Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can ask us to do with it.
1. Who this policy is about
This policy explains how CyberCache handles personal data in connection with this website and with enquiries made through it.
2. What this website does not do
It is easier to state the absences first, because they remove most of what a privacy policy usually has to cover. As built, this website:
- sets no cookies of any kind, and uses no local storage or session storage;
- runs no analytics, no tag manager, no session recording, and no heat mapping;
- loads no third-party scripts, embeds, chat widgets, or social plugins;
- serves its fonts from this domain, so no font provider receives your IP address;
- contains no advertising or tracking pixels, and does no cross-site tracking;
- does not build a profile of you and does no automated decision-making.
Because no cookies are set and no tracking takes place, there is no cookie banner. If that changes, this policy will change first.
3. What we collect
3.1 When you contact us
If you use our scope review form or email us, we receive what you choose to send: typically your name, work email address, company, optionally your website, the type of engagement you are interested in, your timeline, whatever you tell us about your product, and your answer on authorization.
Please do not send us credentials, live customer data, or sensitive personal data through the form or by ordinary email. If an enquiry requires sensitive detail, ask us and we will arrange a secure channel.
3.2 Server logs
Our hosting provider records standard technical information when a page is served, which typically includes the IP address making the request, the time, the page requested, the referring page where one is sent, and the browser user agent string. These logs exist for security and operational purposes, such as diagnosing faults and identifying abuse.
We do not use server logs for analytics, and we do not attempt to identify individuals from them. Retention is determined by our hosting provider\u2019s configuration; see section 7.
3.3 During an engagement
If you become a client, we will hold contact details for the people we work with, and we may incidentally access personal data within your systems during testing. That is governed by the engagement documents and by our Authorized Testing Policy, which requires us to minimise what we collect and retain. Where we process personal data on your behalf, a separate data processing agreement applies.
4. Why we use it, and our legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to your enquiry | Contact and enquiry details you send | Consent, and our legitimate interest in responding to a business enquiry |
| Preparing a proposal or scope | Enquiry details and subsequent correspondence | Steps taken at your request prior to entering a contract |
| Delivering an engagement | Client contact details, engagement records | Performance of a contract |
| Website security and fault diagnosis | Server logs | Legitimate interest in keeping the website available and secure |
| Meeting legal and accounting obligations | Contract and billing records | Legal obligation |
We do not use your enquiry to add you to a marketing list. If we ever introduce a mailing list, it will require a separate, explicit opt-in.
5. Who we share it with
We do not sell personal data and we do not share it for advertising. Data is shared only with service providers that are necessary to operate:
- Our hosting provider, which serves this website and holds the server logs described above.
- Our email provider, which carries correspondence with you.
- Professional advisers and authorities, where we are required to disclose information by law.
The scope review form is not currently connected to a third-party delivery service, so enquiries reach us by email. If a form provider is introduced, it will be named here before the form goes live. See TBD_REGISTER.md item T-03.
Some providers may process data outside your country. Where personal data is transferred outside the UK or EEA, it is protected by an adequacy decision or by standard contractual clauses. The specific providers and their locations must be confirmed and listed here before publication, since we will not describe arrangements we have not verified (see TBD_REGISTER.md item T-02).
6. Security
This website is served over HTTPS and is a set of static files, which removes the database and application layers that are usually the target of an attack. Correspondence is held in access-controlled accounts, and client evidence is handled as described in our Authorized Testing Policy.
We would rather be plain than reassuring: no set of measures makes a breach impossible. If a breach affecting your personal data occurs, we will act on it and notify you and the relevant supervisory authority where the law requires.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become engagements | Up to 12 months from our last exchange, then deleted |
| Client correspondence and engagement records | For the duration of the relationship, then as required for legal and accounting purposes |
| Testing evidence | As specified in the engagement documents, then securely destroyed |
| Server logs | As configured by the hosting provider. This period must be confirmed and stated here before publication (TBD_REGISTER.md item T-02) |
8. Your rights
Depending on where you are, you may have the right to request access to the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable form, and to withdraw consent where processing relies on it.
To exercise any of these, write to info@cybercache.cc. We will respond within one month, and we will tell you if we need longer and why. There is no charge.
If you are unhappy with how we have handled your data you can complain to your data protection authority. In the United Kingdom that is the Information Commissioner\u2019s Office; in the EEA it is the supervisory authority in your country of residence. We would appreciate the chance to put it right first.
9. Children
Our services are provided to businesses and this website is not directed at children. We do not knowingly collect personal data from anyone under 16.
10. Changes to this policy
If we change what we collect or how we use it, we will update this page and the effective date above. Introducing analytics, a third-party form provider, or any tracking technology would require this page to be updated first, not afterwards.
11. Contact
Questions, requests, or complaints about privacy can be sent to info@cybercache.cc.