PRIVACY & COOKIES

Nothing hidden. Including this page.

Most privacy policies are written to be skipped. This one is organised by who you are and what you did — so you can read the part that applies to you and ignore the rest.

THE SHORT VERSION

We're Outside The Box Consulting — a UK cyber security consultancy. Legally, that's Outside The Box Consulting Limited, registered in England & Wales under company number 16093723, with a registered office at 82a James Carter Road, Mildenhall, IP28 7DE. For anything on this page, we're the data controller and the person to email is hello@outsidethebox.io.

Our stance is the same one we bring to client work: nothing hidden. Every change we make to this policy is listed at the bottom of this page, dated, in plain English — so you can see what changed and when, rather than a bare "last updated" stamp you're asked to trust.

And the headline: this site sets no cookies. None at all. No analytics, no tracking pixels, no consent banner theatre. The rest of this page is the detail behind that sentence.

Find the section that describes you — visitor, correspondent, chat user, client — and read that one. Each tells you what we collect, why, and exactly how long we keep it. The last two sections cover your rights and the short list of companies that process data for us.

COOKIES: 0  ·  THIRD-PARTY TRACKERS: NONE  ·  POLICY HISTORY: PUBLISHED BELOW

YOU'RE VISITING THIS WEBSITE

Reading this site is about as private as browsing gets. We're a security firm; a website that quietly harvests its visitors would be a strange advertisement for the day job.

The site is hosted on Microsoft Azure, in an EU/UK region. Like every web server, Azure keeps standard server logs: your IP address, the pages you requested, the time, and your browser's user-agent string. We use these for security and to keep the site running — spotting abuse, debugging errors — and for nothing else. They're kept for Azure's standard retention period and then gone.

Everything on the page is served by us. Fonts, images, stylesheets — all from our own domain. Your browser makes no third-party requests just because you opened a page here, which means no third party learns you visited.

We do count page views, and we do it ourselves. When a page loads it sends us four things: which page, which site you arrived from (the domain only, never the full address), whether your screen is large or small, and the country your request came from. That's the entire list.

What we deliberately don't collect: your IP address, any identifier, any cookie, or anything that links one page view to another. We can see that the DORA article was read four hundred times; we cannot see that you read it, that you came back, or what you read next. There is no Google Analytics here, no advertising pixel, and no third party receiving anything — the measurement goes to our own service on Microsoft Azure in the UK, and is deleted after 31 days.

One honest footnote: the light/dark toggle in the navigation remembers your choice using your browser's local storage. That's a preference saved on your own device. It isn't a cookie, it's never sent to us or to anyone else, and clearing your browser data removes it.

There is no cookie banner on this site because there is nothing to consent to. We set no cookies, first-party or otherwise.

YOU'VE CONTACTED US

If you fill in our contact form, it goes to our own service running on Microsoft Azure in the UK, which emails the message to us. It doesn't pass through a CRM, a marketing platform, or anyone else's servers.

What we store is what you gave us: your name, your email address, your company if you told us, and your message. Nothing is enriched, appended, or bought in from elsewhere.

Why we store it is equally short: to reply to you, and to manage the relationship if the conversation goes somewhere. That's "legitimate interests" in UK GDPR terms — you asked us something; we'd like to answer and remember that we did.

How long: your message lives in our mailbox, and we clear out enquiries that went nowhere 24 months after our last contact with you. If you email us once and we never speak again, your details don't sit in a database for a decade waiting for a newsletter we don't send. And no — contacting us does not put you on a mailing list. We don't have one.

Who sees it: the consultants at Outside The Box, and nobody else. We don't share contact details with partners, pass them to resellers, or trade them for a slot in someone's webinar. If you contact us, you hear from us — that's the whole flow.

When you submit the form we send you an immediate acknowledgement by email, with a copy of what you wrote, so you have a record that it arrived.

The same applies if you skip the form and just email hello@outsidethebox.io — same data, same purpose, same 24 months.

YOU'VE USED THE ASSISTANT

The "Ask us anything" button opens an AI assistant that answers questions about this firm using the content of this website. It's ours — not a third-party chat widget — and it sets no cookies.

Here's exactly what happens when you send it a question. Your message goes to our service on Microsoft Azure in the UK, which passes it, along with the site's own content, to Microsoft's Azure AI service in the UK to generate a reply. It is processed to produce that answer and is not used to train models. We don't store the conversation: it lives in your browser tab and disappears when you close it. Nothing is logged against you, and there is no transcript for us to read later.

If the assistant can't help, it offers an "Ask a person" button. That carries the questions you asked into the contact form's message box, held in your browser's session storage — never in the web address, never sent anywhere until you press send. It's cleared the moment it's used, you can edit or delete every word first, and nothing reaches us unless you submit the form.

We do keep a count of how many questions the assistant answers and how much it costs us to run — numbers only, never the questions themselves, and nothing that identifies who asked.

Because we can't see the conversation, please don't put anything sensitive in it — no incident details, no personal data, nothing you wouldn't say to a stranger. If you want to tell us something real, use the contact form or email us, where a human is on the other end.

The assistant answers from this website and nothing else. It isn't giving you security advice, it can be wrong, and it will tell you to email us when a question deserves a person. Treat it as a faster way to read the site, not as counsel.

YOU'RE A CLIENT

If we work together, we hold more than a contact record — contracts, statements of work, invoices, correspondence about the engagement, and the deliverables themselves. We hold them because we have to run the engagement, bill for it, and stand behind the work afterwards. Legally, that's performance of a contract, plus our legitimate interest in being able to answer for our advice.

Engagement records are kept for six years after the engagement ends — the limitation period for contract claims in England & Wales. If either of us ever needs to establish what was agreed and what was delivered, the record exists. After six years, it doesn't.

Anything security-sensitive you share with us during an engagement — architecture diagrams, findings, the things you'd rather your competitors never saw — is governed by the confidentiality terms in our engagement contract, which go well beyond anything this page needs to say. The retention clock applies to it all the same.

Individual contacts at client firms — the people we actually talk to — sit in the same CRM as everyone else, with the same 24-month rule counted from last contact. It's the engagement record that carries the six-year retention, not your inbox history.

One thing we don't do: we don't name clients, use their logos, or describe their engagements publicly without written permission. If you've seen anonymised examples on this site, that's why they're anonymised.

YOUR RIGHTS

UK GDPR gives you rights over your data. Stripped of the legalese, they come to this:

To exercise any of these, email hello@outsidethebox.io. No forms, no portals, no proving your identity three ways for a record that contains your name and one email. We'll respond within a month, as the law requires — usually much faster, because the data is small and the list of places to look is short.

If you think we've handled your data badly and we haven't put it right, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to fix it first, but that's your call, not a precondition.

WHO PROCESSES YOUR DATA

The complete list of companies that process data on our behalf. Everything sits with Microsoft in the UK, plus GitHub for the source code.

PROCESSORWHAT IT DOESWHAT IT SEESWHEN
Microsoft Azure Hosts this website and sends us your contact-form messages, in a UK region. Standard server logs — IP address, pages requested, timestamps. Every visit.
Microsoft Azure AI Generates the site assistant's replies, in the same UK region as the rest of our hosting. The question you type into the assistant. Not used to train models; not stored by us. Only if you use the assistant.
Microsoft Azure Monitor Stores our own page-view counts, in the UK. Page path, referring domain, screen size band, country. No IP, no identifier, no cookie. Every page view. Deleted after 31 days.
GitHub Hosts the site's source code — including this policy and its change history. Nothing about you. Visitor data never touches it. Never sees personal data.

That's the whole list. No advertising networks, no data brokers, no "trusted partners". Where a processor moves data outside the UK, it does so under the UK's approved safeguards — the international data transfer agreement or a UK adequacy decision.

While we're listing things: we never sell personal data, we never send marketing you didn't ask for, and we never use client data for anything beyond the engagement it belongs to. If any of that changes — it won't — this page changes first, in public.

CHANGES TO THIS POLICY

Every substantive change to this policy gets a dated line below — what changed, in language you can check against the sections above. If we ever add a processor, a new purpose, or a longer retention period, it appears here and at the top of the page, not buried in a reworded paragraph.

We keep the full history of this page under version control, and we'll provide the earlier text on request. Nothing hidden isn't a line we drop when it's our own paperwork.

v1.1

First-party page counts added

We began counting page views ourselves — page, referring domain, screen size band and country, deleted after 31 days. No cookies, no identifiers, no third-party analytics. Added Microsoft Azure Monitor to the processor list, and noted that we count the assistant's questions without recording them.

v1.0

First published

Initial policy covering website visitors, enquiries, the site assistant and client engagements.

Questions about any of this? Just ask.

Get in touch