Privacy notice
What we collect
For the people who use the service: name, work email address, job title, and the times and addresses from which they sign in. For the organisation: the asset inventory, findings, risk register, controls, evidence, and anything else deliberately entered or imported.
Why we hold it
To provide the service under our contract with the customer organisation. Sign-in records exist to detect and investigate unauthorised access, which is a legitimate interest and, for many of our customers, a regulatory requirement.
What we do not do
We do not sell data. We do not use customer data to train models. There is no third-party analytics or advertising script on any page of this service; the content security policy would block one.
Where it lives
In a managed PostgreSQL database in our primary hosting region, encrypted at rest by the provider. Alternative regions are available on a Custom plan. Payment processing is carried out by Stripe, which acts as an independent controller for the payment data it holds.
How long
For as long as the organisation has an account. On cancellation, data is retained for ninety days so it can be exported or the account reinstated, then deleted. Audit records are retained for the period the organisation configures, which defaults to two years.
Your rights
Individuals may ask for access to, correction of, or deletion of their personal data, and may object to processing. Requests go to [email protected]. Where we process data on behalf of a customer organisation we will refer the request to them, because it is their contract that governs it.
Last updated September 2026 · CyberRisk Protection Ltd