzse.fit or using any unsubscribe mechanism provided in the communication. We will honour opt-out requests promptly.
We distinguish service messages (such as contract, billing, security or project notices) from marketing. Service messages necessary to perform a contract or provide requested information may continue even if you opt out of marketing.
Telephone contact for marketing purposes will comply with PECR and any applicable Telephone Preference Service rules. If you prefer not to receive marketing calls, please tell us and we will record your preference.
24. Accuracy and Your Responsibilities
We take reasonable steps to keep personal data accurate and up to date. Please notify us of changes to your contact details or other personal data you have provided. If you provide personal data about another person, you must ensure you have the authority to do so and that the individual has been provided with appropriate privacy information where required.
Clients must ensure that instructions given to YOUZSE LTD as a processor are lawful and that datasets shared with us do not contain unnecessary special category data or other high-risk data unless expressly agreed and appropriately protected.
