Last updated: 28 July 2026
This Privacy Policy explains how Fossphorus (“Fossphorus”, “we”, “us” or “our”) collects, uses, shares and protects your personal information when you visit our websites, use our products and services, apply for a role with us, or otherwise interact with us. We operate internationally and are committed to handling your information lawfully, fairly and transparently wherever you are located.
1. Who we are & the scope of this policy
Fossphorus is a technology company providing web and software development, IT consulting, cybersecurity and related services, and we build and operate our own software products, including NexFirm and ComplyEze. We deliver these services through offices and affiliated entities in the United Kingdom, the United States, Bermuda, the Middle East and Pakistan.
Depending on where you are and how you interact with us, the Fossphorus entity responsible for your personal information (the “data controller”) may differ. The relevant entity, together with our full contact details, is set out in section 15. For questions about which entity is responsible for your information, contact us at privacy@fossphorus.com.
This policy applies to personal information we process about website visitors, prospective and existing clients and their staff, users of our products, suppliers and partners, job applicants, and other individuals we interact with. It does not apply to third-party websites or services that we link to but do not control (see section 13). Where we process personal information on behalf of a client under a contract (for example, when operating a product or platform for them), the client is the controller and we act as a “processor”; that processing is governed by our agreement with the client and, where relevant, their own privacy notice.
2. The information we collect
We collect personal information in three main ways:
Information you give us
- Identity & contact data — name, job title, employer, email address, telephone number, postal address and the content of messages you send us.
- Client & project data — information you provide when requesting a quote, scoping a project, or working with us, including business requirements and correspondence.
- Account & product data — details you provide when registering for or using our products (such as NexFirm and ComplyEze), including login credentials and configuration settings.
- Recruitment data — if you apply for a role, your CV/résumé, cover letter, work history, education, right-to-work information and any details you choose to share.
- Payment data — billing details needed to invoice and receive payment. Card payments are handled by our payment providers; we do not store full card numbers.
Information we collect automatically
- Technical data — IP address, device and browser type, operating system, language, and referring URLs.
- Usage data — pages viewed, links clicked, time on site and similar analytics, and how you use our products.
- Cookies & similar technologies — see section 4.
Information from other sources
We may receive information from your employer or colleagues, our business partners and referrers, publicly available sources and professional networks, analytics and advertising providers, and fraud prevention and identity verification services.
We generally do not seek to collect “special category” or sensitive personal information (such as health, biometric, or information revealing race, religion or political opinions). Please do not send us such information unless we specifically request it and explain why.
3. How and why we use your information
We use personal information to: respond to enquiries and provide quotes; deliver, operate, support and improve our services and products; manage our relationship with clients, suppliers and partners; process payments and keep accounting records; run recruitment; send service messages and, where permitted, marketing; ensure security, prevent fraud and enforce our terms; and comply with legal obligations.
Where UK, EU or comparable data protection law applies, we rely on one or more of the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Providing services and products under a contract | Performance of a contract |
| Responding to enquiries and quotes | Legitimate interests / steps prior to a contract |
| Improving and securing our services, and preventing fraud | Legitimate interests |
| Marketing and analytics cookies | Consent |
| Accounting, tax and legal compliance | Legal obligation |
| Recruitment | Legitimate interests / steps prior to a contract |
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time (see section 9). If you do not provide information we need to deliver a service, we may be unable to provide it.
4. Cookies and similar technologies
Our websites use cookies and similar technologies to make the site work, remember your preferences, measure performance and, where you consent, personalise content and measure marketing. We use:
- Strictly necessary cookies — required for the site to function (they do not need consent).
- Analytics cookies — help us understand how the site is used.
- Functional and marketing cookies — used only where you have consented.
Where required by law, we ask for your consent to non-essential cookies through a cookie banner, and you can change your choices at any time through your browser settings or our cookie controls. For more detail, contact us at privacy@fossphorus.com.
5. How we share your information
We do not sell your personal information. We share it only as needed and with appropriate safeguards, with:
- Service providers (processors) — hosting, cloud infrastructure, email, analytics, payment processing, CRM and support tools that process data on our instructions.
- Our group and affiliates — our offices and entities in the UK, US, Bermuda, the Middle East and Pakistan, to deliver and administer our services.
- Professional advisers — lawyers, accountants, auditors and insurers.
- Authorities and other parties — where required by law, to enforce our terms, to protect our rights or safety, or in connection with a corporate transaction (such as a merger or acquisition).
6. International data transfers
Because we operate globally, your personal information may be transferred to, and processed in, countries other than the one in which you are located, including the United Kingdom, the United States, Bermuda, countries in the Middle East and Pakistan. Data protection laws in those countries may differ from those in your own.
Where we transfer personal information across borders, we put in place appropriate safeguards required by applicable law — for example, the UK International Data Transfer Agreement (IDTA) or Addendum, the European Commission’s Standard Contractual Clauses, transfers to countries with an adequacy decision, or comparable mechanisms and consents. You can request more information about these safeguards using the contact details in section 15.
7. How long we keep your information
We keep personal information only for as long as necessary for the purposes described in this policy, including to provide our services, meet legal, accounting and tax obligations, resolve disputes and enforce our agreements. Retention periods vary by the type of data and the reason we hold it — for example, we keep accounting records for the period required by tax law, and recruitment data for a limited period after a decision unless you agree we may keep it longer. When information is no longer needed, we securely delete or anonymise it.
8. How we protect your information
We maintain technical and organisational measures appropriate to the risk, including access controls, encryption in transit, network and application security, monitoring, and staff confidentiality obligations. No method of transmission or storage is completely secure; while we work hard to protect your information, we cannot guarantee absolute security. Where the law requires, we will notify you and the relevant regulator of a personal data breach that is likely to affect your rights.
9. Your privacy rights
Subject to the law that applies to you, you may have some or all of the following rights over your personal information: to access a copy of it; to correct inaccurate or incomplete data; to delete it; to restrict or object to certain processing; to data portability; to withdraw consent; and to opt out of marketing at any time (use the unsubscribe link in our emails or contact us).
To exercise any right, contact us at privacy@fossphorus.com. We will respond within the timeframe required by applicable law. We may need to verify your identity, and we will not discriminate against you for exercising your rights. The region-specific sections below explain how these rights apply where you live.
10. Region-specific privacy rights
United Kingdom & European Economic Area
If you are in the UK or EEA, we process your personal information in accordance with the UK GDPR and the Data Protection Act 2018 (or the EU GDPR, as applicable). You have the rights described in section 9, and the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO), ico.org.uk. We would, however, appreciate the chance to address your concerns before you approach the regulator. Our UK establishment and, where appointed, our representative details are in section 15.
United States
We do not sell your personal information and we do not “share” it for cross-context behavioural advertising as those terms are defined under US state privacy laws. Depending on your state of residence (for example, California under the CCPA/CPRA, and Virginia, Colorado, Connecticut, Utah and other states with comprehensive privacy laws), you may have rights to know or access the personal information we collect, to request deletion or correction, to opt out of sale/sharing or targeted advertising, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. California residents may also request the categories of information collected, the sources, the business purposes, and the categories of third parties with whom it is shared. To exercise these rights, contact us at privacy@fossphorus.com; you may use an authorised agent where the law allows.
Bermuda
If your personal information is handled by our Bermuda operations, we process it in accordance with the Personal Information Protection Act 2016 (PIPA). Consistent with PIPA, we use personal information fairly and for identified purposes, limit it to what is proportionate, and keep it secure. You may request access to and correction of your personal information, and you may contact our Privacy Officer at privacy@fossphorus.com. You may also contact the Office of the Privacy Commissioner for Bermuda, privacy.bm.
Middle East
Where we process personal information in or from the Middle East, we do so in accordance with applicable local data protection laws, which may include the United Arab Emirates Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (and free-zone regimes such as the DIFC and ADGM data protection laws) and the Kingdom of Saudi Arabia Personal Data Protection Law, among others. Subject to those laws, you may request access to, correction or deletion of your personal information, object to certain processing, and withdraw consent. Contact us at privacy@fossphorus.com.
Pakistan
Where our Pakistan operations process your personal information, we do so in line with applicable Pakistani law, including the Prevention of Electronic Crimes Act 2016 and the data protection framework as it develops (including the forthcoming Personal Data Protection legislation). We rely on your consent where required, keep information secure, and honour reasonable requests to access or correct your information. Contact us at privacy@fossphorus.com.
11. Children’s privacy
Our websites, products and services are intended for businesses and adults. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
12. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without a lawful basis and, where required, appropriate safeguards and your right to human review. If this changes for a particular service, we will tell you.
13. Third-party links and services
Our websites and products may link to or integrate third-party websites and services (including our own products’ external sites). We are not responsible for their privacy practices, and we encourage you to read their privacy notices.
14. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. We will post the updated version here and revise the “Last updated” date above. Where changes are significant, we will provide a more prominent notice where required.
15. How to contact us
For any privacy question or to exercise your rights, contact our privacy team at privacy@fossphorus.com or write to us at the relevant office below.
Company registration details, data protection registration/ICO number, and where appointed our UK/EU representative and Data Protection Officer contact, are available on request and will be confirmed here.