Skip to content
Legal

Privacy policy

What we collect, why we hold it, how long it stays, and what happens to the technical data produced during an engagement.

Last updated

16 September 2026

This policy covers the Cybersecly website and the testing and consulting services we deliver. If you are an existing client, the engagement agreement governs your data and takes precedence over anything here that conflicts with it.

1. Introduction

Cybersecly LLC (“Cybersecly”, “we”, “our” or “us”) is committed to protecting your privacy. This privacy policy explains how we collect, use, disclose and safeguard your information when you visit our website or engage our penetration testing and cybersecurity consulting services.

By using our website or services, you agree to the collection and use of information in accordance with this policy.

We act in two roles. For the information you give us through this website, or when you enquire about or contract for our services, we are the data controller. For personal data contained in the systems we test on your behalf, you are the controller and we act as your data processor, on your instructions and under the engagement agreement.

2. Information we collect

We collect information you provide directly to us:

  • Contact information name, email address, phone number, company name and job title when you submit a contact form or book a consultation.
  • Engagement data information about your infrastructure, applications and systems provided during scoping and testing, including IP addresses, URLs, test credentials and architecture documentation.
  • Communication records emails, call notes and messages exchanged during engagements.

We also collect a small amount of information automatically:

  • Server logs our host records the request - page, time, referrer, browser and IP address - as any web server does. We use these for security and troubleshooting, not to build a profile of you.
  • Page analytics where enabled, aggregate counts of which pages are visited and which site referred you. The analytics we use sets no cookies, stores nothing on your device, and does not track you between websites or across sessions.
  • Live chat the chat widget in the corner of the site is provided by Tawk.to. While it is loaded it records basic visitor information - IP address, approximate location, the pages you view and your browser - and, if you open a conversation, the messages you send. It sets its own cookies (see the Cookies and Third-party services sections). Using it is optional.

We do not use advertising networks, tracking pixels, session recording or cross-site trackers, and we do not buy or enrich data about you from anyone else.

4. How we use your information

We use the information we collect to:

  • Deliver the penetration testing, vulnerability assessment and consulting services you have engaged us for.
  • Communicate with you about your engagement, including findings, reports and remediation support.
  • Respond to enquiries and provide quotes for services.
  • Improve our website and service delivery.
  • Comply with legal obligations.

We do not sell, rent or share your personal information with third parties for their marketing purposes.

5. How we handle engagement data

During penetration testing engagements we may access, collect and analyse technical data from your systems, including vulnerability information, system configurations and evidence of findings. This data is:

  • Stored on encrypted, access-controlled systems.
  • Accessible only to the penetration testers assigned to your engagement.
  • Kept in the Vexil platform for as long as you hold an active account with us, so you can regenerate reports and request retests. When you close the account, or ask us to delete your data at any time, it is deleted immediately - not at the end of a retention period.
  • Never shared with third parties except as required by law or with your explicit written consent.

Test credentials, architecture diagrams, captured data and any raw evidence not needed for the report are treated with the same level of confidentiality and are purged 90 days after the engagement closes, unless a longer period is agreed in writing or you ask us to delete them sooner - which we do immediately.

6. Data security

We implement appropriate technical and organisational measures to protect your information, including:

  • Encryption at rest and in transit for all engagement data.
  • Access controls limiting data access to authorised personnel.
  • Regular security assessments of our own infrastructure.
  • Secure deletion procedures for post-engagement data purging.
  • If a security incident affects your data, we notify you without undue delay and give you what you need to meet your own notification duties.

7. Where your data is processed

The Vexil platform, and the engagement data held in it, are hosted in the United Kingdom. The European Commission has recognised the United Kingdom as providing an adequate level of data protection, so data moving from the European Union to that hosting needs no further safeguard.

Our testers work remotely and may access engagement data from outside the European Union and United Kingdom, including from Bangladesh. For personal data of people in the EU or UK we rely on the EU Standard Contractual Clauses, with the UK Addendum where it applies, as the transfer mechanism, and we sign a Data Processing Agreement containing them on request and at no charge.

Website enquiries are delivered to us by an email provider in the United States under its own data processing terms, and page analytics, where enabled, runs on servers in the European Union.

8. Data retention

We retain personal information only as long as necessary for the purposes set out in this policy:

  • Contact form submissions: retained for 12 months for follow-up purposes.
  • Engagement findings and reports: kept in the platform while your account is active, and deleted immediately when the account closes or when you ask.
  • Test credentials, captured data and raw evidence: purged 90 days after the engagement closes, or immediately on request.
  • A copy of each final report: kept for three years from delivery to evidence the work performed and for quality assurance, then deleted - or deleted immediately on written request.
  • Billing and contractual records: retained as required by applicable law.

9. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion of your personal data.
  • Object to or restrict processing of your personal data.
  • Request a copy of your data in a portable format.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the data protection authority in your country if you believe we have handled your data unlawfully. We would ask you to contact us first so we can put it right.

We answer rights requests within one month. We make no decisions about you by automated means, and we do no profiling.

To exercise these rights, contact us at [email protected].

10. Third-party services

We use a limited set of third-party services to operate:

  • Website hosting a cloud hosting provider that serves this website and keeps the server logs described above.
  • Platform hosting (OVH, United Kingdom) the servers on which the Vexil platform and engagement data are held.
  • Email delivery (Resend, United States) for delivering contact form submissions and engagement notifications.
  • Page analytics (Plausible, European Union) where enabled, a cookieless analytics service that receives the page URL and referrer and stores nothing on your device.
  • Live chat (Tawk.to, United States) the chat widget loaded on every page. If you use it, Tawk.to processes your messages and records basic visitor information (IP address, approximate location, pages viewed, browser). It sets its own cookies to keep the chat session.
  • Scheduling if you book through the calendar embedded on our booking page, that scheduler is a third party and may set its own cookies inside that frame. It is not loaded anywhere else on the site.

These providers process data only as instructed by us under their own data processing terms.

11. Cookies and local storage

This website sets no cookies of its own. Not for advertising, not for tracking, and not for analytics. What does set cookies is a third party - the live chat - and that is worth naming precisely:

  • Live chat (Tawk.to) the chat widget loads on every page and sets its own cookies to keep your chat session and remember whether the window is open. These are functional cookies set by Tawk.to, not advertising or cross-site tracking. If you would rather it did not run, block third-party cookies in your browser.
  • Scheduling calendar on our booking page only, the embedded scheduler may set its own cookies inside its frame while you use it. It loads nowhere else.
  • One item of session storage if you dismiss the banner at the foot of the screen, we record that in your browser’s session storage so it stays dismissed. It holds no identifier, it is never sent to us, and your browser discards it when you close the tab.
  • Fonts are served by us the typefaces are downloaded from our own domain at build time rather than requested from Google when you visit, so loading a page makes no request to a font provider.

12. Changes to this policy

We may update this privacy policy from time to time. Changes are posted on this page with an updated date at the top. We encourage you to review this policy periodically.

13. Contact

If you have questions about this privacy policy or our data practices, contact us at [email protected]. We are based in Albuquerque, New Mexico.

Our terms of service cover how engagements are run, including the rules of engagement and confidentiality.