Privacy Policy
Last updated:
Your Privacy Matters: At Cyberphore, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, and safeguard your data in accordance with applicable privacy laws and regulations. For information about our terms of service, please see our Terms & Conditions.
Table of Contents
- 1. Introduction and Scope
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Legal Basis for Processing
- 5. Information Sharing and Disclosure
- 6. Data Security and Protection
- 7. Data Retention and Deletion
- 8. Your Rights and Choices
- 9. Cookies and Tracking Technologies
- 10. International Data Transfers
- 11. Children's Privacy
- 12. Marketing Communications
- 13. Automated Decision Making
- 14. Third-Party Services and Links
- 15. Changes to This Privacy Policy
- 16. Compliance and Regulatory Information
- 17. Contact Us and Data Protection Officer
1. Introduction and Scope
Welcome to Cyberphore Cybersecurity Solutions Ltd. ("Cyberphore", "we", "us", or "our"). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you visit our website at https://cyberphore.com/, use our services, or interact with us in any capacity. This policy applies to all personal information we collect or process in connection with our cybersecurity services and business operations.
We are committed to transparency in our data practices and compliance with all applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Health Insurance Portability and Accountability Act (HIPAA), and other relevant privacy regulations worldwide.
Who We Are
Cyberphore Cybersecurity Solutions Ltd. is a professional cybersecurity services provider specializing in security assessments, penetration testing, incident response, and security consulting. For more information about our company, please see our Legal Notice. For our terms of service, please refer to our Terms & Conditions.
Scope of This Policy
This Privacy Policy applies to:
- Visitors to our website and users of our online services
- Clients who engage our cybersecurity services
- Business contacts and partners
- Job applicants and candidates
- Any other individuals whose personal information we process
This policy should be read in conjunction with our Cookie Policy, which provides detailed information about our use of cookies and similar technologies.
2. Information We Collect
We collect various types of information to provide, maintain, and improve our services. The information we collect depends on how you interact with us and the services you use.
Information You Provide Directly
We collect information that you voluntarily provide to us when you:
- Contact Us: Name, email address, phone number, company name, job title, and message content
- Create an Account: Username, password, email address, phone number, company information, and security preferences
- Use Our Services: Technical details about your systems, network information, security requirements, and business objectives
- Make a Purchase: Billing information, payment method details, billing address, and transaction history
- Attend Events: Registration information, dietary preferences, accessibility requirements, and attendance records
- Apply for Jobs: Resume, cover letter, work history, education, references, and interview feedback
- Subscribe to Communications: Email address, communication preferences, and interests
Information We Collect Automatically
When you visit our website or use our services, we automatically collect certain information:
Technical Information
- IP address and approximate geographic location
- Browser type, version, and language preferences
- Operating system and device information
- Screen resolution and device capabilities
- Referring website or source
- Date and time of access
- Pages visited and navigation paths
Usage Information
- Website pages viewed and time spent on each page
- Click patterns and interaction with website elements
- Search queries entered on our website
- Forms completed and downloads initiated
- Error messages and technical issues encountered
- Feature usage and service interactions
For detailed information about cookies and tracking technologies, please see our Cookie Policy.
Information from Third Parties
We may receive information about you from third-party sources:
- Business Partners: Contact information and business relationships
- Public Sources: Company information, professional profiles, and public records
- Service Providers: Analytics data, payment information, and service usage metrics
- Social Media: Profile information if you connect through social platforms
- Data Brokers: Business contact information for legitimate business purposes
Service-Specific Information
When you use our cybersecurity services, we may collect additional information necessary to provide those services:
- Network architecture and configuration details for network security monitoring
- System logs and security event data
- Vulnerability assessment results and penetration testing findings
- Incident response and forensic data
- Security policies and procedures documentation
- Compliance documentation and audit results
- Employee security awareness training records
- Website security scanning and monitoring data
- Cloud security configuration and access logs
3. How We Use Your Information
We use the information we collect for various legitimate business purposes as described below. The specific purposes depend on the nature of our relationship with you and the information collected.
Service Provision and Delivery
- Provide, operate, and maintain our cybersecurity services
- Process your requests and transactions
- Deliver security assessments and penetration testing
- Provide incident response and forensic services
- Conduct compliance audits and security consulting
- Manage your account and service subscriptions
- Provide technical support and customer service
- Send service-related communications and updates
Business Operations and Administration
- Process payments and manage billing
- Maintain business records and documentation
- Manage vendor and partner relationships
- Conduct internal operations and administration
- Perform accounting and tax compliance
- Manage employment relationships and recruitment
- Enforce our terms and policies
Service Improvement and Development
- Analyze service usage and user behavior
- Improve and optimize our services
- Develop new features and services
- Conduct research and analytics
- Test new technologies and methodologies
- Create anonymized and aggregated data sets
- Benchmark and compare security metrics
Communication and Marketing
- Send marketing communications (with your consent)
- Provide security alerts and threat intelligence
- Share industry news and best practices
- Invite you to events and webinars
- Conduct surveys and gather feedback
- Personalize your experience
- Respond to your inquiries and requests
For more information about marketing communications, see our Marketing Communications section below.
Security and Compliance
- Protect against fraud and unauthorized access
- Monitor for security threats and vulnerabilities
- Investigate security incidents
- Comply with legal obligations and regulations
- Respond to legal requests and prevent harm
- Enforce our agreements and policies
- Maintain logs for security and compliance purposes
| Purpose | Legal Basis | Data Types Used | Retention Period |
|---|---|---|---|
| Cybersecurity service delivery | Contract performance | Personal, Professional, Technical, Service-specific | Duration of contract + 7 years |
| Payment processing | Contract performance | Payment, Billing, Contact information | 7 years for tax compliance |
| Marketing communications | Consent / Legitimate interest | Contact, Preferences, Behavioral | Until opt-out or 3 years of inactivity |
| Service improvement | Legitimate interest | Technical, Usage, Analytics | 2 years (anonymized indefinitely) |
| Legal compliance | Legal obligation | All relevant data types | As required by law |
| Security monitoring | Legitimate interest | Technical, Access logs, Security events | 1 year |
4. Legal Basis for Processing
Under applicable data protection laws, particularly GDPR, we must have a legal basis for processing your personal information. We rely on the following legal bases:
Contract Performance
Processing is necessary to perform our contract with you or to take steps at your request before entering into a contract. This includes providing our cybersecurity services, processing payments, and managing your account.
Legitimate Interest
Processing is necessary for our legitimate business interests, provided these interests are not overridden by your rights and interests. Our legitimate interests include:
- Improving and optimizing our services
- Marketing our services to businesses
- Ensuring security and preventing fraud
- Conducting analytics and research
- Managing business operations
Consent
You have given clear consent for us to process your personal information for specific purposes, such as marketing communications or optional cookies. You can withdraw consent at any time.
Legal Obligation
Processing is necessary to comply with legal obligations, such as tax laws, employment laws, or regulatory requirements.
Vital Interests
Processing is necessary to protect vital interests, such as in emergency situations or to prevent serious harm.
5. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following limited circumstances:
Service Providers and Business Partners
We work with trusted third-party service providers who assist us in operating our business. These providers are bound by confidentiality agreements and data processing agreements:
- Cloud Hosting Providers: For hosting our website and services
- Payment Processors: For processing payments securely
- Email Services: For sending communications
- Analytics Providers: For website and service analytics (see our Cookie Policy)
- CRM Systems: For managing customer relationships
- Security Tools: For monitoring and protecting our systems
- Professional Advisors: Legal, accounting, and consulting services
Legal Requirements and Protection
We may disclose your information when required by law or when necessary to:
- Comply with court orders, subpoenas, or legal processes
- Cooperate with law enforcement investigations
- Comply with regulatory requirements and audits
- Protect our rights, property, or safety
- Protect the rights and safety of our users or others
- Prevent fraud or illegal activities
- Enforce our terms and agreements
Business Transfers
If we are involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will ensure appropriate protections are in place and provide notice before your information is transferred and becomes subject to a different privacy policy.
With Your Consent
We may share your information with third parties when you have given us specific consent to do so, such as when you authorize us to share information with partners or connect third-party services to your account.
Anonymized and Aggregated Data
We may share anonymized and aggregated data that cannot reasonably be used to identify you. This data is used for research, benchmarking, reporting, and improving cybersecurity practices industry-wide.
6. Data Security and Protection
As a cybersecurity company, we implement industry-leading security measures to protect your personal information. Our security program includes:
Technical Safeguards
- Encryption: Data in transit protected with TLS 1.3; data at rest encrypted with AES-256
- Access Controls: Role-based access control (RBAC) and principle of least privilege
- Multi-Factor Authentication: Required for all administrative access
- Network Security: Firewalls, intrusion detection/prevention systems, and network segmentation
- Vulnerability Management: Regular scanning and penetration testing
- Patch Management: Timely application of security updates
- Secure Development: Security built into our development lifecycle
- Monitoring: 24/7 security monitoring and logging
Organizational Measures
- Employee Training: Regular security and privacy training for all staff
- Background Checks: Background screening for employees with data access
- Confidentiality Agreements: All employees sign confidentiality and non-disclosure agreements
- Incident Response: Documented procedures for security incidents and data breaches
- Business Continuity: Disaster recovery and business continuity plans
- Third-Party Management: Security assessments of vendors and partners
- Data Protection Impact Assessments: Regular privacy impact assessments
Physical Security
- Secure data centers with restricted physical access
- Environmental controls and monitoring
- Secure disposal of physical media
- Visitor access controls and logging
- Video surveillance in sensitive areas
Compliance Certifications
Our security program is validated through independent audits and certifications:
- ISO 27001 Information Security Management certification
- SOC 2 Type II compliance
- PCI DSS compliance for payment processing
- Regular third-party security assessments
For more information about our security practices and certifications, see our Legal Notice.
Security Breach Notification: In the unlikely event of a data breach that affects your personal information, we will notify you and relevant authorities as required by law. We maintain detailed incident response procedures to ensure rapid detection, containment, and remediation of security incidents.
7. Data Retention and Deletion
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Criteria
Our retention periods are based on:
- The nature of the information and purpose for collection
- Legal and regulatory requirements
- Contractual obligations
- Our legitimate business interests
- Your preferences and requests
Specific Retention Periods
- Account Information: While your account is active and for 3 years after closure
- Service Data: Duration of contract plus 7 years for compliance and liability purposes
- Marketing Data: Until you opt out or for 3 years of inactivity
- Financial Records: 7 years as required by tax and accounting regulations
- Security Logs: 1 year for security monitoring and incident response
- Website Analytics: 26 months in line with Google Analytics retention
- Employment Records: 7 years after end of employment
- Legal Documents: As required by applicable laws (typically 7+ years)
Data Deletion
When personal information is no longer needed, we securely delete or anonymize it using industry-standard methods:
- Secure deletion of electronic data using data sanitization standards
- Physical destruction of hardware media when decommissioned
- Anonymization of data for research and analytics purposes
- Removal from active systems and backup archives
In some cases, we may retain certain information for longer periods if required by law or for legitimate business purposes such as dispute resolution, legal proceedings, fraud prevention, or historical analysis.
8. Your Rights and Choices
Depending on your location and applicable law, you may have the following rights regarding your personal information:
Access and Portability
You have the right to request access to your personal information and to receive a copy of your data in a portable, machine-readable format. We will provide this information within 30 days of your verified request.
Correction and Updates
You have the right to request correction of inaccurate personal information and to update incomplete information. You can update much of your information by logging into your account or by contacting us.
Deletion and Right to be Forgotten
You have the right to request deletion of your personal information in certain circumstances:
- The information is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The information has been unlawfully processed
- The information must be deleted to comply with legal obligations
We may need to retain certain information for legal compliance or legitimate business purposes even after a deletion request.
Opt-Out of Marketing
You can opt out of receiving marketing communications from us at any time by:
- Using the unsubscribe link in our emails
- Updating your communication preferences in your account
- Contacting us at privacy@cyberphore.com
- Following opt-out instructions in specific communications
You may still receive important service-related communications even after opting out of marketing.
Data Processing Restrictions
You have the right to request that we restrict processing of your personal information in certain circumstances, such as when you contest accuracy, object to processing, or need the data preserved for legal claims.
Object to Processing
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds that override your interests.
Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time. This will not affect the lawfulness of processing before withdrawal.
Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable law. We encourage you to contact us first so we can address your concerns.
Exercising Your Rights
To exercise any of these rights, please contact our Data Protection Officer at dpo@cyberphore.com or use the contact information in the Contact Us section. We will respond to your request within 30 days and may need to verify your identity before processing your request.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our website and to provide our services. Cookies are small text files stored on your device that help us remember your preferences and understand how you use our website.
Types of Cookies We Use
- Essential Cookies: Necessary for website functionality and security
- Analytics Cookies: Help us understand website usage and performance
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Track visitors for advertising purposes
For detailed information about our use of cookies, including specific cookies we use, how to manage cookies, and your options, please see our comprehensive Cookie Policy.
Managing Cookies
You can control cookies through your browser settings and our cookie consent banner. Blocking certain cookies may affect website functionality. See our Cookie Policy for browser-specific instructions.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with applicable data protection laws.
Transfer Mechanisms
We use the following mechanisms to ensure adequate protection for international data transfers:
- Standard Contractual Clauses (SCCs): Approved by the European Commission and other authorities
- Adequacy Decisions: Transfers to countries deemed to provide adequate protection
- Binding Corporate Rules: For transfers within our corporate group
- Certification Schemes: Such as EU-US Data Privacy Framework (if certified)
- Your Explicit Consent: Where required and appropriate
Data Storage Locations
We primarily store data in secure data centers located in [Primary Location]. Some data may be processed or stored in other locations where we or our service providers operate. All transfers comply with applicable data protection requirements.
11. Children's Privacy
Our services are not directed to children under 16 years of age (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 16.
If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete such information immediately. If you believe we have collected information from a child under 16, please contact us at privacy@cyberphore.com.
Parents and guardians have the right to review, delete, or refuse further collection of their child's personal information. For our complete terms of service, see our Terms & Conditions.
12. Marketing Communications
We may send you marketing communications about our services, industry news, and security insights. You have full control over these communications.
Types of Marketing Communications
- Email newsletters and security alerts
- Product and service announcements
- Industry news and best practices
- Event invitations and webinar announcements
- Case studies and whitepapers
- Surveys and feedback requests
Legal Basis for Marketing
We send marketing communications based on:
- Consent: You have explicitly opted in to receive marketing
- Legitimate Interest: You are an existing customer or have a business relationship with us
- Soft Opt-In: Where permitted, such as for similar products/services
Opting Out
You can opt out of marketing communications at any time without affecting your use of our services. Opting out does not apply to service-related communications necessary for providing our services.
13. Automated Decision Making
We do not engage in automated decision making or profiling that produces legal effects or similarly significantly affects you without human involvement.
We may use automated tools for:
- Analyzing website traffic and user behavior
- Detecting fraud and security threats
- Personalizing content and recommendations
- Segmenting marketing audiences
If we begin using automated decision making that significantly affects you, we will inform you and provide you with the right to human review, explanation, and the ability to challenge the decision.
14. Third-Party Services and Links
Our website may contain links to third-party websites, applications, or services that are not owned or controlled by Cyberphore. This Privacy Policy does not apply to those third-party services.
Third-Party Responsibility
We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party services before providing them with personal information.
Social Media Integration
Our website may include social media features and widgets. These features may collect your IP address, page visits, and may set cookies. Social media features are governed by the privacy policies of the companies providing them.
Third-Party Services We Use
For information about specific third-party services we use, including analytics and marketing tools, please see our Cookie Policy.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last updated" date at the top of this policy
- Post the updated policy on our website
- Notify you by email for material changes
- Provide notice through our website or services
- Obtain your consent where required by law
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our services after any changes indicates your acceptance of the updated Privacy Policy.
Material Changes
For material changes that significantly affect your rights or how we process your personal information, we will provide at least 30 days' notice and may require your affirmative consent before the changes take effect.
16. Compliance and Regulatory Information
We are committed to compliance with applicable data protection laws and regulations worldwide.
GDPR Compliance (European Union)
For individuals in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). This includes:
- Lawful basis for all processing activities
- Data protection by design and by default
- Data protection impact assessments
- Data breach notification procedures
- Appointment of Data Protection Officer
- Records of processing activities
CCPA Compliance (California)
For California residents, we comply with the California Consumer Privacy Act (CCPA). Your rights under CCPA include the right to know, delete, opt-out, and non-discrimination.
Other Regulatory Compliance
- HIPAA: For healthcare-related services
- PCI DSS: For payment card data
- SOC 2: For service organization controls
- ISO 27001: For information security management
For more information about our compliance certifications, see our Legal Notice. For our general terms of service, see our Terms & Conditions.
17. Contact Us and Data Protection Officer
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Protection Officer
For privacy-related inquiries, data subject requests, and data protection matters, please contact our Data Protection Officer.
Email Privacy Team Email DPO
Email: privacy@cyberphore.com | dpo@cyberphore.com
Response Time: Within 48 hours for inquiries, 30 days for data subject requests
Phone: [Privacy Hotline Number]
Address: [Company Address - see Legal Notice]
Related Documents
This Privacy Policy should be read together with:
- Terms & Conditions - Our terms of service
- Cookie Policy - Detailed information about cookies
- Legal Notice - Company information and certifications
- Accessibility Statement - Our accessibility commitment
This Privacy Policy is effective as of the date listed above and applies to all information collected by Cyberphore. By using our services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. For questions or concerns, please don't hesitate to contact our Data Protection Officer.