Privacy & Cookie Policy
This policy explains how Cipher Hunt Ltd ("we", "us", "our", "CipherHunt") collects, processes, uses, shares and protects personal data when you visit our website or get in touch about our services, and your rights under UK data protection law.
It covers visitors to our website and people who enquire about our services. If you go on to become a client, we will give you additional privacy information relevant to the investigation or recovery work we carry out for you (including how we handle identity-verification and due-diligence information). Cipher Hunt Ltd and the other companies in the Comera group are legally separate entities.
It provides details of the nature of the personal data collected by us, together with the purposes of the processing. It also indicates your rights in relation to the data processed and who to contact for further information or requests. In this privacy notice your "personal data" is sometimes referred to as your "information."
Who we are
Cipher Hunt Ltd is the data controller for the personal data described in this policy.
- Data controller: Cipher Hunt Ltd, a company registered in England and Wales (company number 06096307), a wholly-owned subsidiary of Comera Intelligence Ltd.
- Registered office: Origin Workspace, 40 Berkeley Square, Bristol, BS8 1HP.
- Data protection contact: privacy@cipherhunt.co.uk.
Having assessed our processing, we are not required to appoint a statutory Data Protection Officer; the contact above handles all data protection matters. This policy is governed by UK data protection law, principally the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR) for cookies (small text files stored in a user's browser) and marketing.
What data we collect
- Enquiry & contact data you give us through our enquiry form: your name, email address, phone number (if you provide it), the type of enquiry, any message you include, and whether you opt in to marketing.
- Communications: the content of any emails or messages you send us.
- Technical & usage data: IP address, device and browser type, pages visited and referring pages — collected through cookies and analytics, and only with your consent for non-essential cookies (see Cookies below).
Please never include wallet seed phrases, private keys, PINs or passwords in a form message or email — we do not need them to assess an enquiry and will never ask for them by email. Please also avoid including sensitive personal information (such as health details) or operationally sensitive material; the website is not intended to collect special category or classified data and no responsibility will be taken for any such information sent by you using the website.
How we use your data and our lawful bases
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Respond to your enquiry and assess whether we can help | Taking steps at your request before entering a contract (Art. 6(1)(b)), and our legitimate interests in responding to enquiries (Art. 6(1)(f)) |
| Involve our parent company or another Comera group company where an enquiry needs the group's wider capability | Legitimate interests (Art. 6(1)(f)) |
| Manage our relationship with you and keep business records | Legitimate interests; legal obligation |
| Carry out identity verification and due diligence before accepting an engagement | Legal obligation (anti-money-laundering law); legitimate interests |
| Send you marketing (occasional updates on crypto fraud trends and our services) | Consent (Art. 6(1)(a)) — only if you opt in; you can withdraw at any time |
| Measure, manage, improve and enable navigation of the website | Consent (for non-essential analytics cookies) |
| Provide investigation and recovery services and meet our legal and regulatory duties (if you become a client) | Contract; legal obligation (including anti-money-laundering law) |
We will only send you marketing if you have opted in, and every marketing email includes an unsubscribe link. We do not sell your data or share it with third parties for their own marketing.
Cookies and similar technologies
When you first visit our site we show a cookie banner that lets you accept or reject non-essential cookies. Non-essential cookies are not set until you consent. You can change or withdraw your choice at any time — select , here or in the footer of any page, and choose again. Withdrawing consent switches analytics off and deletes the analytics cookies already set. We use the following categories:
| Category | Examples | Purpose | Consent needed? |
|---|---|---|---|
| Strictly necessary | A record of your cookie choice, stored in your browser | Remembers your consent decision so we don't ask again, and keeps the site working | No — required for the service |
| Analytics / performance | Google Analytics (_ga, _ga_*) | Measures how the site is used so we can improve it | Yes |
Google Analytics loads only after you accept analytics cookies. We enable IP anonymisation and do not use it for advertising. Google Analytics cookies last up to 2 years; we retain the analytics data for up to 14 months. You can also block or delete cookies through your browser settings, though some parts of the site may not work properly without strictly necessary cookies.
Withdrawing consent is as easy as giving it: use and select "Reject". We then disable Google Analytics for your browser and delete the
analytics cookies it set (_ga, _ga_*, and any legacy _gid or
_gcl_*), so no further analytics data is collected about your visit.
Who we share your data with
We do not sell your data. We share it only as follows:
- With Comera group companies — principally Comera Intelligence Ltd (our parent company), where an enquiry needs the group's wider intelligence, investigations or risk capability; a group company will use your information only to help respond to you.
- Fasthosts (UK) — website hosting.
- Zoho Corporation — ZeptoMail (EU) — sends transactional emails, such as the confirmation you receive after making an enquiry.
- Zoho Corporation — Zoho CRM & Zoho Campaigns — manages enquiries and leads and, if you opt in, sends our marketing.
- Google — Google Analytics, used only with your consent.
Our service providers act under contracts that require them to protect your data and use it only on our instructions. We may also disclose data where required by law, by a regulator or law-enforcement body, or to establish, exercise or defend legal claims. If you become a client, we may share data with exchanges, legal partners and authorities as needed to deliver our services — this is covered in your engagement information.
International transfers
Some of our providers process data outside the UK. Where they do, an appropriate safeguard is in place:
| Provider | Role | Location | Safeguard |
|---|---|---|---|
| Fasthosts | Hosting | United Kingdom | No overseas transfer |
| Zoho (ZeptoMail) | Transactional email | European Union | UK adequacy regulations for the EEA |
| Zoho (CRM / Campaigns) | CRM & marketing | International | International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses |
| Analytics | United States / global | UK Extension to the EU–US Data Privacy Framework and/or the IDTA |
Details of the specific safeguards are available on request from our data protection contact.
How long we keep your data
- Enquiries that don't become clients: up to 24 months from your last contact with us, then deleted.
- Marketing contacts: until you unsubscribe or withdraw consent (we also review our list periodically).
- Website analytics: up to 14 months.
- Client records (if you engage us): at least 6 years after our engagement ends, to meet record-keeping obligations including anti-money-laundering law.
We keep personal data no longer than necessary for the purpose it was collected, unless the law requires us to keep it for longer.
How we protect your data
We use technical and organisational measures proportionate to the data we hold: encryption in transit (HTTPS/TLS), reputable service providers, access limited to those who need it, education and training to relevant staff to ensure they are aware of our data protection obligations when processing personal data, physical security measures (such as staff security passes to access our premises), and protections on our forms against spam and abuse. The transmission of data over the internet (including by e-mail) is never completely secure. We endeavour to protect personal data, but we cannot guarantee the security of data transmitted to us or by us. We take reasonable steps to safeguard your information.
Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, object to and be informed about our collection and processing of your personal data, to data portability, and to withdraw consent at any time where processing is based on consent. You also have rights in relation to automated decision making and profiling. To exercise any of these rights, email privacy@cipherhunt.co.uk. We will respond within one month, and there is normally no charge.
Complaints
If you have concerns about how we handle your data, please contact us first so we can try to put things right. If you remain dissatisfied or feel the matter was not resolved by us, you also have the right to complain to the UK supervisory authority: the Information Commissioner's Office (ICO) — ico.org.uk/make-a-complaint, helpline 0303 123 1113, address The Office of the Information Commissioner, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the "last updated" date above. Where changes are significant, we will take reasonable steps to highlight them.
Third party requests
If you are submitting a personal data request on behalf of someone other than yourself, please contact us by using the contact details in this Privacy Notice and include proof that you are authorised to make the request. This may be in the form of a written authorisation signed by the person whom you are acting on behalf of or a valid power of attorney.
Contact us
Cipher Hunt Ltd
Origin Workspace, 40 Berkeley Square, Bristol, BS8 1HP
Data protection: privacy@cipherhunt.co.uk