This policy covers the Cyber Made Simple website and platform at cybermadesimple.co.uk. It applies to visitors, account holders and organisation administrators.
It does not cover CMS SecureMe, which is a separate product with different data flows and its own privacy notice.
Who we are
CMS InfoSec Ltd, trading as Cyber Made Simple, is the controller for the personal data described here unless we tell you otherwise for a specific activity. We are registered in England & Wales and operate from the United Kingdom.
Privacy questions and requests: privacy@cmsinfosec.com. General enquiries: hello@cmsinfosec.com.
What we collect
Account and profile. Your name, email address, user identifier, optional profile fields, organisation memberships, roles, and the preferences you save. Passwords are handled by our authentication system and we do not store them in plain text. Where you use a passkey or an authenticator app, we store the material needed to verify it and nothing more.
Organisation and billing. Organisation name, billing contact details, subscription state mirrored from our payment provider, and seat counts. Card numbers and full payment credentials go to our regulated payment processor and are never stored on our systems.
Usage and product content. The pages and features you use, timestamps, the diagnostics needed to run and secure the platform such as error fingerprints and rate-limit counters, and the content you create: assessment answers, tool outputs, generated policies, training progress and evidence records.
Communications. Messages you send us, transactional email delivery metadata, and your marketing preferences where you have opted in.
Cookies. As described in the cookie controls in the product. Strictly necessary cookies keep you signed in; anything else is set only with your consent.
Integration data. Where you connect a third-party service, whatever that integration needs in order to work, with credentials held encrypted.
Why we use it
- To do what you signed up for. Providing the service, signing you in and managing billing.
- Because we have a fair reason. Securing the platform, stopping abuse, improving the product, running proportionate analytics, and replying to your enquiries, each balanced against your rights.
- Because you agreed. Non-essential cookies and marketing email. Withdraw it through the cookie controls or the unsubscribe link at any time.
- Because the law says so. Where we must keep or hand over information for tax, accounting or regulatory reasons.
Artificial intelligence
Some features send text to a third-party AI provider to generate a response: the AI security assistant, the phishing message analyser, message risk scoring, and the generation of draft policies, plans, supplier questionnaires and site content.
What is sent is the text the feature needs: your question, the message you pasted in, the answers you gave a questionnaire, or the organisation details you entered.
What is not sent is your name, your email address or your account identifier. The providers act as our processors, and are contractually barred from using your content to train their models.
If you would rather no AI provider saw a particular piece of text, do not paste it into these features. The deterministic checks in the phishing analyser, and every other part of the product, work without them.
Breach and exposure data
Breach checking tells you whether an address or domain appears in datasets we can query. Those datasets are incomplete and are not real-time. “No breaches found” means it does not appear in what we can see, not that it has never been exposed.
Where a breach-checking provider requires the address itself rather than a hash prefix, the lookup runs on our servers rather than in your browser, so the provider receives our address and not yours.
Who we share data with
We use processors who act on our instructions under contract. We do not sell personal data, and we do not share it for anyone else’s marketing.
| Recipient | What they process | Why |
|---|---|---|
| Microsoft Azure | Application data, database, cache, file storage, logs | Hosting the platform |
| Cloudflare | Request metadata, IP addresses | Content delivery, TLS and attack mitigation |
| Stripe | Billing contact details, payment credentials | Payments, subscriptions and the customer portal |
| Resend | Email address, message content | Service email such as security alerts, account notices and billing |
| Brevo | Name, email address, which form you used | Customer relationship records and, where you opted in, marketing email |
| Anthropic | The text an AI feature needs | Generating a response, as described above |
| OpenAI | Text submitted for semantic search | Generating embeddings for search and retrieval |
| Breach data providers | An email address or domain to check | Breach and exposure checking |
We may also disclose information where required by law, or where necessary to establish, exercise or defend a legal claim.
When you use a contact form
We create a contact record in our customer relationship tool, holding your name, your email address and which form you used, so we can reply and recognise you next time. We do not copy the content of your message into that record. Ask us at privacy@cmsinfosec.com and we will delete it.
International transfers
We aim to keep data in the UK or the EEA. Where a processor operates outside the UK, we rely on the UK International Data Transfer Addendum to the European Commission’s standard contractual clauses, or on UK adequacy regulations where they apply.
How long we keep it
- Account data. For as long as your account is open, and up to 90 days after you close it, so an account deleted in error can be restored.
- Content you created. Deleted with the account, on the same schedule.
- Billing records. Seven years, because tax law requires it.
- Security and audit logs. Up to 12 months.
- Support correspondence. Up to three years after the last message.
- Marketing consent records. For as long as the consent stands, plus a record of its withdrawal.
Your rights
You can ask us to give you a copy of your data, correct it, erase it, restrict or object to our processing (including anything we do because we have a fair reason), or provide it in a portable format. Much of this is available directly in your account settings. For the rest, write to privacy@cmsinfosec.com. We respond within one month.
You can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you raised it with us first, but that is your choice.
Security, and its deliberate limit
We protect personal data with technical and organisational measures appropriate to the risk: encryption in transit and at rest, role-based access control, multi-factor authentication, and audit logging.
More important than any of those is what the product deliberately cannot do. We do not install agents on your machines, we do not ask for administrative access to your email or systems, and we do not connect to your infrastructure. Everything the platform does is guidance, self-assessment, document generation and checks against publicly visible information.
That is a limit on the product, chosen on purpose. It means a breach of us can never become a breach of you.
Report a security problem to security@cmsinfosec.com.
Children
Cyber Made Simple is for adults and for businesses. We do not knowingly collect personal data from children.
Changes
If this policy changes substantively, the “Last updated” date at the top of this page moves in the same revision, and we tell account holders where the change is material.
