PRIVACY

Privacy notice

Who we are

CyberProva is run by a small team of IT professionals who deal with cyber security incidents as part of our day-to-day work. We built CyberProva to give smaller organisations a clear, practical view of their security, and of the gaps we most often see behind real incidents, before those gaps are exploited.

CyberProva is based in the United Kingdom.

Privacy enquiries: hello@cyberprova.com

Our role and where information comes from

This notice covers visitors to this site, account holders, business contacts and people whose information appears in customer workspaces.

We are the controller of personal data we use to run accounts, subscriptions, business enquiries and the security of the service. For personal data inside customer workspaces (uploaded evidence, results of connected Microsoft 365 checks and assessment records) we act as a processor on the customer’s instructions. The customer decides why that information is processed and is responsible for telling the people concerned. Our commitments as a processor are set out in the data-processing schedule.

Information comes from you, your organisation or its IT provider, workspace invitations and uploads, Microsoft sign-in and any Microsoft 365 connection your organisation authorises, payment notifications from Stripe, and your use of the service. If your organisation supplied information about you, you can ask it about that; we will pass on requests where appropriate.

What we hold, and why

These are the categories the software actually stores today:

  • Account data — the directory identifier and email address of each person who signs in, and their role in the workspace.
  • Organisation data — your organisation name, your declared assessment scope, and your Microsoft tenant identifier once connected.
  • Assessment results — the outcome of each check, when it ran, and the finding text.
  • Evidence you upload — the files themselves, their filenames and any notes. These may contain personal data depending on what you choose to upload; you control that.
  • Configuration read from Microsoft 365 — security settings, and directory identifiers of affected accounts. We do not request the email addresses of accounts flagged in our leaked-credential check.
  • Billing data — subscription status and Stripe identifiers. Card details are handled by Stripe and never reach us.

Purposes and lawful bases

Where we are the controller, we use personal data for the purposes below. Customer workspace data is processed on the customer’s instructions and under the customer’s own lawful basis.

  • Accounts, invitations and support: work contact details, sign-in identifiers, roles and correspondence, so that people can sign in, be invited and get help. Lawful basis: our legitimate interests in providing and administering a business service, or contract where you are personally a party to it.
  • Subscriptions and billing: contact details, plan, payment status and transaction references, to take payment and keep accounts. Lawful basis: contract, or our legitimate interests in administering your organisation’s subscription. We keep accounting records because the law requires it (legal obligation).
  • Security and reliability: technical logs recording your IP address, the page or address requested, browser details, time and outcome of each request, so that we can investigate errors, prevent abuse and protect accounts. Lawful basis: our legitimate interests in keeping the service safe and working.
  • Service messages: recipient addresses, related workspace records, message content and delivery status, to send invitations, evidence requests and alerts you or your organisation have asked for. Lawful basis: our legitimate interests in operating the service. We do not send marketing email.

We need account identifiers to give you access, and billing details to provide a paid subscription. Connecting Microsoft 365 and uploading evidence are optional; without them some controls cannot be checked. Please do not upload passwords, unnecessary personal information or special category data.

Your right to object: where we rely on legitimate interests, you can object on grounds relating to your particular situation.

How long we keep it

  • Accounts, workspaces, assessment results, evidence and service messages: for as long as the workspace is in use. When a customer closes its workspace or asks us to delete it, we delete this data within 30 days, unless we must keep specific records to meet a legal obligation or deal with a legal claim.
  • Invitation links: expire after 7 days or when used.
  • Technical logs: 30 days.
  • Billing and accounting records: six years, as UK tax law requires.
  • Support and privacy correspondence: two years after the matter is closed.
  • Backups: database backups are overwritten within 7 days. Deleted evidence files and earlier versions of files are permanently removed from storage within 30 days.

Cancelling a subscription or withdrawing Microsoft 365 consent does not by itself delete stored data. To ask for deletion, contact us at hello@cyberprova.com. For data in a customer workspace we may need the customer’s instruction.

Who else processes it

We use these service providers, who process personal data on our behalf under contracts that protect it:

  • Microsoft (Azure): hosting, database, file storage and technical logs, in Microsoft data centres in the United Kingdom. Microsoft Entra ID provides sign-in, and Microsoft Graph provides the read-only Microsoft 365 checks your organisation authorises.
  • Stripe: checkout and payment processing. Card details you enter at checkout go to Stripe and are not stored by us.
  • Our email delivery provider: sending service messages.

Authorised members of your workspace can see data according to their roles. Evidence requests go to the providers your organisation chooses. Anyone who receives a report you export sees what you choose to share.

We may also disclose information where the law requires it, to professional advisers bound by confidentiality, or to establish or defend legal claims. If the business or its assets are transferred, including to a company we set up to run CyberProva, personal data would transfer with appropriate safeguards and we would tell affected people.

International transfers

We store customer data in the United Kingdom. Some providers, such as Stripe and Microsoft for support and security operations, may process data in other countries, including the United States. Where they do, the transfer is protected by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework) or by the International Data Transfer Addendum to the standard contractual clauses. Contact us for more information about these safeguards.

Your rights

You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, and to receive it in a portable form. You can also complain to the Information Commissioner's Office, though we would prefer the chance to put things right first.

Depending on the purpose and lawful basis, you can ask us for access to, correction, deletion or restriction of your data, or for a portable copy, and you can object to processing. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out. These rights have conditions and exemptions, and we may need to verify your identity. We will respond within one month.

To make a request or complaint, contact us at hello@cyberprova.com. You can also complain to the Information Commissioner’s Office or another data protection authority at any time; you do not need to contact us first.

Assessments automatically summarise selected security controls to support human decisions. We do not make solely automated decisions about individuals that have legal or similarly significant effects.

Cookies

We use cookies for sign-in, request protection and your language preference. The application does not include advertising or third-party analytics tracking.

  • Sign-in cookies: keep you signed in; deleted when you sign out or close your browser.
  • Request protection cookie: protects forms against cross-site request forgery; deleted when you close your browser.
  • Language cookie: remembers the language you choose; lasts one year.
  • Plan choice cookie: remembers the plan you picked while you sign up; lasts one hour.

These cookies are strictly necessary for the service, so we do not ask for consent to them. We do not use advertising or analytics cookies. Microsoft and Stripe set their own cookies when you use their sign-in and checkout pages.

Changes to this notice

When we change this notice we will update the date above, and tell account holders about significant changes before they take effect.

Terms of Service