>
Legal

Privacy Policy

How we collect, use, protect, and respect the personal information you share with us.

Last Updated: January 15, 2025
8 min read
GDPR Compliant
01

Overview

CyberSec ("we," "our," or "us") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or engage with us in any capacity.

We operate under applicable data protection laws including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other regional privacy frameworks. Please read this policy carefully — if you disagree with any of its terms, please discontinue use of our services.

Key Principle

We collect only the data we need, use it only for the purposes stated, and never sell your personal information to third parties. Your data is yours — we are its custodians, not its owners.

02

Information We Collect

We collect information you provide directly, information generated automatically when you use our services, and in some cases, information from third-party sources. The categories below describe what we collect and why.

Personal Identification Data

Full name, email address, phone number, job title, company name — provided when you contact us, request a demo, or create an account.

Usage & Technical Data

IP address, browser type, device identifiers, pages visited, time on site, referral URLs — collected automatically via cookies and analytics tools.

Payment & Billing Data

Billing address and payment method details — processed securely via PCI-DSS compliant third-party payment processors. We never store full card numbers.

Communications Data

Records of correspondence, support tickets, feedback forms, and survey responses when you interact with our team.

Location Data

Approximate geographic location derived from IP address for regional service delivery and fraud prevention. We do not collect precise GPS data.

03

How We Use Your Information

We use the information we collect based on legitimate interests, contractual necessity, legal obligations, or your explicit consent. Specifically, we use your data to:

  • Provide, operate, and improve our cybersecurity services and products
  • Process transactions, send invoices, and manage your account
  • Respond to inquiries, provide technical support, and communicate service updates
  • Send marketing communications where you have opted in — always with an unsubscribe option
  • Conduct security research, threat intelligence analysis, and service diagnostics
  • Comply with legal obligations, enforce our terms, and resolve disputes
  • Detect and prevent fraud, abuse, and security threats
  • Analyze usage patterns to improve the user experience and develop new features

We do not use your data to train third-party AI models, sell advertising, or profile you for purposes unrelated to the services you have engaged us for.

04

Sharing & Disclosure

We do not sell, trade, or rent your personal information. We may share data only in the following limited circumstances:

Service Providers

Trusted vendors who assist us in operations — cloud hosting, payment processing, email delivery, analytics — under strict data processing agreements.

Legal Requirements

When required by law, court order, regulatory authority, or to protect the rights, property, or safety of CyberSec, our users, or the public.

Business Transfers

In the event of a merger, acquisition, or asset sale — you will be notified, and your rights under this policy will be maintained by any successor entity.

05

Data Security

As a cybersecurity company, we hold ourselves to the highest standards of data protection. Our security measures include:

  • AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • Role-based access control with multi-factor authentication for all internal systems
  • Regular penetration testing, vulnerability assessments, and third-party security audits
  • Zero-trust network architecture governing internal access to production environments
  • ISO 27001-aligned information security management practices
  • 24/7 security monitoring with automated anomaly detection and incident response

While no transmission over the internet is 100% secure, we continuously invest in state-of-the-art safeguards. In the event of a data breach, we will notify affected individuals within 72 hours as required by GDPR.

06

Cookies & Tracking

We use cookies and similar tracking technologies to enhance your experience, analyze traffic, and support our marketing efforts. You may control cookie preferences through your browser settings or our cookie consent manager.

Essential Cookies

Required for the site to function — session management, security tokens, and load balancing. Cannot be disabled.

Analytics Cookies

Help us understand how visitors use the site — page views, session duration, and navigation paths. We use anonymized data only.

Marketing Cookies

Used to deliver relevant advertising and measure campaign effectiveness. Opt-in only and fully manageable via our cookie preferences panel.

07

Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@cybersec.com. We will respond within 30 days.

Right to Access

Request a copy of the personal data we hold about you and information about how it is used.

Right to Rectification

Request correction of inaccurate or incomplete personal information we hold.

Right to Erasure

Request deletion of your personal data where we no longer have a lawful basis for processing it.

Right to Object

Object to processing based on legitimate interests, including direct marketing — effective immediately upon request.

Right to Portability

Receive your data in a structured, machine-readable format and transfer it to another controller.

08

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Typical retention periods:

  • Account data: Retained for the duration of our business relationship plus 3 years
  • Contract and billing records: 7 years in accordance with financial regulations
  • Marketing and analytics data: 2 years from last interaction
  • Support and communication records: 3 years from ticket resolution
  • Security logs: 12 months for operational security purposes

Upon expiry of applicable retention periods, data is securely deleted or anonymized in accordance with our data destruction policy.

09

Children's Privacy

Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information without parental consent, please contact us immediately and we will delete it promptly.

10

Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you via email or a prominent notice on our website at least 30 days prior to the change taking effect.

Your continued use of our services after the effective date of the revised policy constitutes your acceptance of the updated terms. We encourage you to review this policy periodically.

11

Contact Our Privacy Team

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, our dedicated Privacy Team is here to help.

Privacy Team

privacy@cybersec.com · Typically responds within 2 business days

Email Privacy Team

Questions About Your Data?

Our privacy team responds within 2 business days — no bots, no runaround.