CybAura
DRAFT — PENDING LEGAL REVIEW — NOT FOR PUBLIC USE UNTIL REVIEWED BY COUNSELThis document has been generated as a starting point and has not yet been reviewed by a qualified solicitor. It must not be shown to customers or published on any public-facing page until legal review is complete.

Privacy Policy

Last updated: [DATE]  ·  Effective: [DATE]

1. Who We Are

CybAura Ltd (“CybAura”, “we”, “us”, “our”) is a company incorporated in England and Wales (Company No: [NUMBER], registered address: [ADDRESS]). We operate the CybAura cybersecurity management platform available at app.cybaura.io.

2. Our Roles Under GDPR

We act in two distinct capacities depending on the data involved:

  • Data Controller — for personal data we collect directly from individuals who interact with our website and platform, such as names, work email addresses, and job titles of customer contacts and authorised users.
  • Data Processor — for any personal data our customers upload into the platform (for example, employee training records or data subject request information). In this capacity we act only on the customer’s instructions. Our obligations as processor are set out in our Data Processing Agreement.

This Privacy Policy covers our role as Data Controller. If you are a customer seeking information about our processor obligations, please refer to the DPA.

3. Personal Data We Collect

Account and Contact Data

  • Full name and work email address
  • Job title and organisational role
  • Company name, company size, and billing address
  • Password (stored as a one-way cryptographic hash; we never store plain-text passwords)
  • Profile picture, if voluntarily uploaded

Usage and Technical Data

  • IP address, browser type, and operating system
  • Pages visited, features used, and session duration
  • Error logs and crash reports
  • API request logs (endpoint, timestamp, response status)

Communication Data

  • Support requests and email correspondence
  • Survey responses and product feedback

Billing Data

Billing contact details. Payment card data is processed and held by our payment processor (Stripe). We store only the last four digits and card type as a reference; we never hold full card numbers.

4. How We Use Your Data

PurposeLawful Basis
Provide the CybAura platform and your accountContract performance (Art. 6(1)(b))
Process billing and paymentsContract performance (Art. 6(1)(b))
Provide customer support and resolve issuesContract performance (Art. 6(1)(b))
Send service notifications (security alerts, downtime notices)Legitimate interests (Art. 6(1)(f))
Improve and develop the platformLegitimate interests (Art. 6(1)(f))
Analyse platform usage to understand how features are usedLegitimate interests (Art. 6(1)(f))
Prevent fraud, abuse, and security incidentsLegitimate interests (Art. 6(1)(f))
Send product update and marketing emails (where opted in)Consent (Art. 6(1)(a))
Comply with legal and regulatory obligationsLegal obligation (Art. 6(1)(c))

5. Retention Periods

Data TypeRetention Period
Account dataDuration of contract + 2 years
Usage and access logs12 months rolling
Support correspondence3 years from last interaction
Billing records7 years (legal and tax requirement)
Marketing consent recordsUntil consent is withdrawn + 1 year
Security incident logs3 years

After the applicable retention period, data is securely deleted or irreversibly anonymised. We do not retain data “just in case”.

6. Who We Share Your Data With

We do not sell, rent, or trade your personal data. We share it only as follows:

Service Providers (Processors)

ProviderPurposeLocation
Amazon Web ServicesCloud infrastructure hostingEU (eu-west-2)
Google Cloud PlatformCloud infrastructure (secondary)EU
Anthropic, PBCAI model processing for agent featuresUnited States
Twilio SendGridTransactional email deliveryUnited States
StripePayment processingUnited States
IntercomCustomer support toolingUnited States

All processors are subject to written data processing agreements and are required to implement appropriate security measures.

Legal Obligations

We may disclose personal data where required by law, court order, or to cooperate with a regulatory or law enforcement authority. We will notify you of any such disclosure unless we are legally prohibited from doing so.

7. International Transfers

CybAura’s primary infrastructure is hosted within the UK/EU. Where we transfer personal data outside the UK/EEA — principally to Anthropic (United States) for AI agent processing, and to SendGrid and Stripe for email and payments — we rely on:

  • EU data: Standard Contractual Clauses approved by the European Commission (Commission Decision 2021/914)
  • UK data: The UK International Data Transfer Agreement (IDTA) approved by the UK ICO

Copies of the applicable SCCs or IDTA are available on request from privacy@cybaura.io.

EU Representative (GDPR Article 27)

CybAura Ltd is established in the United Kingdom. Where Article 27 of the EU GDPR requires a representative in the Union for our processing of EU personal data, CybAura will appoint one. Article 27 Representative: [To be appointed before EU customer onboarding].

8. Automated Decision-Making

CybAura’s AI agents produce recommendations, risk scores, alerts, and analysis. These outputs are advisory only. All significant security and compliance decisions are presented to human operators for review and approval before any action is taken.

We do not make fully automated decisions that produce legal or similarly significant effects about individuals without human review. If this changes, we will update this policy and, where required by GDPR Article 22, obtain your explicit consent.

9. Your Rights

Under UK GDPR and EU GDPR, you have the following rights:

Right of Access (Art. 15)

Request a copy of the personal data we hold about you and information about how we use it.

Right to Rectification (Art. 16)

Ask us to correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

Ask us to delete your personal data, subject to any legal retention obligations we must satisfy.

Right to Restriction (Art. 18)

Ask us to pause processing of your data while a dispute about accuracy or legitimate interests is resolved.

Right to Portability (Art. 20)

Receive your personal data in a structured, commonly used, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds.

Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent (e.g. marketing emails), withdraw it at any time. Withdrawal does not affect prior lawful processing.

To exercise any right, contact privacy@cybaura.io. We will acknowledge your request within 72 hours and respond substantively within one calendar month (extendable by two months for complex requests, with notification).

10. Security

We implement appropriate technical and organisational security measures including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, multi-factor authentication for platform access, and regular security testing. For a full description of our security programme, see cybaura.io/security.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay and no later than 72 hours after becoming aware. Where the breach is unlikely to result in such a risk, we will document it internally.

11. Cookies

We use cookies and similar technologies. Please see our Cookie Policy for a full description of the cookies we use and how to control them.

12. Children

The CybAura platform is designed for use by businesses and their employees. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have received data from a minor, please contact privacy@cybaura.io and we will delete it promptly.

13. Changes to This Policy

We will notify you of material changes to this policy by email at least 30 days before they take effect. The effective date at the top of this page will always reflect the version you are reading. Minor changes such as updated contact details will be made without notice.

14. Right to Complain

If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority:

  • UK: Information Commissioner’s Office (ICO) — ico.org.uk — 0303 123 1113
  • EU: Your local data protection authority in your EU member state

We would always appreciate the opportunity to resolve your concern directly before you contact a regulator. Please reach out to privacy@cybaura.io in the first instance.