Privacy Notice

Jurisdiction: United Kingdom

Effective Date: September 15, 2026
Last Updated: September 2026

1. Introduction

This Privacy Notice explains how Dionaea collects, uses, stores, shares and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

It applies when you:

  • visit or use our website, dionaeax.com;
  • contact us by email, telephone, through a website form or by another communication channel;
  • communicate or interact with us in a professional or business capacity;
  • attend an event, meeting, webinar or conference involving Dionaea;
  • receive a professional or business development communication from us;
  • provide services to us, represent a supplier, partner, client or prospective client; or
  • otherwise engage with Dionaea.

This Privacy Notice does not apply to personal data processing undertaken by Dionaea as part of human intelligence (HUMINT) collection, intelligence and investigative operations, litigation support, due diligence inquiries, asset tracing, risk assessments, or other client-directed intelligence engagements. Such activities are subject to separate engagement terms and contractual obligations with you, legal instructions, professional confidentiality requirements, and applicable laws and regulations. The categories of personal data processed, the purposes of processing, and the applicable legal bases may vary according to the specific operational context and are governed by the relevant engagement documentation.

2. Who We Are

For the purposes of applicable data protection laws, the controller responsible for your personal data is: Rivka Lavi Belinstein (rivka@dionaeax.com)

Dionaea Ltd., trading as Dionaea, Company registration number: 516068400

Registered address: 159 Yigal Alon St. Tel-Aviv

Country of incorporation: Israel

UK representative (for the purposes of Article 27, UK GDPR): Solomon Taylor & Shaw LLP, 3 Coach House Yard, Hampstead High Street, London NW3 1QF

Email: office@dionaeax.com

Website: www.dionaeax.com

References in this Privacy Notice to “Dionaea”, and its website “www.DionaeaX.com”, “we”, “our” or “us” refer to the legal entity identified above.

Our data privacy manager can be contacted at office@dionaeax.com.

3. Personal Data We May Collect

Depending on how you interact with us, we may collect and process the following categories of personal data.

3.1 Website and technical information

When you visit our website, we may collect:

  • Internet Protocol address;
  • browser type and version;
  • device type;
  • operating system;
  • time zone and approximate location derived from technical data;
  • pages visited;
  • time spent on the website;
  • referring website;
  • navigation and interaction data;
  • cookie identifiers; and
  • information required to maintain the security and technical operation of the website.

3.2 Identity and professional information

This may include:

  • your name;
  • job title;
  • employer, firm or organization;
  • professional role, practice area and seniority;
  • professional biography;
  • business address;
  • business telephone number;
  • professional email address;
  • professional qualifications, memberships and affiliations;
  • publicly available information concerning your professional activities; and
  • information about matters, sectors or services that may be relevant to your professional role.

3.3 Contact and communication information

This may include:

  • correspondence with us;
  • information submitted through our contact forms;
  • requests for information;
  • meeting records;
  • business development communications;
  • your communication preferences;
  • records of whether you opened, replied to or opted out of communications, where such functionality is lawfully used;
  • notes relating to previous professional interactions; and
  • records of requests not to receive further communications.

3.4 Client, prospective client and business relationship information

This may include:

  • information provided when considering or establishing a business relationship;
  • information relating to requested services;
  • information required for conflict, legal, compliance or risk checks;
  • billing and transaction information;
  • contractual and engagement information;
  • records of meetings, proposals and negotiations; and
  • information relating to representatives, advisers, suppliers and professional contacts.

3.5 Information from public and professional sources

We may collect professional contact information from sources other than the individual concerned, including:

  • law firm and company websites;
  • professional directories;
  • publicly accessible corporate records;
  • professional networking platforms;
  • conference, webinar and event materials;
  • speaker, participant or membership lists made available for professional networking purposes;
  • legal and industry publications;
  • professional rankings and directories;
  • publicly available court, regulatory and corporate information;
  • referrals and introductions from professional contacts; and
  • third-party business information providers, where their use of the information is lawful.

We do not treat the public availability of personal data as consent to receive marketing communications. We assess whether the proposed use is relevant, proportionate and reasonably connected to the individual’s professional role.

4. How We Use Personal Data

We may use personal data for the following purposes:

4.1 Website operation

  • to operate, administer and maintain our website;
  • to respond to website enquiries;
  • to improve website content, performance and functionality;
  • to understand how visitors use the website;
  • to identify and address technical problems; and
  • to protect the website against misuse, fraud, cyber threats and unauthorized access.

4.2 Client and professional relationships

  • to respond to enquiries and requests;
  • to evaluate potential engagements;
  • to prepare proposals;
  • to enter into and manage contractual relationships;
  • to provide services;
  • to communicate with clients, prospective clients, advisers, suppliers and partners;
  • to administer payments and business records;
  • to manage professional relationships;
  • to perform conflict, compliance, legal and risk checks; and
  • to establish, exercise or defend legal rights.

4.3 Business development and professional communications

We may use professional contact information to:

  • identify organizations and professionals whose work may be relevant to our services;
  • contact individuals in their professional capacity;
  • introduce Dionaea and its services;
  • provide information about our professional capabilities;
  • follow up on meetings, introductions, conferences, webinars or previous communications;
  • discuss possible collaboration, referrals or business opportunities;
  • invite professional contacts to relevant events or presentations;
  • share professional insights, case studies, publications or updates; and
  • maintain records of business development activity.

Any such communication will be directed at the recipient in their professional capacity and should be relevant to their role, organization, practice area or publicly stated professional interests.

We will not continue to send direct marketing communications to an individual who has objected or asked us to stop.

4.4 Compliance and protection

We may process personal data:

  • to comply with applicable laws, regulations, court orders and lawful requests;
  • to maintain appropriate business and compliance records;
  • to investigate suspected misuse of our website;
  • to prevent or detect fraud or unlawful activity;
  • to protect our legal rights, confidentiality, personnel, clients and systems; and
  • where necessary in connection with legal proceedings or regulatory matters.

5. Lawful Bases for Processing

Where the UK GDPR, the EU General Data Protection Regulation, Data Protection Act 2018, Data (Use and Access) Act 2025 (as commenced), or another law requiring a lawful basis applies, we rely on one or more of the following bases.

5.1 Legitimate interests

We may process personal data where necessary for our legitimate interests or those of a third party, provided that those interests are not overridden by the individual’s rights and interests. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests.

Our legitimate interests may include:

  • operating and protecting our business and website;
  • responding to professional enquiries;
  • developing our business;
  • identifying and communicating with prospective business clients, professional advisers, law firms, companies and referral partners;
  • maintaining professional relationships;
  • providing relevant B2B information to individuals in their professional capacity;
  • preventing fraud and unauthorized activity;
  • maintaining network and information security; and
  • establishing, exercising or defending legal claims.

When relying on legitimate interests for business development or direct marketing, we consider:

  • the individual’s professional role;
  • the relevance of our services to that role;
  • the source of the information;
  • the nature and frequency of the proposed communication;
  • the individual’s reasonable expectations;
  • the potential effect on the individual; and
  • whether the individual can easily object or opt out.

5.2 Contract

We may process personal data where necessary:

  • to take steps at your request before entering into a contract; or
  • to perform a contract with you or the organization you represent.

5.3 Legal obligation

We may process personal data where necessary to comply with a legal or regulatory obligation.

5.4 Consent

Where required by applicable law, we may request consent for a specific purpose, including certain electronic marketing communications or non-essential cookies.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing undertaken before consent was withdrawn.

5.5 Legal claims and substantial public interest

Where applicable, we may process information where necessary for the establishment, exercise or defense of legal claims or for another legally recognized substantial public interest purpose.

6. Direct Marketing and B2B Communications

We may send relevant professional communications to corporate bodies and to individuals acting in a business or professional capacity, where permitted by applicable law.

Electronic communications directed to corporate subscribers, including limited companies and limited liability partnerships, may be sent without prior consent where permitted under the Privacy and Electronic Communications Regulations.

However, where an email address or other information identifies an individual, we will continue to process that personal data in accordance with applicable data protection law.

We will:

  • identify ourselves clearly;
  • use contact details only where we believe the communication is professionally relevant;
  • provide a simple way to object to further communications;
  • honor objections and opt-out requests;
  • maintain an appropriate suppression record to prevent accidental future contact; and
  • comply with stricter consent requirements where they apply, including where the recipient is an individual subscriber, sole trader, certain partnership structures or is located in a jurisdiction requiring prior consent.

We do not assume that a professional email address published online constitutes consent to receive marketing.

7. Your Right to Object to Direct Marketing

You have the right to object at any time to the processing of your personal data for direct marketing purposes.

When you object, we will stop using your personal data for that purpose.

You may object by:

  • following the opt-out links in any marketing communication; or
  • replying to the relevant email or contacting us at office@dionaeax.com.

We may retain your name, business email address and opt-out status on a suppression list. This limited record is retained solely to ensure that your objection is respected and that you are not inadvertently contacted again for direct marketing purposes.

Opting out of direct marketing will not affect service-related or other non-marketing communications that are necessary for administrative, security, contractual or legal purposes.

8. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies may include:

8.1 Strictly necessary cookies

These cookies are required for the website to operate securely and correctly. They may be used without consent where permitted by law.

8.2 Analytics cookies

These cookies help us understand how visitors use our website, including which pages are visited and how users navigate the website.

8.3 Functional cookies

These cookies may remember preferences or provide enhanced website functionality.

8.4 Marketing cookies

Where used, these cookies may support advertising, campaign measurement or user tracking across websites.

Where applicable law requires consent, we will not place non-essential cookies before obtaining consent through an appropriate cookie management mechanism.

You can manage your preferences through our cookie banner or browser settings. Disabling certain cookies may affect website functionality.

A separate Cookie Policy providing additional information regarding the specific cookies used on the website can be found HERE (Cookie Policy – Dionaea – Unique business intelligence).

9. Sharing Personal Data

We do not sell or rent personal data.

We may share personal data with:

  • website hosting and maintenance providers;
  • email, cloud storage and business communication providers;
  • customer relationship management providers;
  • analytics and website security providers;
  • professional advisers, including lawyers, accountants and compliance advisers;
  • contractors and service providers supporting our business operations;
  • regulators, courts, law enforcement authorities and public bodies where legally required;
  • potential purchasers, investors or advisers in connection with a corporate transaction, subject to appropriate confidentiality protections; and
  • other parties where necessary to establish, exercise or defend legal rights.

Service providers are permitted to use personal data only as necessary to provide services to us and must protect it in accordance with applicable law and contractual obligations.

10. International Data Transfers

Dionaea operates internationally and may process personal data anywhere in the world.

Some of our service providers may process personal data outside the country in which it was collected, including outside the United Kingdom or European Economic Area.

Where required, we use legally recognized safeguards for international transfers. These may include:

  • a transfer to a country recognized as providing an adequate level of data protection under an applicable ‘adequacy decision’;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission Standard Contractual Clauses;
  • the European Commission Standard Contractual Clauses;
  • contractual, organizational and technical safeguards; or
  • binding corporate rules recognized or approved under applicable law; or another legally permitted transfer mechanism.

Further information about safeguards applicable to a particular transfer may be requested by contacting office@dionaeax.com.

11. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, regulatory, contractual, accounting, security and dispute resolution requirements.

Retention periods depend on:

  • the nature and sensitivity of the information;
  • the purpose for which it is processed;
  • the existence and duration of a business relationship;
  • whether there is an ongoing enquiry, proposal or engagement;
  • applicable limitation periods;
  • legal and regulatory requirements; and
  • the risk associated with retaining or deleting the information.

As a general approach, the following periods apply:

  • website enquiries and related correspondence may be retained for up to three years after the most recent meaningful interaction;
  • prospective business contact information may be reviewed periodically and deleted or anonymized when it is no longer relevant;
  • client and contractual records may be retained for the duration of the relationship and for seven years thereafter, subject to applicable requirements;
  • website security logs may be retained for one year;
  • analytics data may be retained according to the settings of the relevant analytics provider; and
  • suppression records may be retained for as long as reasonably necessary to ensure that an opt-out request continues to be respected.

We may retain information for longer where required by law or where necessary in connection with actual or anticipated legal proceedings.

12. Data Security

We use reasonable technical and organizational measures designed to protect personal data from:

  • unauthorized access;
  • unlawful processing;
  • accidental loss;
  • alteration;
  • disclosure; and
  •  

These measures may include access controls, authentication measures, encryption where appropriate, secure service providers, staff confidentiality obligations, system monitoring and internal data handling procedures.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

No electronic transmission or storage system can be guaranteed to be completely secure. You should avoid submitting highly sensitive or confidential information through general website forms unless appropriate secure arrangements have been agreed.

13. Your Data Protection Rights

Depending on your location and applicable law, you may have the right to:

  • request access to personal data we hold about you (commonly known as a “subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are processing it lawfully;
  • request correction of inaccurate or incomplete data. This enables you to have incomplete or inaccurate data we hold about you corrected, although we may need to verify the accuracy of any new data you provide;
  • request deletion of personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it, including where you have successfully objected, where we may have processed it unlawfully or where we are required to erase it to comply with law. Legal exceptions may apply and will be explained to you, if relevant;
  • request restriction of processing. This enables you to ask us to suspend processing where you contest the accuracy of the data, our use is unlawful but you do not want erasure, we no longer need the data but you need it for legal claims, or you have objected while we verify whether we have overriding legitimate grounds;
  • object to processing based on legitimate interests. This enables you to object where we rely on our legitimate interests or those of a third party, including profiling based on those interests. We may continue processing if we can demonstrate compelling legitimate grounds that override your rights;
  • object at any time to processing for direct marketing. This is an absolute right, and we will stop using your personal data for that purpose when you object;
  • request transfer of certain personal data in a portable format. This enables you to receive, or ask us to transmit to another controller, personal data in a structured, commonly used and machine-readable format. This right generally applies only to automated information you provided to us and processed on the basis of your consent or a contract;
  • withdraw consent where processing is based on consent. This enables you to stop future processing based on that consent, but does not affect the lawfulness of processing before withdrawal and may affect our ability to provide certain services;
  • request information about international transfer safeguards. This enables you to ask for details of the safeguards used for a particular transfer, subject to applicable legal restrictions; and
  • lodge a complaint with an applicable data protection authority. This enables you to ask the relevant regulator to review our processing, subject to its procedures and jurisdiction.

These rights are subject to legal conditions, limitations and exemptions.

We may need to request specific information from you to help us confirm your identity and ensure that your request relates to personal data you are entitled to receive. This is a security measure to prevent personal data being disclosed to anyone who has no right to receive it. We may also ask for further information about your request to help us respond more quickly.

To exercise a right, contact us at office@dionaeax.com, explaining the right you wish to exercise and, where possible, the personal data or processing to which your request relates.

You will not usually have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or refuse to comply in those circumstances.

We try to respond to all legitimate requests within one month. Occasionally it may take longer if your request is particularly complex or you have made a number of requests. If so, we will notify you and keep you updated.

14. Complaints

We encourage you to contact us first so that we can address any concern. Before contacting the ICO, please first make your complaint to us or ask us for clarification if there is something you do not understand. The ICO will expect you to have done this before reviewing your complaint.

You may also have the right to complain to the UK Information Commissioner’s Office (www.ico.org.uk).

15. Children

Our website and services are intended for businesses and professionals and are not directed at children.

We do not knowingly collect personal data from children through the website. If you believe that a child has provided personal data to us, please contact us immediately.

16. Third-Party Websites

Our website may contain links to websites operated by third parties.

We do not control and are not responsible for the privacy, security or content practices of third-party websites. You should review the privacy information provided by those websites.

17. Automated Decision-Making

We do not use personal data collected through our website or ordinary business development activities to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

18. Changes to This Privacy Notice

We may update this Privacy Notice to reflect changes in our practices, services, technology or legal obligations.

The updated version will be published on this page and identified by the “Last Updated” date.

Material changes may be communicated by additional means where appropriate.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example if your business address, telephone number or email address changes.

19. Contact Us

Questions, requests and concerns regarding this Privacy Notice or our processing of personal data should be sent to:

Dionaea Ltd.
Trading as Dionaea and/or DionaeaX
159 Yigal Alon St., Tel-Aviv.
Email: office@dionaeax.com