legal · privacy
Privacy Policy
This notice describes what personal data BigDataCyberCloud (operated by RHC Solutions) collects when you visit this site, how we use it, and the rights you have over it under the EU GDPR, the UK GDPR, and equivalent laws.
Last updated: 10 June 2026.
1. Who we are
BigDataCyberCloud.com is a knowledge property of RHC Solutions, an IT services company operating since 1994. The data controller for this site is RHC Solutions. If you need to contact us about your personal data, write to [email protected] or use the contact form at rhcsolutions.com/contact.
2. What we collect
We minimise data collection by default. The categories below are everything we may collect; most visits to this site will only ever generate the first two.
- Server logs. Every HTTP request to this site produces a log line containing the IP address, request path, response code, timestamp, user-agent string, and referrer. Logs are retained for up to 30 days for abuse mitigation and rotated thereafter.
- Strictly-necessary cookies. A small number of cookies are set to keep the site working: session identifiers for the admin area, a one-time first-run flag, and CSRF protection tokens. None of these track you across sites.
- Analytics cookies (only if you consent). If you accept analytics on the cookie banner, Google Analytics 4 sets cookies that record aggregated, pseudonymised behaviour (pages viewed, session duration, country-level location). IP addresses are truncated before storage.
- Form submissions. If you fill in a contact or careers form, we store the data you submitted (name, email, message, any attached resume) so we can reply.
- Authentication data (admin users only). Email, bcrypt-hashed password, TOTP secret, and a per-account login history. This applies only to staff accounts on the
/admin area.
3. Why we use it (lawful bases)
- Server logs + strictly-necessary cookies — legitimate interest (running the site, fraud prevention).
- Analytics cookies — your consent, withdrawable at any time via the cookie banner.
- Form submissions — to answer your enquiry (pre-contractual measures at your request) and, where applicable, the eventual contract.
- Admin authentication — necessary for the performance of our staff contracts.
4. Who we share it with
We do not sell personal data. We share it only with processors who help us run the site:
- Cloudflare — CDN, DDoS protection, TLS termination.
- Brevo (Sendinblue) — transactional email (e.g. contact-form replies, admin notifications).
- Google Analytics — analytics, only if you have consented.
- Telegram (Bot API) — internal operator notifications when forms are submitted or admin events occur. Telegram only ever receives the data you submitted to the form (no IPs beyond what's already public).
All processors are bound by data-processing agreements. Some are based outside the EEA; transfers rely on Standard Contractual Clauses where required.
5. How long we keep it
- Server logs: 30 days.
- Analytics data: 14 months (GA4 default minimum).
- Form submissions: until your enquiry is closed, then up to 24 months for audit.
- Job applications: up to 24 months after the decision, unless you ask us to delete sooner.
- Admin accounts: for the lifetime of the staff relationship; deactivated within 7 days of leaving.
6. Your rights
Under GDPR/UK GDPR you can ask us, at any time, to:
- Access the personal data we hold about you;
- Correct anything that's wrong;
- Delete it (right to erasure) — subject to legal retention obligations;
- Restrict or object to processing;
- Receive a portable copy (data portability);
- Withdraw consent for analytics or any other consent-based use.
Send requests to [email protected]. We respond within one month. You also have the right to lodge a complaint with your local supervisory authority.
7. Security
Traffic to this site is encrypted in transit (TLS 1.2+). The admin area requires email/password plus a one-time TOTP code. Failed login attempts are IP-rate-limited. Account passwords are stored as bcrypt hashes, never in clear text. We continually monitor dependencies for known vulnerabilities (via Aikido) and apply security patches on a weekly cadence.
8. Changes
If we change this notice we'll publish the new version here and update the date at the top. Material changes (new data uses, new categories of processor) will be notified to anyone we've previously corresponded with.
← Back to the field guide