Privacy Notice

Who are we?

We are Hyperion Technology Limited (‘Hyperion’, ‘we’, ‘us’, ‘our’). We provide a cloud-based compliance monitoring and risk management platform (‘the Platform’) for regulated financial firms, along with associated support services (‘Platform Services’).

Why this Notice?

We take the protection of personal data seriously, not just because the law requires it, but because it’s the right thing to do.

This Notice explains what information Hyperion collects when:

  • you use our website, hyperioncmp.com (‘the Site’);

  • we’re engaged directly to carry out Platform Services; or

  • we receive or gain access to your personal data while providing Platform Services to another company.

Our core principles

We handle personal data in line with the following principles:

  • Lawfulness, fairness and transparency

  • Purpose limitation

  • Minimisation

  • Accuracy

  • Storage limitation

  • Confidentiality and integrity

  • Accountability

What personal data do we collect?

Where we decide how and why personal data is used (i.e. where we act as Controller), this may happen when:

  • you use our website;

  • we provide Platform Services directly to you or your employer;

  • we send updates about Platform features.

Where another organisation decides how personal data is collected and shares it with us (i.e. where we act as Processor), this may happen when we:

  • provide Platform Services or general consultancy to other companies.

Where we act as Processor, please also check the privacy notice of the company that engaged us, it will explain what data is collected, how it’s used, and your rights.

Any other website you visit, including ones linked from our Site, is governed by that site’s own terms and policies, not ours.

Who do we share your data with?

Given our size, we don’t routinely share personal data. The following may occasionally have limited access:

  • our outsourced accounting and tax advisors.

When you use our website

Contact forms: If you submit an enquiry via our website forms, it’s emailed to Hyperion’s Directors and retained in line with our retention periods. We use Lettermint (based in the EU) to handle this process; anything you submit is held by Lettermint for 28 days before deletion.

We expect only limited personal data here — typically a business email address and a brief description of the service required. By using this form, you consent to your data being processed as described. You can withdraw this consent at any time by emailing info@hyperioncmp.com.

General site use: Our Site uses a single cookie containing an encrypted session ID, needed for the Site to function — we don’t use any other cookies.

We use Umami to gather anonymous usage statistics. Umami doesn’t use cookies and strips out any personally identifiable information, so no personal data is collected. It complies with GDPR, CCPA and other privacy regulations.

When we provide Platform Services

When engaged directly to provide Platform Services, we may receive:

  • names

  • contact details

  • job roles and titles

  • working hours and availability

  • details of the compliance or regulatory challenges the company faces

  • names and details of the company’s own clients or customers, where needed to fulfil our responsibilities

We collect this data under a combination of contractual necessity and legitimate interest, specifically, our interest in tailoring and delivering effective Platform Services.

Where we’re given access to the Platform, we may also encounter a broader range of personal data held by our clients. In these cases, we act on the client’s instructions and follow their own privacy notices and data protection policies.

Our legal basis here is contractual necessity. Data is retained for as long as the relevant contract requires. Where it’s within our control, we delete data or suspend access once a contract ends, or retain it for up to seven years (or longer if the client requires it).

Data security

We maintain security measures to protect against accidental loss, misuse, unauthorised access, alteration or disclosure of your data. Access is limited to those who need it - staff, agents, contractors and other third parties. All act only on our instructions, under a duty of confidentiality. We don’t permit third-party providers to use your data for their own purposes. We also don’t use automated decision-making to process personal data.

We may occasionally be legally required to disclose data to a third party, over whom we have limited control regarding how it’s subsequently protected.

We have procedures in place to respond to any suspected data breach, and will notify you and any relevant regulator where legally required to do so.

Your rights

Under the Data Protection (Bailiwick of Guernsey) Law, 2017, you have the right to:

  • data portability: request that your data be transferred to another party

  • access: request a copy of the personal data we hold about you (a ‘subject access request’)

  • object: object to processing based on legitimate interest, direct marketing, or public interest/historical/scientific purposes

  • rectification: correct inaccurate or incomplete data

  • erasure: request deletion where there’s no good reason for us to keep processing it

  • restriction: ask us to pause processing, for example while we verify accuracy

  • notification: be informed of any rectification, erasure or restriction

  • object to automated decisions: not be subject to decisions based solely on automated processing

  • withdraw consent: where you’ve given consent for a specific type of processing, withdraw it at any time

To exercise any of these rights, contact info@hyperioncmp.com.

Making a complaint

If you’re unhappy with how we’ve handled your data, please contact us first at info@hyperioncmp.com. You can also complain directly to the Office of the Data Protection Authority (‘ODPA’):

Block A, Lefebvre Court, Lefebvre Street, St Peter Port, GY1 2JP

Or via their website.

Changes to this Notice

We may update this Notice at any time; new versions will be published on our website, and we may notify you separately where appropriate. This Notice was last updated on 22 June 2026.

>