Privacy notice
IntelSensus assessments, including the Mind Yer Business free cyber check
Last updated: 5 October 2026 · Version 1.1
What changed in version 1.1. Added EU GDPR and Republic of Ireland coverage and the Irish Data Protection Commission (sections 10, 11). Corrected what the funder receives: aggregate figures plus your full postcode for monitoring, while published statistics use only the outward code (sections 1, 2, 3, 5, 8). Replaced the partner-invited text with how the CyberAxis partners share data (section 1). Added a line that providing the information is needed to use the assessment (section 3). Set the data-protection contact as privacy@talentsensus.com (sections 10, 12). Added a cookies cross-reference (section 2). Clarified the three-year retention is our own policy, not a legal mandate (section 7).
This notice explains what personal information we collect when you take an assessment on the IntelSensus platform, why we collect it, who we share it with, how long we keep it and what your rights are. It covers the Mind Yer Business free cyber check at mindyerbusinessni.com and every assessment that runs on intelsensus.com.
We've tried to keep it short and plain. If anything isn't clear, ask us using the details in section 12.
1. Who we are
IntelSensus (the free cyber assessment tool under the CyberAxis project) is a product of TalentSensus. TalentSensus is a trading name of Upskill Enterprise Ltd, a company registered in Northern Ireland (company number NI632984), registered office 12–16 Castle Lane, Belfast, BT1 5DA.
When you take an assessment, buy a report from us, or otherwise use IntelSensus, Upskill Enterprise Ltd is the controller of your personal information. That means we decide how it is used and we are responsible for protecting it.
About Mind Yer Business and the CyberAxis partners
Mind Yer Business is a CyberAxis campaign. CyberAxis is part of CyberSpark and TalentSensus, and is funded by UK Government through the TechFirst programme. CyberAxis is delivered by three separate companies working together under the CyberAxis name: TalentSensus (Upskill Enterprise Ltd), CyberSpark and FaultLine.
Who controls your assessment data. TalentSensus is the controller of your assessment answers and report. To deliver the project and report on it, we may share the minimum information needed with CyberSpark and FaultLine, under a written data sharing agreement. Where a partner only acts on our instructions, it does so as our processor. Where a partner uses information for its own part of the project, we share only what is necessary and each of us is responsible for our own use of it. We will not use your assessment answers to market unrelated products.
-
Your individual answers and report. Only the staff who need to see them do. We do not publish or share your individual answers or report in any form that identifies you or your business, except with your specific consent.
-
What our funder receives. TechFirst and the UK Government receive aggregate figures (for example how many businesses took part), plus the limited information they need to monitor and evaluate a publicly funded programme, which includes your full postcode. They do not receive your assessment answers or your report. Any statistics we publish use only the outward part of the postcode (the area only); see sections 2 and 8.
2. What we collect
| What | Examples | Where it comes from |
|---|---|---|
| Your account | Your name and email address | You, when you sign up |
| Your business | Business name, sector, size and full postcode | You, during the assessment |
| Your answers and results | Your answers, your scores and the report we produce | You, and our scoring of your answers |
| Phone number | Only if you choose to give it | You |
| Payment | Only on the paid route (£199). Card payments are handled entirely by Stripe and we never see or store your card number. We keep a record that you paid. | You, via Stripe |
| Technical information | IP address, browser type, and the times you sign in | Your device, when you use the site |
Your postcode. We collect your full postcode for two reasons: to confirm your business is in Northern Ireland (so the Mind Yer Business report is free), and because our funder needs it to monitor and evaluate the programme. For any statistics or trend analysis, we use only the outward part of the postcode, which identifies an area, not a street or a specific business.
Most of what the assessment asks is about your business, not about you. Information about a business isn't personal data in law, but we protect it to the same standard anyway (see section 8). We don't ask for special category information such as health, religion or ethnicity, and we ask you not to include it in any free-text answers.
Cookies. Our separate cookies policy explains the cookies and similar technologies the websites use, and how you control them.
3. How we use it, and our legal basis
| What we use it for | Our legal basis |
|---|---|
| Creating your account, letting you sign in, and saving your progress | Contract: we need it to provide the assessment you asked for |
| Scoring your answers, producing your report and emailing you when it's ready | Contract |
| Checking your postcode is in Northern Ireland, so the Mind Yer Business report is free | Contract |
| Taking payment on the paid route only | Contract, and legal obligation for financial records |
| Producing anonymised, combined figures, and reporting to our funder on a publicly funded programme, including your full postcode for monitoring and evaluation | Legitimate interests: to give the local economy useful evidence and to report on public funding. Your business is never identifiable in published figures (section 8). |
| Sharing the minimum necessary with the CyberAxis partners (CyberSpark, FaultLine) to deliver the project and report on it | Contract and legitimate interests, under a data sharing agreement |
| Keeping the platform secure, preventing fraud and misuse, and fixing problems | Legitimate interests |
| Keeping records for the required period | Legal obligation |
| Using a quote from your answers, or naming your business in any output | Consent. We only do this if you specifically agree, and you can change your mind at any time. |
You don't have to give us this information, but we need it to create your account and produce your assessment, so without it we can't provide the service. Where we rely on legitimate interests, we've weighed them against your rights, and you can object at any time (section 10). We will not sell your information. If we'd like to send you anything beyond your results and service emails, we'll ask first.
4. Automated scoring
Your score and report are produced automatically from your answers. They're guidance to help you improve your cyber security. They don't lead to any decision with a legal or similarly significant effect on you or your business. If you think a result is wrong, contact us and a person will look at it.
5. Who we share it with
We use a small number of trusted service providers, called processors, to run the platform. They only use your information on our instructions and under a written contract.
| Provider | What they do |
|---|---|
| Amazon Web Services | Hosts the platform and its database, in Ireland (EU) |
| Cloudflare | Security and fast delivery of both websites; hosts mindyerbusinessni.com |
| Clerk | Sign-up, sign-in and verification emails |
| Twilio SendGrid | Service emails, such as “your report is ready” |
| Mailgun | Email for intelsensus.com |
| Stripe | Card payments (paid route only) |
We also share information:
-
with the CyberAxis partners, CyberSpark and FaultLine, where necessary to deliver the project, report on it or carry out later work packages. We share only the minimum needed, under a written data sharing agreement, and only for CyberAxis purposes;
-
with our funder, TechFirst (UK Government): aggregate figures, plus the limited monitoring and evaluation information it requires, which includes your full postcode. It does not receive your answers or your report;
-
where the law requires it, for example with the police or a regulator if we receive a valid legal request.
6. Where your data is held
Your information is stored in Ireland, within the EU, which the UK recognises as giving equivalent protection.
Some of the services we use for sign-in, email, website security and card payments are run by companies based in the United States, and may process limited information, such as your name, email address or IP address, there. When that happens, we make sure it's protected to UK standards. We rely on the UK–US data bridge where the company is certified under it, or otherwise on contract terms approved by the Information Commissioner. Ask us if you'd like more detail.
7. How long we keep it
| What | How long |
|---|---|
| Your answers, scores and report | 3 years from when you complete the assessment. This is our own retention policy, not a legal requirement. Then deleted or fully anonymised. |
| Your account | Until you ask us to close it, or 3 years after you last used it |
| Payment records (paid route only) | 6 years, as required for tax records |
| Security and sign-in logs | 12 months |
| Anonymised, combined figures | These no longer identify anyone, so we may keep them |
8. How we keep it safe
-
Your data is stored in Ireland, encrypted, on infrastructure with restricted access.
-
Phone numbers are encrypted individually.
-
Sign-in uses a dedicated identity service, and staff access is limited to those who need it.
-
We follow our published Anonymisation and Aggregation Policy for any figures we produce. It means:
- no business can be picked out of a published result;
- small groups are combined or withheld (we never publish a figure based on fewer than 10 businesses);
- we analyse location using only the outward part of the postcode (the area), and full postcodes are never published;
- your business is never named without your specific consent.
9. Answering anonymously
Some assessments let you answer anonymously, without giving contact details. If you do, we can't find your response afterwards, so we can't correct, export or delete it for you. We'll always tell you before you start if an assessment works this way.
10. Your rights
You have the right to: access the personal information we hold about you; have it corrected if it's wrong; have it deleted; restrict how we use it; object to us using it on the basis of legitimate interests; move it to another organisation (data portability); and withdraw consent at any time, where we rely on consent.
If you are in the Republic of Ireland or the EU. The EU GDPR also applies to you. You have the same rights as above, and you can also complain to the Irish Data Protection Commission as well as, or instead of, the UK regulator (section 11).
To use any of these rights, email us at privacy@talentsensus.com. We'll reply within one month. We may need to check your identity first. There's usually no charge.
Separately from your legal rights, if you believe your business could be identified in any figure we've published, you can ask how it was produced and ask for it to be reviewed or withdrawn. We'll answer within 20 working days.
11. Complaints
If you're unhappy with how we've handled your information, please tell us first and we'll try to put it right. You also have the right to complain to a data protection regulator:
-
United Kingdom: the Information Commissioner's Office (ICO), ico.org.uk/make-a-complaint, phone 0303 123 1113.
-
Republic of Ireland or the EU: the Irish Data Protection Commission, dataprotection.ie.
12. Contact us
Data protection lead, Upskill Enterprise Ltd (trading as TalentSensus).
-
Email: privacy@talentsensus.com
-
Post: 12–16 Castle Lane, Belfast, BT1 5DA
General questions about the Mind Yer Business campaign can go to info@cyberaxis.co.uk.
13. Changes to this notice
We'll update this notice if anything about how we use your information changes. The date at the top shows when it was last changed. If a change is significant, we'll tell you before it takes effect.