FARORBIS LTD trench-section mark
FARORBIS LTD CTX.LEGAL
HORIZON LEGAL / OPEN Recover the context

This Privacy Policy explains how FARORBIS LTD collects, uses, stores, discloses and otherwise processes personal data in connection with the website at https://farorbis.social and in connection with professional services supplied from the United Kingdom. FARORBIS LTD is a company operating from 27 Old Gloucester Street, LONDON, WC1N 3AX United Kingdom. For privacy correspondence the contact address is inquiry@farorbis.social and the telephone number is +44 7284 556677. This Policy is written for a serious commercial audience and is intended to be read with our Cookie Policy, Terms of Service and Terms and Conditions. It is not a privacy notice for a consumer social network, a public archive, or an academic research repository.

FARORBIS LTD acts as a controller for personal data processed to operate this website, to respond to context requests, to administer contracts, to keep statutory records, and to protect the security of our systems. Where we process personal data solely on documented instructions of a client in the course of Cybersecurity Solutions, Cloud Computing Solutions, Digital Platform Development, Custom Computer Programming Services, Data Analytics Services or related professional work, we act as a processor in respect of that client dataset. The distinction matters. Website enquiries, billing contacts and our own staff records are controller processing. Client production data, log extracts, identity inventories and similar engagement materials are processor processing except where law requires us to retain independent records.

1. Who we are and the law that applies

FARORBIS LTD is established in the United Kingdom. The principal data protection laws that apply to our processing are the United Kingdom General Data Protection Regulation as retained and amended in UK law, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 as amended, and any successor legislation. Where a client is established in the European Economic Area and a transfer or processor relationship so requires, we will also have regard to the EU General Data Protection Regulation to the extent it applies to that relationship. We do not rely on informal foreign privacy codes in place of UK law.

Supervisory authority for our UK establishment is the Information Commissioner's Office. Data subjects who believe we have infringed their rights may lodge a complaint with the ICO, though we ask that they first write to inquiry@farorbis.social so that we can locate the relevant context unit and respond with a recorded interpretation rather than a fragmented reply. The ICO's published contact channels are independent of this Policy and may change; we do not reproduce them as if they were our own.

This Policy applies to visitors to https://farorbis.social, to persons who submit a context request note, to representatives of actual or prospective clients, to suppliers and professional advisers, to applicants for engagement, and to any other natural person whose data we process in the ordinary course of Computer Systems Design and Related Services, Professional Scientific and Technical Services, Computer Related Consulting Services and allied activities named on this site. It does not apply to third-party websites linked from our pages. It does not apply to processing carried out by a client on systems we have merely advised upon.

2. Categories of personal data

We process identity and contact data such as name, job title, organisation, email address, telephone number and postal address, including the address you may supply in a context request. We process professional context such as the horizon of systems you describe, the industry sector, and the fact that you approached a cybersecurity and digital platform practice in London. We process communications content contained in messages, attachments you choose to send, call notes and meeting records. We process contract and billing data including purchase orders, invoice details, payment references and tax identifiers of organisations, which may include names of finance contacts. We process technical data generated by the website such as IP address, approximate location derived from IP, browser type, device type, referring URL, pages viewed, date and time of visit, and cookie identifiers as described in the Cookie Policy.

We do not seek special category data through the public website. We ask you not to send health data, biometric data, trade-union membership, political opinions, religious beliefs, genetic data, or data concerning sex life or sexual orientation in a first contact note. If such data appear incidentally in a security artefact during an engagement, we will treat them as high-risk fragments, tag them, restrict access, and process them only as necessary for the documented purpose of the engagement or to comply with law.

We do not use this website to collect children's data. Our services are directed to organisations and professional adults. If we learn that a person under eighteen has submitted personal data through the form, we will delete that record unless a legal duty requires a short retention for evidence of the incident.

During Cybersecurity Solutions and related consulting we may process system identifiers, usernames, email addresses found in logs, IP addresses, device names, access-control lists, and similar artefacts that constitute personal data of a client's workforce or customers. Those artefacts are not harvested from this website. They are received under contract, tagged as evidence, stored in a restricted context pack, and returned or destroyed according to the engagement and this Policy.

3. Sources

Most personal data come directly from you or from the organisation that engages us. Additional data may come from publicly available professional sources such as a company website, Companies House filings, or a professional profile you have published, used only to verify that a request is genuine and to reduce fraud against our field station. Technical data come from your device and from our hosting and security logs. We do not purchase marketing lists. We do not scrape social networks for lead generation. Social Networks and Other Media Networks and Content Providers appear in our service catalogue as client systems we may be asked to design or secure, not as a source of harvested contacts.

4. Purposes and lawful bases

We process website operation data on the basis of legitimate interests in keeping a professional site available, secure and measurable, balanced against your rights as a visitor. We process context-request data to take steps at your request prior to entering a contract, and thereafter to perform a contract, or on legitimate interests in assessing whether we can accept an engagement without unlawful access or unmanaged conflict. We process client-delivery data to perform a contract for Cybersecurity Solutions, Cloud Computing Solutions, Software Development Services, Web Application Development, Mobile Application Development, Streaming Platform Development, Social Media Platform Development, Search Engine Technologies, Digital Content Distribution, API Development and Integration, Data Analytics Services, Digital Platform Development and related Computer Related Services. We process billing and statutory records to comply with legal obligations including tax, company and anti-money-laundering duties that apply in the United Kingdom. We process security logs on legitimate interests in protecting confidentiality, integrity and availability of our systems and of client context packs. We process limited professional communications on legitimate interests in maintaining a business relationship you have initiated, subject to PECR where electronic marketing rules apply. We do not send unsolicited marketing by email or SMS to individuals without a lawful PECR basis.

Where we rely on legitimate interests we have considered whether a less intrusive method would suffice, whether you would reasonably expect the processing, and whether a right to object should be offered in the relevant channel. Running a London professional practice, preventing abuse of a contact form, keeping evidence of instructions, and defending legal claims are interests we consider legitimate. Profiling for behavioural advertising is not an interest we pursue on this site.

Consent is used where required for non-essential cookies, as set out in the Cookie Policy. You may withdraw cookie consent without affecting the lawfulness of processing before withdrawal. Consent is not used as a disguised condition of receiving a contractual security engagement.

5. Website form and communications

The contact form collects name, email and message. It is a field context request note, not a general newsletter signup. Do not include passwords, private keys, session tokens, unreleased vulnerability details, or bulk personal data of third parties. If you do so despite this warning, we may delete the message, isolate it, or retain a limited record if needed to manage a security incident. We will use the email address as a return path. We do not publish form contents. We do not sell form contents. Telephone calls to +44 7284 556677 may be noted in a field record. We do not record calls as a default practice. If a particular engagement requires recording, we will say so in advance where the law requires it.

6. Cookies and similar technologies

The Cookie Policy describes cookies and similar technologies in full. In summary, strictly necessary technologies may operate to deliver the site and protect it. Non-essential technologies, if introduced, will require consent in the United Kingdom. This Privacy Policy does not duplicate every cookie table. Read both documents. Analytics, if used, will be configured to reduce identifiability where practicable, for example by IP truncation, and will not be used to make solely automated decisions producing legal effects about a visitor.

7. Recipients

We disclose personal data to personnel and contractors who need it for the relevant context unit, bound by confidentiality. We disclose data to hosting, email, domain, accounting, legal and insurance providers who process as processors or as independent controllers according to their roles. We may disclose data to a client where the data concern that client's engagement. We may disclose data to a competent authority where required by law, including under a production order, or where necessary to protect vital interests or to establish, exercise or defend legal claims. We do not disclose personal data to data brokers. We do not permit a processor to use website enquiry data for its own marketing.

If a Cybersecurity Solutions engagement requires a specialist laboratory, cloud tenant, or sub-processor, we will impose written terms that meet UK processor requirements, including instructions, confidentiality, security, sub-processing controls, assistance with data-subject rights, deletion or return, and audit cooperation proportionate to the risk. Names of routine infrastructure providers may be supplied on request where disclosure would not itself create a security risk.

8. International transfers

FARORBIS LTD is established in the United Kingdom. Some processors, for example certain email or hosting providers, may process data in other countries. Where a transfer from the UK to a third country occurs, we will use a lawful transfer tool such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another mechanism recognised by UK law, together with transfer risk assessment where required. We will not transfer client engagement datasets outside the location agreed in the relevant contract without documented authority, except where a mandatory legal demand in the United Kingdom requires a limited disclosure.

9. Retention

Website logs are retained for a short security window, typically not more than ninety days unless an incident requires a longer sealed pack. Context-request notes that do not become engagements are retained for up to twenty-four months so that we can recognise repeat contact and manage abuse, then deleted or anonymised. Contracts, invoices and tax records are retained for at least six years after the end of the relevant accounting period, or longer if a claim is outstanding. Client evidence packs are retained for the period stated in the engagement, then returned or securely destroyed, except for a minimal professional record of what work was done, which may be kept to defend legal claims and to maintain professional continuity. Destruction means a method appropriate to the medium, with confirmation recorded. We do not keep trophy copies of client vulnerabilities for marketing.

10. Security

We apply organisational and technical measures proportionate to the risk of a cybersecurity and software practice: access control, least privilege, encryption in transit for this website, credential hygiene, logging, supplier diligence, and a method of tagging and isolating unexpected fragments. No method is perfect. Transmission over the public internet carries residual risk. You should not use the public form as a high-assurance channel for secrets. We will notify a personal-data breach to the ICO and to data subjects when UK law requires it, and we will notify a client without undue delay where the breach concerns data processed for that client.

11. Your rights

Under UK data protection law you may have the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to object to processing based on legitimate interests, the right to data portability where processing is automated and based on consent or contract, and the right to withdraw consent where consent is the basis. You also have the right to complain to the ICO. These rights are not absolute. We may refuse a request that is manifestly unfounded or excessive, or where an exemption applies, including exemptions relevant to legal professional material, management forecasting, or negotiations, to the extent UK law allows. We will respond within one month, extendable by two further months for complex or numerous requests, and we will explain any extension. We may need to verify identity before releasing a pack, because a context recovery practice must not hand tagged evidence to the wrong recorder.

To exercise rights, write to inquiry@farorbis.social with enough context for us to locate the record: your name, organisation, approximate date of contact, and the nature of the request. Do not send copies of passports unless we ask for a proportionate verification step. If you object to legitimate-interest processing we will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims.

12. Automated decision-making

We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects about website visitors or clients. Human practitioners interpret context. Tools may assist, including analytics or security scanners, but a verified interpretation of a client's estate is not issued by an unattended model as a binding decision about a natural person.

13. Jobs and suppliers

If you send a curriculum vitae or supplier proposal to inquiry@farorbis.social, we will process it to assess the proposal on the basis of legitimate interests or pre-contract steps. Unsolicited applications may be deleted if we have no open requirement. We will not use candidate data to train public models. Referee data should be supplied only with the referee's knowledge.

14. Client instructions and conflicting duties

If a client instructs us to process personal data in a way that would infringe UK data protection law, we will refuse that instruction and record the refusal. If a legal demand requires disclosure of a context pack, we will, where legally permitted, inform the client before disclosure. Computer Misuse Act 1990 boundaries are not waived by a privacy notice. Authorisation to examine systems must exist in the engagement. This Policy does not authorise unauthorised access.

15. Third-party platforms we may build or secure

When we design or assess Streaming Platform Development, Social Media Platform Development, Web Search Portals, Media Streaming Distribution Services or Digital Content Distribution platforms for a client, the client remains responsible for its own privacy information to end users, for lawful bases toward those users, and for age-appropriate design where those duties apply. FARORBIS LTD may assist with technical measures and with drafting support, but this website Privacy Policy is not the privacy notice of any client platform. End users of a client product should read that product's notice, not this one, for processing carried out by the client.

16. Changes

We may update this Policy when our processing, our suppliers, or the law changes. The updated Policy will be published at privacy-policy.html with a revised date. Material changes affecting a live engagement will be communicated to the client contact on record where reasonably practicable. Continued use of the website after publication constitutes awareness of the updated website terms of privacy; contractual processor terms change only by the mechanism in the relevant contract.

17. Contact for privacy

Privacy correspondence: FARORBIS LTD, 27 Old Gloucester Street, LONDON, WC1N 3AX United Kingdom. Email: inquiry@farorbis.social. Telephone: +44 7284 556677. Website: https://farorbis.social. Please mark the subject as a privacy request so it is not handled as a generic sales note. We will tag the request, record the context, and answer from the actual pack, not from a template that ignores your facts.

This Policy was published for the FARORBIS LTD field station in London in 2026. It should be read in the language of the site, English, and interpreted under the laws of England and Wales as to its presentation on this website, without prejudice to mandatory data-protection rights that cannot be contracted away.

If you arrived here from a search engine or from a third-party citation, confirm that you are reading the Policy on https://farorbis.social and not a mirrored page. Only the version on our domain is issued by FARORBIS LTD. Cached or scraped copies may be incomplete. We are not responsible for incomplete copies circulated without our control. A printed extract is not a substitute for the current page if the extract is older than the published date on this Policy.

Nothing in this Policy limits any right that cannot be limited under the Data Protection Act 2018. Nothing in this Policy creates a duty to accept every engagement, to hold data longer than stated, or to disclose security methods in a level of detail that would itself increase risk to clients or to the station. Transparency about purposes, bases, rights and retention is required. A complete map of every defensive control is not required and will not be published here.

18. Additional processing note

We keep a register of processing activities proportionate to a practice of our scale, covering website operation, enquiry handling, contract administration, supplier management, and processor activities for named engagements. The register is an internal field record, not a public catalogue.

19. Additional processing note

Closed-circuit television, if ever used at a location we occupy, would be signed and limited. The registered office at 27 Old Gloucester Street may be a shared building; building security is not automatically our controller processing of your image.

20. Additional processing note

We may process data to establish, exercise or defend legal claims, including to show that a context request was received, that a warning not to send secrets was published, and that Authorised Scope was or was not granted.

21. Additional processing note

If we appoint a new processor that materially changes risk for website visitors, we will update this Policy. If we appoint a processor only for a Client engagement, we will address that in the engagement, not necessarily on this public page.

22. Additional processing note

We do not use personal data of website visitors to train a public generative model. Internal quality review of anonymised writing samples from our own staff is not visitor processing.

23. Additional processing note

Payment data, if you pay the Company, are typically processed by a regulated payment provider. We receive limited references, not a standing store of full card numbers on this website, which has no checkout.

24. Additional processing note

We may process the fact that a domain or an organisation contacted us, because professional context is necessary to detect conflicts and fraud. That fact is not a licence to write a public case study naming you.

25. Additional processing note

Where a data-protection impact assessment is required for a novel high-risk Client system we are asked to build, we will assist the Client as processor or adviser according to the contract. This website itself is not that novel system.

26. Additional processing note

Records of consent for cookies, if consent is collected, will be kept long enough to demonstrate compliance, then deleted or anonymised according to the Cookie Policy and this Policy.

27. Additional processing note

We may share information with Companies House or similar registries only as required for corporate filings, which concern the Company, not your enquiry, unless you are an officer whose details the law requires.

28. Additional processing note

If you contact us from a role at a public body, we still treat your personal contact data under this Policy. Freedom of information duties, if any, attach to the public body, not to FARORBIS LTD as a private company, except where a statute says otherwise.

29. Additional processing note

We may use a ticketing or mailbox system hosted in the United Kingdom or in a country with a lawful transfer tool. Mailbox search exists so we can locate a Context Unit, not so we can build a marketing graph of your colleagues.

30. Additional processing note

Telephone numbers stored from +44 contacts will not be used for automated marketing calls. We do not operate a call centre script that ignores PECR.

31. Additional processing note

If a Client asks us to insert tracking into a product, that is Client-instruction processing of the Client's users, governed by the Client contract and the Client's notices, not by a hidden clause in this Policy.

32. Additional processing note

We will not sell personal data. If the law later defines a novel form of 'sale' that includes ordinary professional hosting, we will interpret that definition in good faith and update this Policy rather than pretend the statute does not exist.

33. Additional processing note

Access requests will be met with the data we hold, not with a reconstruction of every server log that has already aged out of the security window, unless a longer sealed pack exists for an incident.

34. Additional processing note

We may refuse to disclose information that would adversely affect the rights of another person, including another Client's Confidential Information mixed into a file, in which case we will extract what we can or explain the refusal.

35. Additional processing note

Direct marketing, if we ever undertake it to existing organisational contacts who would reasonably expect a professional update, will include a simple stop method and will not be disguised as a security alert.

36. Additional processing note

This Policy applies to processing in connection with English-language professional services. If we later publish another language site, we will not use translation as an excuse to reduce rights.

37. Additional processing note

Staff training on data protection is part of our organisational measures. Training records contain staff names, not your message contents.

38. Additional processing note

If we receive personal data by mistake, we will tag the fragment, restrict it, and either return it or delete it after notifying the sender if we can do so without amplifying the mistake.

39. Additional processing note

Backup media, if used, are subject to the same access control and are overwritten on a cycle. A backup is not a second live marketing database.

40. Additional processing note

We may process your data to prevent crime against the Company, including payment fraud and credential stuffing against this website.

41. Additional processing note

Where two-factor authentication is used on our own tools, authentication secrets are not your personal data from the contact form; they are our staff security fragments.

42. Additional processing note

You may write to us by post at 27 Old Gloucester Street, LONDON, WC1N 3AX United Kingdom. Postal requests are slower than email to inquiry@farorbis.social but are equally valid.

43. Records of requests and internal governance

FARORBIS LTD maintains internal governance proportionate to a United Kingdom professional practice. Directors and senior practitioners review high-risk processing. We keep a log of data-subject requests, including date received, identity-verification steps, outcome, and any exemption relied on. That log contains limited personal data of requesters and is retained long enough to show we answered, typically not more than three years unless a dispute continues. We do not publish the log. We may use it to detect vexatious repeat requests that UK law allows us to refuse as excessive.

Internal policies cover acceptable use of Company systems, encryption of portable media, and reporting of suspected breaches. Those policies are not public, because a complete control catalogue would itself become a buried signal for an attacker. This Privacy Policy remains the public account of purposes, bases, rights, recipients, transfers, and retention. Staff who mishandle personal data may be subject to disciplinary process under employment law, which is a separate horizon from your rights as a data subject.

44. Joint controllers and platforms we do not operate

FARORBIS LTD does not ordinarily act as a joint controller with a Client. Design of a Client's Social Media Platform Development or Streaming Platform Development product does not make us a joint operator of that product. If a rare project required joint-controller allocation, we would set it out in a transparent arrangement as UK law requires. Map, font, and hosting providers may be independent controllers for their own logs. You should read their notices if you interact with their services through our pages. We remain controller for the personal data we decide to collect through our form and our own mailbox at inquiry@farorbis.social.

45. Data protection officer and representatives

UK law does not require every small professional firm to appoint a statutory data protection officer. FARORBIS LTD has not appointed a statutory DPO as at the date of this Policy. Privacy correspondence is still received at inquiry@farorbis.social and at 27 Old Gloucester Street, LONDON, WC1N 3AX United Kingdom. If a future assessment concludes that a statutory DPO is required, we will name that person or service in an updated Policy. We have not appointed an EU representative unless and until we conduct processing that requires one; Clients who need an EU representative for their own products must appoint their own.

46. Special processing in cybersecurity artefacts

Logs, packet captures, identity inventories, and similar artefacts can contain personal data of persons who are not our Client's contracting staff, including customers of the Client. We process such data only as processor on documented instructions, for the Authorised Scope, and for no independent marketing purpose. We apply additional access restriction to artefacts that appear to contain special category data or criminal-offence data. We will tell the Client if an artefact appears to include such data unexpectedly, so the Client can adjust instructions. We will not use those artefacts to build a Company product. Telephone +44 7284 556677 may be used to arrange a more secure transfer channel once a context unit exists; it is not itself an encrypted channel.

47. Accuracy, minimisation and storage limitation in practice

We ask you to keep your contact details accurate. We do not continually verify your job title against the open web. We collect the minimum we need for the purpose: a context request needs a name, a return path, and a message; it does not need your date of birth. We store data in identifiable form only for the retention stated, then we delete or irreversibly anonymise. Anonymisation, if used, will be designed so that we cannot reasonably re-identify you from the remaining field notes. Aggregation of website traffic for capacity planning is not a profile of you as a named person.