Privacy Policy

How we collect, use, and protect your personal information.

1. Introduction and Scope

This privacy policy applies to citizens and legal permanent residents of the United Kingdom and all individuals whose personal data is processed by Talastron Ltd. It was last updated on 29 September 2026.

Talastron Ltd (“we”, “our” or “us”) is committed to protecting your privacy and handling your personal information with transparency, integrity and care. This privacy policy explains how we collect, use, store and safeguard your personal information when you:

  • Visit our website at talastron.com (“Website”).
  • Send us an enquiry through the form on our Website.
  • Used any online assessment, quiz, diagnostic tool or calculator on our previous website, including our AI Maturity Assessment, Data Governance Checklist, AI Use Case Prioritisation Matrix and ROI Calculator (“Assessment Tools”). These tools are no longer offered; Section 9 explains how the data you gave through them is handled.
  • Engage with our consulting services in data analytics, artificial intelligence strategy, Microsoft Fabric, Power Platform and Azure cloud implementations.
  • Use any software application or analytics platform published by us, including any offers listed on the Microsoft Commercial Marketplace (“Marketplace Offers”).
  • Subscribe to our newsletter or marketing communications.
  • Interact with us in any other professional or commercial capacity.

We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (PECR), and the Data Use and Access Act 2025. We are registered with the Information Commissioner’s Office (ICO) under registration number ZB804967.

2. Data Controller

For the purposes of UK and EU data protection laws, Talastron Ltd is the “data controller” of your personal information. Cloudflare, Resend and Microsoft act as “data processors” and process your personal data on our behalf as described in this policy.

Talastron Ltd
The Long Barn, Cobham Park Road, Cobham, Surrey, KT11 3NE, United Kingdom
Companies House Registration Number: 15464691
ICO Registration: ZB804967
Email: enquiries@talastron.com
Telephone: +44 (0)7795 467 284
Website: talastron.com

Trading name: Talastron. Formerly Orion Data Analytics Ltd.

3. Information We Collect

3.1 Information You Provide Directly

  • Identity data such as your full name, professional title and company name, provided when you enquire about our services, complete a contact form or register for a Marketplace Offer.
  • Enquiry data: what you give us in the enquiry form on our Website: your name, work email, organisation, role, where you would like to start, what you are working on, and whether you would like our evidence pack.
  • Contact data including your professional email address, telephone number and business address.
  • Newsletter data: the email address you give us to receive our Insights newsletter, whether you have confirmed and are subscribed, and when you confirmed.
  • Assessment data including your responses, selections and input to the Assessment Tools on our previous website. This may include information about your organisation’s technology maturity, data governance practices, AI readiness, business priorities and infrastructure details that you voluntarily provided during the assessment process.
  • Contractual information required to deliver our consulting services, including project-related data shared during engagements under a separate Statement of Work or Data Processing Agreement.
  • Marketplace customer information shared with us by Microsoft when you purchase or subscribe to our Marketplace Offers, including your contact details and transaction information, as permitted under the Microsoft Publisher Agreement.

3.2 Information Collected Automatically

  • Technical data including your internet protocol (IP) address, browser type and version, time zone setting, operating system and platform, collected via server logs.
  • Usage data such as the pages visited, the referring page, browser and device type, and the country a visit comes from, collected as aggregated statistics by Cloudflare Web Analytics. It does not use cookies or any other storage on your device, and it is not used to identify you or to follow you across other websites.
  • Form protection data: when you send our enquiry form or sign up for our newsletter, Cloudflare Turnstile checks signals from your browser and connection to confirm that you are a person and not an automated program.
  • Assessment analytics data including completion rates, time spent on assessment sections, result categories and aggregate scoring data from the Assessment Tools on our previous website. Individual assessment results are not shared with third parties without your consent.
  • Security data including IP addresses, request timestamps and browser fingerprints, collected by Cloudflare for security and performance optimisation purposes.
  • Log file data including IP addresses, timestamps, HTTP request details and browser data, collected for security monitoring, service interruption detection and infrastructure performance analysis.
  • Application usage data from our software products and Marketplace Offers, including feature interaction patterns, error logs and performance metrics, collected to improve service delivery and product quality.

3.3 Information from Third Parties

We may receive information from publicly available sources such as Companies House, LinkedIn or industry directories to support our business development activities, always in accordance with applicable data protection legislation. We may also receive customer contact information from Microsoft in connection with Marketplace transactions, which we process solely for transactional purposes or to respond to customer enquiries about our offers.

4. Lawful Basis for Processing

We process your personal information for the following purposes, each supported by a lawful basis under UK GDPR:

PurposeDescriptionLawful Basis
Service DeliveryTo respond to enquiries, including those sent through the form on our Website, deliver consulting engagements, and provide data strategy, AI and cloud services.Contractual necessity; Legitimate interest
Assessment ToolsTo hold the results of the Assessment Tools on our previous website for the period set out in Section 12, and to use anonymised aggregate data to improve our services.Consent; Legitimate interest
Marketplace FulfilmentTo process subscriptions, deliver and support Marketplace Offers, and manage the customer relationship.Contractual necessity
MarketingTo send our Insights newsletter via Resend where you have signed up and confirmed your subscription.Consent
Website AnalyticsTo measure how our Website is used and how well it performs, with Cloudflare Web Analytics, which uses no cookies and does not identify you.Legitimate interest
SecurityTo protect our website and infrastructure from malicious activity using Cloudflare (including Cloudflare Turnstile on our enquiry and newsletter forms) and Microsoft Defender for Cloud.Legitimate interest
Log File AnalysisTo collect IP addresses, timestamps and browser data for security monitoring and service interruption detection.Legitimate interest
Legal and RegulatoryTo comply with legal obligations, regulatory requirements, court orders or governmental authority.Legal obligation
Product ImprovementTo analyse usage patterns and performance data from our software products to improve functionality.Legitimate interest

5. Microsoft Cloud Services and Data Hosting

Talastron Ltd utilises Microsoft Azure and Microsoft 365 cloud computing platforms to host our applications, store professional data and deliver our consulting services and software products. As a result, your personal information may be processed by Microsoft Corporation as a sub-processor on our behalf. These services are essential for providing our data analytics, artificial intelligence and cloud solutions, and for ensuring high levels of security, availability and compliance.

5.1 Data Residency

Our primary data residency is within the United Kingdom (UK South region). All Azure resources provisioned for our products and consulting engagements default to UK South unless a specific client requirement dictates otherwise.

5.2 International Data Transfers

The use of Microsoft’s global infrastructure may involve the transfer of data to servers located outside the United Kingdom or the European Economic Area. In such instances, we rely on the following safeguards to ensure your information receives a level of protection equivalent to that provided under UK data protection law:

  • Standard Contractual Clauses (SCCs) approved by the Information Commissioner’s Office.
  • The UK Extension to the EU–US Data Privacy Framework, where applicable.
  • Adequacy decisions issued by the UK Secretary of State, where the receiving country has been assessed as providing an adequate level of data protection.
  • Binding Corporate Rules, where adopted by the receiving organisation.
  • Microsoft’s Data Protection Addendum (DPA), which contractually commits Microsoft to comprehensive data protection standards.

You may request further information about the safeguards we apply to international transfers by contacting us at the details provided in Section 19.

5.3 Technical and Organisational Security Measures

In alignment with Microsoft’s security standards and the Microsoft Cloud Security Benchmark, we implement comprehensive technical and organisational measures to protect your data from unauthorised access or manipulation. These include:

  • Multi-factor authentication (MFA) enforced across all administrative and user accounts via Microsoft Entra ID Conditional Access policies.
  • Advanced encryption for data at rest (AES-256) and data in transit (TLS 1.2 or higher) across all systems and communications.
  • Role-based access control (RBAC) ensuring that access to personal data is limited to authorised personnel with a legitimate business need.
  • Continuous security monitoring through Microsoft Defender for Cloud, with automated threat detection and incident alerting.
  • Regular security assessments, vulnerability scanning and penetration testing of our infrastructure.
  • Secure development practices aligned with the Microsoft Security Development Lifecycle (SDL) and OWASP guidelines.
  • Cloudflare Web Application Firewall (WAF) and DDoS protection for our public-facing web infrastructure.
  • Data loss prevention (DLP) policies applied across Microsoft 365 to prevent unauthorised data exfiltration.
  • A minimum Partner Centre Security Score of 80 or above, maintained and monitored as part of our ongoing Microsoft partnership compliance.

6. Artificial Intelligence and Automated Processing

In line with current regulatory standards and our commitment to transparency, we disclose that our analytics platform, consulting deliverables, Assessment Tools and Marketplace Offers may utilise Artificial Intelligence (AI) and automated processing to generate insights from provided datasets. This includes the use of Azure OpenAI Service, machine learning models and AI-powered assessment and diagnostic tools.

These systems are designed to assist professional decision-making and do not produce legal or similarly significant effects on individuals without human oversight. We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you without human intervention.

You have the right to request a manual review of any automated output that affects your professional standing. To exercise this right, please contact us using the details in Section 19.

Where our AI systems process personal data, we apply the following safeguards:

  • All AI processing is conducted within Microsoft Azure’s secure infrastructure, subject to the same data residency and encryption standards described in Section 5.
  • We apply the principles of data minimisation, ensuring that AI systems process only the data necessary for the intended purpose.
  • Human oversight is maintained for all AI-generated outputs that inform consequential business decisions.
  • We conduct regular reviews of AI system outputs for accuracy, bias and fairness, in alignment with Microsoft’s Responsible AI principles.

7. Third-Party Service Providers and Data Processors

We share your personal data only with trusted service providers who process data on our behalf under appropriate contractual safeguards, including data processing agreements. We do not sell your personal information to any third party.

7.1 Cloudflare

Our website is hosted and protected by Cloudflare, which also measures how it is used (Cloudflare Web Analytics, without cookies) and checks that our forms are sent by people (Cloudflare Turnstile). Cloudflare acts as a data processor on our behalf and processes the following data to ensure the security, stability and performance of our platform:

  • Your IP address, for the purpose of routing requests and preventing malicious activity.
  • HTTP request headers, including browser type, referring URL and request timestamps.
  • Browser fingerprint data used for bot detection and DDoS mitigation.
  • TLS connection metadata for encrypted communication.

Cloudflare may set essential cookies for security purposes. These cookies are strictly necessary for the legitimate purpose of enabling the use of our Website and ensuring protection against cyberattacks.

Cloudflare Turnstile protects our enquiry and newsletter forms from automated abuse. When you send a form, it checks signals from your browser and connection to confirm that you are a person. It is a security measure and is strictly necessary for the form to work safely.

Cloudflare Web Analytics measures how our Website is used. It records the page visited, the referring page, browser and device type, and the country a visit comes from, and reports them to us as aggregated statistics. It does not set cookies, does not use local storage or any other storage on your device, and does not use your IP address or any fingerprint to identify or track you. When you send an enquiry, the address of the page changes to /contact/sent/ so that the number of enquiries appears in these statistics; nothing about you is recorded by this.

Cloudflare’s data processing is governed by their Data Processing Addendum and their infrastructure operates across a global network, which may involve processing in locations outside the UK. We rely on the safeguards described in Section 5.2 for such transfers.

7.2 Resend

We use Resend to send our Insights newsletter. You can sign up on our Website: on the Insights page, after each article and in the footer. Sign-up is double opt-in: we first send you an email with a confirmation link, and you are added to the newsletter only when you follow that link. Resend processes the following data only where you have signed up and confirmed:

  • Your email address.
  • Your subscription status: whether you are subscribed or have unsubscribed.
  • The record of your consent: that you confirmed your subscription, and when.
  • Send and delivery events for the emails we send you, such as whether an email was delivered.

Every email we send you has an unsubscribe link, and you can also unsubscribe by contacting us directly. Resend sets no cookies on our Website.

Resend stores this data in the United States. We rely on the UK International Data Transfer Addendum to the Standard Contractual Clauses, and on the EU–US Data Privacy Framework and its UK Extension, as the safeguards for this transfer.

7.3 Microsoft

Enquiries sent through the form on our Website are delivered by email to our Microsoft 365 mailbox and recorded in a Microsoft SharePoint list in our own Microsoft 365 tenant; they are not passed to any other party. We reply from Microsoft 365, and if you ask for our evidence pack on the enquiry form, we send it to you by email with our reply; it is not sent through a mailing list and does not add you to one. Microsoft acts as a sub-processor for our consulting services and software products hosted on Azure and Microsoft 365, and facilitates transactions for our Marketplace Offers and may share customer contact information with us in accordance with the Microsoft Publisher Agreement. We process such information solely for transactional purposes or to respond to customer enquiries.

7.4 Legal Disclosure

We may disclose your personal information where required to do so by law, regulation, court order or governmental authority, or where disclosure is necessary to protect our rights, safety or property, or the rights, safety or property of others. If our business or organisation is acquired, merged or sold, your details may be disclosed to our advisers and any prospective purchasers and will be passed on to the new owners.

8. Microsoft Marketplace Offers

Where we publish software products, assessment tools or services on the Microsoft Commercial Marketplace (AppSource or Azure Marketplace), additional privacy provisions apply:

  • Marketplace customer contact information provided to us by Microsoft is used solely for transactional purposes or to respond to customer enquiries about our offers. We do not use this information to direct customers to purchase offers on competing marketplaces.
  • You may be required to agree to our End User Licence Agreement (EULA) or terms of service in addition to this privacy policy when subscribing to a Marketplace Offer.
  • Data processed through Marketplace Offers is subject to the same technical and organisational security measures described in Section 5 of this policy.
  • We are responsible for informing customers of this privacy policy in connection with Marketplace Offers and for ensuring that our data processing complies with all applicable data protection legislation.
  • The privacy policy URL submitted to the Marketplace listing corresponds to the live version of this policy at talastron.com/privacy-policy.

9. Assessment Tools and Quiz Data

Our previous website hosted interactive Assessment Tools including the AI Maturity Assessment, Data Governance Checklist, AI Use Case Prioritisation Matrix, ROI Calculator and other diagnostic or benchmarking tools. These tools are no longer offered. Where you used them:

  • Your assessment responses and input data were processed to generate personalised results, recommendations and reports.
  • If you provided your email address to receive your results, that address was processed for the sole purpose of delivering your assessment report. It was not added to our marketing list without your separate, explicit consent.
  • Aggregate and anonymised assessment data (such as average scores, common maturity levels and sector-level trends) may be used to improve our services and to produce industry benchmarking content. This aggregate data cannot be used to identify you.
  • Assessment results are not shared with any third party without your explicit consent.
  • Individual results are retained for the period set out in Section 12, and the safeguards described in Section 6 apply to any automated scoring that was used.

10. Data Processing During Consulting Engagements

In the course of delivering our consulting services in data analytics, artificial intelligence strategy, Microsoft Fabric, Power Platform and Azure cloud implementations, we may process personal data belonging to our clients or their employees.

Where we act as a data processor on behalf of a client, the terms of data processing are governed by a separate Data Processing Agreement (DPA) or Statement of Work (SOW), which defines the scope, purpose and duration of processing, as well as the technical and organisational measures applied.

Client data processed during engagements is handled in accordance with the principle of data minimisation. We access only the data necessary to deliver the agreed services, and we do not retain client data beyond the duration required by the engagement unless otherwise agreed in writing.

11. Cookies and Tracking Technologies

Our Website does not use cookies for analytics, marketing or advertising, so it does not need to ask for your consent to cookies and does not show a cookie banner. It uses:

  • Essential (Functional) cookies: Set by Cloudflare for security and performance. These are always active and do not require your consent, as they are strictly necessary for the legitimate purpose of enabling the use of our Website. Cloudflare may set cookies such as __cf_bm and cf_clearance for bot management and security challenge purposes.
  • Cookieless analytics: Cloudflare Web Analytics measures how our Website is used without setting cookies or storing anything on your device.
  • Form protection: Cloudflare Turnstile checks that an enquiry or a newsletter sign-up comes from a person. This is strictly necessary to protect our forms.

If we ever introduce a cookie that needs your consent, we will ask for it before setting that cookie, and update this policy and our Cookie Policy, which gives full details of the cookies we use and how to manage them.

12. Data Retention and Deletion

We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:

Data CategoryRetention PeriodBasis
Client engagement dataDuration of engagement plus six years.HMRC and contractual requirements.
Marketplace subscription dataDuration of the subscription plus a 90-day grace period for data portability.Contractual necessity.
Assessment Tool dataIndividual results retained for 12 months. Anonymised aggregate data retained indefinitely.Legitimate interest.
Newsletter dataUntil you withdraw consent or unsubscribe, held by Resend. Deleted automatically when you unsubscribe, and in any case within 30 days of withdrawal.Consent.
Website analytics dataAggregated statistics that do not identify you, held by Cloudflare Web Analytics.Legitimate interest.
Security log dataMaximum of 12 months.Legitimate interest in security monitoring.
Enquiry data24 months from last interaction, held in our Microsoft 365 tenant. Securely deleted if no engagement results.Legitimate interest.
Application usage dataMaximum of 24 months in anonymised form.Legitimate interest in product improvement.

When personal data is no longer required, it is securely deleted or anonymised in accordance with our data retention schedule. Deletion is confirmed once the legitimate interest or service provision ends.

You have the right to request the permanent erasure of your data from our systems and, where technically feasible, from our sub-processors’ environments. We will process such requests within one calendar month, provided there is no overriding legal or contractual requirement to retain the information.

13. Your Legal Rights

Under the UK General Data Protection Regulation, the Data Protection Act 2018 and the Data Use and Access Act 2025, you have the following rights in relation to your personal data:

  • Right of access: You may submit a Subject Access Request to obtain a copy of the personal data we hold about you, and to know why it is needed, what will happen to it, and how long it will be retained for.
  • Right to rectification: You may request that we correct any inaccurate or incomplete personal data.
  • Right to erasure (Right to be Forgotten): You may request that we delete your personal data where there is no compelling reason for us to continue processing it.
  • Right to restrict processing: You may request that we limit the processing of your personal data in certain circumstances.
  • Right to data portability: You may request that we provide your personal data in a structured, commonly used and machine-readable format, or transfer it to another controller.
  • Right to object: You may object to the processing of your personal data where we rely on legitimate interest as the lawful basis.
  • Right to withdraw consent: Where we process your data based on consent, you have the right to revoke that consent at any time and to have your personal data deleted.
  • Rights related to automated decision-making: You have the right to request a manual review of any automated output that affects your professional standing.

To exercise any of these rights, please contact us at privacy@talastron.com or enquiries@talastron.com. We will respond within one calendar month of receiving your request, or as required by applicable law. Please ensure you clearly state who you are so that we can verify your identity.

14. Submitting a Complaint

If you are not satisfied with how we handle your personal data or your complaint about our processing practices, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk
Report a concern: ico.org.uk/make-a-complaint

15. Data Protection Lead and Privacy Contact

Our Data Protection Lead is responsible for overseeing compliance with this privacy policy and applicable data protection legislation.

Data Protection Lead: Sibylle Moller-Sherwood, Director
Privacy contact email: privacy@talastron.com
General enquiries: enquiries@talastron.com

This is the designated privacy contact for the purposes of Microsoft Entra ID tenant configuration and Microsoft Partner Centre compliance.

16. Children’s Privacy

Our website and services are not designed to attract children and it is not our intent to collect personal data from children under the age of consent in their country of residence. We therefore request that children under the age of consent do not submit any personal data to us. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete that information.

17. Third-Party Websites

Our Website and Marketplace Offers may contain links to external websites operated by third parties. This privacy policy does not apply to those third-party websites. We cannot guarantee that these third parties handle your personal data in a reliable or secure manner and recommend that you read the privacy statements of those websites prior to making use of them.

18. Changes to This Privacy Policy

We reserve the right to make amendments to this privacy policy from time to time to reflect changes in our practices, legal requirements or business operations. It is recommended that you consult this privacy policy regularly to be aware of any changes. In addition, we will actively inform you wherever possible. The latest version will always be available on our Website with the effective date clearly stated.

19. Contact Us

For questions about this privacy policy, to exercise your data protection rights, or for any privacy-related enquiry, please contact us:

Talastron Ltd
The Long Barn
Cobham Park Road
Cobham
Surrey
KT11 3NE
United Kingdom

Email
privacy@talastron.com

Phone
+44 7795 467284

ICO Registration
ZB804967

You can also file a complaint with the ICO at www.ico.org.uk.