Privacy Notice
Last updated: 23/07/2026 · Version 2.0
1. Who we are (Controller)
Cyber Essential Check (the "Service") is operated by Cyber Essential Check Ltd ("we", "us", "our"), a company registered in England and Wales.
- Registered office: [TBD — update in this notice]
- Company number: [TBD]
- ICO registration number: [TBD]
- Data protection contact: privacy@cyberessentialcheck.co.uk
- EU/EEA representative (Article 27 GDPR): [TBD if serving EU users]
2. Personal data we process
- Account data: name, work email, job title, phone number, employer, hashed password (via Supabase Auth), IP address, session tokens.
- Assessment data: domains you enter, questionnaire answers, scan results and derived findings, scope information (staff/device counts, cloud services used).
- Connector data (optional): OAuth tokens (encrypted at rest with AES-256-GCM) and read-only metadata from services you connect (e.g. Microsoft 365, Google Workspace).
- Billing data: processed by our payment processor; we hold plan tier, invoice history and last-four of card only.
- Product telemetry (with consent): aggregated page views and feature usage.
3. Purposes and lawful bases (UK GDPR Art. 6)
- Provide the Service — performance of contract (Art. 6(1)(b)).
- Security, fraud prevention, audit logs — legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).
- Service transactional emails — performance of contract.
- Analytics and product improvement — consent (Art. 6(1)(a)); withdrawable at any time.
- Marketing communications — consent, or soft opt-in for existing customers under PECR reg. 22(3); unsubscribe in every message.
4. Sharing and sub-processors
We share personal data with vetted sub-processors acting on our documented instructions. A current list is available in our Data Processing Addendum and includes:
- Supabase (database, auth, storage) — EU region.
- Cloudflare (edge compute, DDoS/WAF).
- Payment processor (Stripe or Paddle — see checkout).
- Transactional email provider.
We do not sell personal data. We do not share it for cross-context behavioural advertising.
5. International transfers
Where personal data leaves the UK/EEA, transfers are protected by the UK International Data Transfer Addendum, EU Standard Contractual Clauses (2021/914), and supplementary measures (encryption in transit and at rest). A copy of the safeguards is available on request.
6. Retention
- Account and assessment data: for the life of your account, then 30 days.
- Scan history and evidence packs: 24 months (or until you delete them).
- Billing records: 6 years (UK statutory).
- Security logs: 12 months.
7. Your rights
Under UK GDPR / EU GDPR you have the right to:
- Access, rectify, erase or restrict processing of your personal data.
- Portability (structured, machine-readable export).
- Object to processing based on legitimate interests or direct marketing.
- Withdraw consent at any time (without affecting prior lawful processing).
- Complain to the ICO (ico.org.uk) or your local EU supervisory authority.
California residents (CCPA/CPRA) additionally have the right to know, delete, correct, and limit use of sensitive personal information, and to opt out of the "sale" or "sharing" of personal data — we do not sell or share, but you can confirm your preferences via the cookie banner or by emailing privacy@cyberessentialcheck.co.uk. We do not discriminate against users who exercise their rights.
We respond to verified rights requests within 30 days (extendable by 60 days for complex requests).
8. Security
TLS 1.2+ in transit; AES-256 at rest; row-level security in the database; least- privilege access controls; encrypted OAuth tokens; audit logs; independent security reviews. Report vulnerabilities to security@cyberessentialcheck.co.uk.
9. Automated decision-making
Scan results are generated by automated checks against public DNS/HTTP and your questionnaire answers. They are advisory only and do not produce legal or similarly significant effects on you. A human at your organisation reviews and acts on results.
10. Children
The Service is for business use and is not directed to under-16s.
11. Changes
Material changes will be notified by email or in-product notice at least 14 days before they take effect.