Privacy Policy
Last updated: [DATE] · Effective: [DATE]
1. Who We Are
CybAura Ltd (“CybAura”, “we”, “us”, “our”) is a company incorporated in England and Wales (Company No: [NUMBER], registered address: [ADDRESS]). We operate the CybAura cybersecurity management platform available at app.cybaura.io.
- Data controller contact: privacy@cybaura.io
- Data Protection Officer: legal@cybaura.io
2. Our Roles Under GDPR
We act in two distinct capacities depending on the data involved:
- Data Controller — for personal data we collect directly from individuals who interact with our website and platform, such as names, work email addresses, and job titles of customer contacts and authorised users.
- Data Processor — for any personal data our customers upload into the platform (for example, employee training records or data subject request information). In this capacity we act only on the customer’s instructions. Our obligations as processor are set out in our Data Processing Agreement.
This Privacy Policy covers our role as Data Controller. If you are a customer seeking information about our processor obligations, please refer to the DPA.
3. Personal Data We Collect
Account and Contact Data
- Full name and work email address
- Job title and organisational role
- Company name, company size, and billing address
- Password (stored as a one-way cryptographic hash; we never store plain-text passwords)
- Profile picture, if voluntarily uploaded
Usage and Technical Data
- IP address, browser type, and operating system
- Pages visited, features used, and session duration
- Error logs and crash reports
- API request logs (endpoint, timestamp, response status)
Communication Data
- Support requests and email correspondence
- Survey responses and product feedback
Billing Data
Billing contact details. Payment card data is processed and held by our payment processor (Stripe). We store only the last four digits and card type as a reference; we never hold full card numbers.
4. How We Use Your Data
| Purpose | Lawful Basis |
|---|---|
| Provide the CybAura platform and your account | Contract performance (Art. 6(1)(b)) |
| Process billing and payments | Contract performance (Art. 6(1)(b)) |
| Provide customer support and resolve issues | Contract performance (Art. 6(1)(b)) |
| Send service notifications (security alerts, downtime notices) | Legitimate interests (Art. 6(1)(f)) |
| Improve and develop the platform | Legitimate interests (Art. 6(1)(f)) |
| Analyse platform usage to understand how features are used | Legitimate interests (Art. 6(1)(f)) |
| Prevent fraud, abuse, and security incidents | Legitimate interests (Art. 6(1)(f)) |
| Send product update and marketing emails (where opted in) | Consent (Art. 6(1)(a)) |
| Comply with legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
5. Retention Periods
| Data Type | Retention Period |
|---|---|
| Account data | Duration of contract + 2 years |
| Usage and access logs | 12 months rolling |
| Support correspondence | 3 years from last interaction |
| Billing records | 7 years (legal and tax requirement) |
| Marketing consent records | Until consent is withdrawn + 1 year |
| Security incident logs | 3 years |
After the applicable retention period, data is securely deleted or irreversibly anonymised. We do not retain data “just in case”.
6. Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share it only as follows:
Service Providers (Processors)
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure hosting | EU (eu-west-2) |
| Google Cloud Platform | Cloud infrastructure (secondary) | EU |
| Anthropic, PBC | AI model processing for agent features | United States |
| Twilio SendGrid | Transactional email delivery | United States |
| Stripe | Payment processing | United States |
| Intercom | Customer support tooling | United States |
All processors are subject to written data processing agreements and are required to implement appropriate security measures.
Legal Obligations
We may disclose personal data where required by law, court order, or to cooperate with a regulatory or law enforcement authority. We will notify you of any such disclosure unless we are legally prohibited from doing so.
7. International Transfers
CybAura’s primary infrastructure is hosted within the UK/EU. Where we transfer personal data outside the UK/EEA — principally to Anthropic (United States) for AI agent processing, and to SendGrid and Stripe for email and payments — we rely on:
- EU data: Standard Contractual Clauses approved by the European Commission (Commission Decision 2021/914)
- UK data: The UK International Data Transfer Agreement (IDTA) approved by the UK ICO
Copies of the applicable SCCs or IDTA are available on request from privacy@cybaura.io.
EU Representative (GDPR Article 27)
CybAura Ltd is established in the United Kingdom. Where Article 27 of the EU GDPR requires a representative in the Union for our processing of EU personal data, CybAura will appoint one. Article 27 Representative: [To be appointed before EU customer onboarding].
8. Automated Decision-Making
CybAura’s AI agents produce recommendations, risk scores, alerts, and analysis. These outputs are advisory only. All significant security and compliance decisions are presented to human operators for review and approval before any action is taken.
We do not make fully automated decisions that produce legal or similarly significant effects about individuals without human review. If this changes, we will update this policy and, where required by GDPR Article 22, obtain your explicit consent.
9. Your Rights
Under UK GDPR and EU GDPR, you have the following rights:
Right of Access (Art. 15)
Request a copy of the personal data we hold about you and information about how we use it.
Right to Rectification (Art. 16)
Ask us to correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Ask us to delete your personal data, subject to any legal retention obligations we must satisfy.
Right to Restriction (Art. 18)
Ask us to pause processing of your data while a dispute about accuracy or legitimate interests is resolved.
Right to Portability (Art. 20)
Receive your personal data in a structured, commonly used, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent (e.g. marketing emails), withdraw it at any time. Withdrawal does not affect prior lawful processing.
To exercise any right, contact privacy@cybaura.io. We will acknowledge your request within 72 hours and respond substantively within one calendar month (extendable by two months for complex requests, with notification).
10. Security
We implement appropriate technical and organisational security measures including TLS encryption in transit, AES-256 encryption at rest, role-based access controls, multi-factor authentication for platform access, and regular security testing. For a full description of our security programme, see cybaura.io/security.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay and no later than 72 hours after becoming aware. Where the breach is unlikely to result in such a risk, we will document it internally.
11. Cookies
We use cookies and similar technologies. Please see our Cookie Policy for a full description of the cookies we use and how to control them.
12. Children
The CybAura platform is designed for use by businesses and their employees. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have received data from a minor, please contact privacy@cybaura.io and we will delete it promptly.
13. Changes to This Policy
We will notify you of material changes to this policy by email at least 30 days before they take effect. The effective date at the top of this page will always reflect the version you are reading. Minor changes such as updated contact details will be made without notice.
14. Right to Complain
If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner’s Office (ICO) — ico.org.uk — 0303 123 1113
- EU: Your local data protection authority in your EU member state
We would always appreciate the opportunity to resolve your concern directly before you contact a regulator. Please reach out to privacy@cybaura.io in the first instance.