This Privacy Policy explains how ExoRisk Limited (“we”, “us”, “our”), a company registered in England and Wales under company number 17245256, with its registered office at 167 – 169 Great Portland Street, 5th Floor, London, England, W1W 5PF, collects, uses, and protects information when you visit www.exorisk.global (the “Site”) or otherwise interact with us.
We are the data controller for the personal data described in this policy. If you have any questions, contact us at enquiry@exorisk.global
We may collect the following categories of information:
We do not knowingly collect special category data (e.g. health, religious belief) or information from children. Our Site is intended for business use by professional audiences.
We use the information we collect to:
Where UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Responding to enquiries | Legitimate interests / performance of a contract |
| Sending B2B marketing communications | Legitimate interests (with opt-out) or consent |
| Website analytics | Legitimate interests / consent (for non-essential cookies) |
| Complying with legal obligations | Legal obligation |
You have the right to object to processing based on legitimate interests at any time.
We do not sell personal data. We may share information with:
We do not transfer personal data outside the UK/EEA unless appropriate safeguards are in place (e.g. Standard Contractual Clauses or an adequacy decision).
Our Site uses cookies and similar technologies to:
You can control cookies through your browser settings or via our cookie consent banner. Disabling non-essential cookies will not affect your ability to browse the Site, but may limit certain features.
[Insert a cookie table here listing specific cookies, providers, purpose, and duration once your cookie audit is complete.]
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, including:
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at enquiry@exorisk.global
As we market our services to businesses in the United States, this section addresses rights available to individuals under applicable US state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and comparable laws in states such as Virginia, Colorado, Connecticut, and Utah.
Scope note: Many US state privacy laws provide narrower protections (or exemptions) for personal data collected in a business-to-business context — for example, data about an individual acting in their role as an employee, owner, director, officer, or contractor of a company we deal with. Where such exemptions apply, this section may not confer additional rights beyond those described elsewhere in this policy. We include it to be transparent about our practices regardless.
Categories of personal information we collect, per the categories defined under CCPA/CPRA, may include: identifiers (name, email, phone, IP address); commercial information (services enquired about); internet or network activity (Site usage data); and professional or employment-related information (job title, company).
We do not sell or share personal information (as those terms are defined under CCPA/CPRA) for cross-context behavioural advertising, and we have not done so in the preceding 12 months.
Your rights, subject to applicable exemptions, may include the right to:
To make a request, contact us at enquiry@exorisk.global. We will verify your request using reasonable means before responding, and you may designate an authorised agent to act on your behalf where permitted by law.
We do not knowingly collect personal information from California residents under 16 for purposes of sale or sharing.
For marketing emails sent to recipients in the United States, we comply with the CAN-SPAM Act. This means we will:
You can unsubscribe from marketing emails at any time using the link provided in the email, or by contacting us at enquiry@exorisk.global
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.
Our Site may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review their privacy policies independently.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The “Last updated” date at the top of this page indicates when it was last revised. Material changes will be communicated where appropriate.
If you have questions about this Privacy Policy or how we handle your personal data, please contact:
ExoRisk Limited, 167 – 169, Great Portland Street, 5th Floor, London, United Kingdom, W1W 5PF, enquiry@exorisk.global