Legal
Privacy Policy
Last updated: 21 March 2026
Who we are
This website is operated by Noel Bradford, trading as The Small Business Cybersecurity Guy (thesmallbusinesscybersecurityguy.co.uk). For the purposes of UK GDPR, Noel Bradford is the data controller.
If you have any questions about how we handle your data, please contact us.
What data we collect and why
Analytics (Google Analytics 4)
With your consent, we use Google Analytics 4 (GA4) to understand how visitors use this site. GA4 collects:
- Pages visited and time spent on each page
- Approximate geographic location (country/region level โ not precise location)
- Device type, browser, and operating system
- How you arrived at the site (search engine, direct, social media, etc.)
- A randomly assigned client ID stored in a cookie
GA4 anonymises IP addresses by default. We do not use this data to identify you as an individual. Analytics data is processed by Google LLC, which participates in the EUโUS Data Privacy Framework. You can opt out at any time by declining cookies or using Google's opt-out browser add-on.
GA4 is only activated after you give explicit consent via the cookie banner. If you decline, no analytics cookies are set and no data is sent to Google.
Contact form submissions
When you submit the contact form, your name, email address, and message are sent to us via Web3Forms, a third-party form processing service. The data is:
- Transmitted securely to our email inbox
- Used solely to respond to your enquiry
- Not stored by Web3Forms beyond the transmission
- Not shared with any third party for marketing purposes
The legal basis for processing contact form data is legitimate interests (responding to a request you have initiated).
Cookies
This site uses the following cookies:
- cookie-consent โ stored in
localStorage(not a cookie technically, but serves the same purpose). Records whether you have accepted or declined analytics. Never expires automatically; cleared when you clear site data. - _ga, _ga_* โ Google Analytics cookies set only after consent. Expire after 2 years. Used to distinguish unique visitors and sessions.
You can change your cookie preference at any time using the link.
Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Rectification of inaccurate data
- Erasure ("right to be forgotten") of your data
- Restrict how we process your data
- Object to processing based on legitimate interests
- Withdraw consent at any time (where consent is the legal basis)
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk
To exercise any of these rights, please contact us. We will respond within 30 days.
Data retention
Contact form enquiries are kept in our email inbox for as long as the correspondence is relevant, and then deleted. GA4 data is retained for 14 months within Google's systems (the minimum GA4 allows).
Third-party services
This site uses the following third-party services:
- Google Analytics 4 โ analytics (consent-gated)
- Google Fonts โ font delivery (no cookies set; connects to Google servers to load fonts)
- Web3Forms โ contact form processing
- Podbean โ podcast audio hosting (audio streams from Podbean CDN when you press play)
- DigitalOcean App Platform โ website hosting
Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top of this page will reflect any changes. Continued use of the site after changes constitutes acceptance of the updated policy.
Questions about your data? Contact us.