Privacy notice
RightCyber Analysis is the controller for the personal data submitted through this service. You can contact us at info@rightcyber.co.uk.
What we collect
We collect your work email, organisation context intended to be non-identifying, report answers, optional notes, generated report content, payment status and Stripe identifiers, IP-derived rate-limit data, and Cloudflare Turnstile verification results. The assessment does not ask for your name or organisation name.
Cyber-security answers and notes can still be sensitive even when names are omitted. The forms tell you not to submit credentials, keys, network identifiers, raw logs, configuration exports, personal data or exploitable incident detail. This service does not request evidence-file uploads.
How we use data
We use this data to generate and send a cyber-readiness report, operate its secure link, prevent abuse, respond to support requests, and improve report quality. The organisation-name-free context is stored with the assessment so a later report can remain tailored without asking for an organisation name. Because it is linked to the delivery email, this service is data-minimised rather than anonymous.
You are responsible for removing names and identifying or sensitive technical details from free-text context and notes before submission. While you complete a paid follow-up, an unfinished answer draft is kept only in that browser tab's session storage. It is cleared after generation and is not uploaded until you submit the form.
Service emails for report delivery and access are sent because they are needed to provide the service. The assessment form does not subscribe you to marketing emails.
Processors
OpenAI processes the organisation context you provide, assessment answers, optional answer notes, deterministic scores, and report instructions to generate the wording. Your email is not sent to OpenAI, and the assessment does not request an organisation name. Stripe processes your email and payment details in its hosted Checkout; the application stores only the payment identifiers and status needed to unlock or revoke access. Resend sends report and service emails. Cloudflare Turnstile checks whether a report request appears automated. Hosting and database providers process the data needed to run the site.
Legal Bases
Report generation, Stripe checkout, report delivery, and support are processed to provide the requested service or take steps before providing it. Abuse prevention, service security, product improvement, and record keeping are processed on legitimate interests.
Retention
Free report links remain available for 30 days and advanced report links for 90 days. The underlying assessment, delivery, and minimal payment records may be retained longer where needed to provide support, prevent fraud, meet accounting obligations, or resolve disputes. Operational and abuse-prevention records are retained only as long as reasonably needed to operate and protect the service.
International Transfers
Some processors may process data outside the UK or EEA. Where this happens, the transfer is handled through the processor's published safeguards, such as standard contractual clauses or equivalent transfer mechanisms.
Your Rights
You can ask for access, correction, deletion, restriction, objection, or portability. You also have the right to complain to the UK Information Commissioner's Office if you are unhappy with how personal data is handled.