All guides

IT and privacy

Security and data handling

Where the data lives, how it is protected, how long it is kept and what is agreed about its processing. For buyers and IT administrators.

This guide is for a company buyer or IT administrator assessing Cyberact as a supplier. It sets out briefly where the data lives and how it is protected. What is stored and who can see it is covered in more detail in Privacy and your data.

Where the data lives

  • The app and its database run on Hostinger's servers in a data centre in Germany, so the data stays in the EU.
  • The database is outside the web root, where no web address reaches it.
  • The database is backed up every night. Each copy is checked for integrity, and the 14 most recent daily copies are kept.
  • Hostinger also keeps its own backups of the server. See Hostinger's FAQ on data integrity and backups.

Payments

Payments are handled by Stripe. The contracting party is Stripe Payments Europe, Limited, Ireland. Card details are entered directly in Stripe's checkout and never reach Cyberact.

Of a purchase, we keep the buyer's name and email address, the company name, the plan, the billing period, the amount, and Stripe's reference numbers for the subscription and its invoices.

Stripe describes its security at Security at Stripe and its handling of data in its privacy policy.

How the data is protected

  • Encrypted connections. Every Cyberact address works over HTTPS only, and the server tells browsers to keep using an encrypted connection (HSTS).
  • No passwords. People sign in with a code sent to their email. The code is valid for 10 minutes and stops working after the fifth wrong attempt. Only a keyed hash of the code is stored.
  • Sessions. The session cookie travels only over an encrypted connection and is out of reach of the page's JavaScript. A session ends after a week without use, and after 30 days at the latest. Forms and changes are protected with a CSRF token.
  • Roles. A learner sees only their own progress. A manager sees and manages the people in their own organisation and never another organisation's data. The organisation's main admin has the Manager role in the app. Cyberact's own super-admins see all organisations so that they can run the service and help customers. See Roles and access.
  • Access log. Sign-ins, failed sign-ins, code requests, invitations, access changes and data exports are recorded in the access log. A manager sees their own organisation's log.
  • IP addresses. An IP address is never stored as such, only as a keyed hash.
  • Lessons and answers. The lesson content and answer keys are not part of the app. The server hands out one lesson at a time after checking that the person may open it, and answers are graded on the server.
  • Rate limits. Requesting sign-in codes, exporting data and fetching lessons are rate-limited. The sign-in limits are described in For IT administrators.
  • No tracking. Cyberact uses no analytics, tracking or advertising. The app loads no third-party scripts or fonts: everything comes from its own address.
  • Security headers. The Content Security Policy allows scripts, styles and connections from the service's own address only, and the service cannot be embedded in another site. The server also sends X-Content-Type-Options, Referrer-Policy, Permissions-Policy and X-Frame-Options.

Retention and deletion

  • Company data is kept for 12 months after paid access ends, or for a longer period agreed with the customer. The main admin gets an email reminder 30 days before deletion.
  • A personal account is deleted after 24 months without a sign-in, with an email warning 30 days before. An account with an active subscription is never deleted.
  • One person: a manager can delete a person and all of their data at any time.
  • The whole organisation: its data is deleted when the retention period ends. If you want it deleted sooner, write to support@cyberact.io.
  • Backups: deleted data is gone from the backups within 14 days.
  • Export: a manager can export the training log and other evidence as CSV files from the manager console at any time, and one person's data as a JSON file. See Evidence for your auditor.

All retention periods are listed in Privacy and your data.

Agreements and sub-processors

Annex 2 of the data processing agreement lists the sub-processors. The privacy notice gives the same list.

  • Hostinger: server, database, backups and email. The server is in Hostinger's data centre in Germany (Frankfurt), in the EU. The contracting party is Hostinger International Ltd, Larnaca, Cyprus.
  • Stripe: payments, subscriptions, invoices and the calculation of VAT. The contracting party is Stripe Payments Europe, Limited, Ireland. Stripe processes only the buyer's and billing data, never training data.
  • Anthropic: the language model that writes the manager console's summary when AI is in use. Anthropic receives only the organisation's aggregated figures: no names, email addresses, user identifiers, organisation name or text written by learners. Figures for a group are sent only for groups of five or more. AI can be switched off for an organisation. The contracting party for customers in the EEA is Anthropic Ireland, Limited, Ireland.

More on the AI summary is in Privacy and your data.

Security incidents

If a security incident affects a customer's data, we notify the affected customers without undue delay, as set out in the data processing agreement, so that you can make your own notification to the supervisory authority.

Reporting a vulnerability: if you find a vulnerability in the service, write to support@cyberact.io. The contact is also in our security.txt.