Skip to content
The //Zyber// Security

Legal

Privacy Policy

This unified Privacy Policy explains how we collect, use, share, and protect personal data. It is written to comply with the EU/UK GDPR, California CCPA/CPRA, India's DPDP Act 2023 and IT Act 2000, and comparable global regulations.

Last updated · 2026-07-21Reviewed by counsel: pending (owner to confirm)

1. Who we are

The Zyber Security ("ZyberSecurity", "we", "us") operates the website at https://thezybersecurity.com and provides the offensive-security and compliance services described elsewhere on this site. For the personal data described in this policy we act as: Data Controller under GDPR; Business under CCPA/CPRA; Data Fiduciaryunder India's DPDP Act 2023.

General contact: contact@thezybersecurity.com. Privacy contact / DPO: privacy@thezybersecurity.com. Grievance officer (India, DPDP): grievance@thezybersecurity.com.

2. What data we collect

  • Contact data — name, business email, organization, role, message content — provided by you via the contact form.
  • Engagement data — client scoping details, statements of work, engagement artifacts. Handled under a separate MSA / DPA.
  • Technical data — IP address, user agent, coarse geolocation derived from IP, referrer, requested URL, timestamps. Collected in server logs for security and troubleshooting.
  • Analytics data — aggregate page-view counts and referrer paths, collected via a privacy-preserving analytics provider only if you consent. No third-party ad-network cookies are ever set.
  • Cookies — see our Cookie Policy.

We do not intentionally collect data of children under the applicable age of digital consent (13 in the US, 16 in most of the EU, 18 in India under DPDP).

3. Why we use it — legal bases

PurposeData usedGDPR basisCCPA purposeDPDP basis
Respond to inquiriesContact dataLegitimate interest / Contract stepsBusiness purposeLegitimate use / consent
Deliver servicesEngagement dataContractBusiness purposeContract / consent
Site security & abuse preventionTechnical dataLegitimate interestSecurityLegitimate use
AnalyticsAggregate technical dataConsentAnalytics (opt-in)Consent
Legal complianceAll aboveLegal obligationLegal complianceLegal obligation

4. Who we share it with

  • Sub-processors listed in our current DPA (updated periodically) — cloud hosting, email delivery, calendar scheduling, and error monitoring. Every sub-processor is bound by SCCs where personal data leaves its home region.
  • Professional advisers (legal, accounting, insurers) under duties of confidentiality.
  • Public authorities when required by law and only to the minimum extent required.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are defined by CCPA/CPRA. See Section 9 (Do Not Sell or Share).

5. International transfers

Personal data may be processed in the EU/UK, US, and India. For EU→non-adequate-country transfers we rely on the EU Standard Contractual Clauses (SCC 2021/914) plus supplementary measures. For UK transfers we rely on the UK IDTA. For India-outbound transfers we rely on DPDP Act 2023 Section 16 mechanisms and contract-based safeguards.

6. How long we keep it

  • Contact-form inquiries: 24 months from last interaction, unless you become a client.
  • Server logs: 90 days (rolling).
  • Client engagement data: per contract, typically 7 years for tax and audit obligations.
  • Analytics: aggregate only; no personal identifiers retained beyond 14 months.

7. Your rights

Under GDPR / UK GDPR you have the right to access, rectify, erase, restrict, port, and object; and to withdraw consent where processing is consent-based. You may lodge a complaint with your supervisory authority.

Under CCPA/CPRA (California residents) you have the right to know, delete, correct, opt-out of sale/sharing (we do not sell), limit the use of Sensitive Personal Information, and non-discrimination for exercising rights.

Under DPDP Act 2023 (India) you have the right to obtain a summary of your data, correction, completion, updating, erasure, and grievance redressal.

To exercise any right, email privacy@thezybersecurity.com. We respond within 30 days (GDPR / DPDP) or 45 days (CCPA), with one extension permitted where legally allowed.

8. Do Not Sell or Share (California)

The Zyber Security does not sell your personal information and does not share it for cross-context behavioral advertising. If you are a California resident and want to confirm this or exercise related rights, contact privacy@thezybersecurity.comwith "Do Not Sell / Share" in the subject line. We also honor the Global Privacy Control (GPC) signal automatically.

9. Grievance officer (India, DPDP)

Grievance officer: grievance@thezybersecurity.com. We acknowledge receipt within 3 business days and provide substantive response within the statutory 30-day window.

10. Security

We apply reasonable security practices and procedures aligned to the ISO/IEC 27001:2022 framework and India's Reasonable Security Practices Rules 2011. Personal data in transit is TLS-encrypted; at rest is AES-256 encrypted; access is least-privilege and MFA-gated.

11. Changes to this policy

We may update this policy from time to time. When we do, we update the "Last updated" date above and — for material changes — provide reasonable advance notice by email to clients and prominent notice on this page.

12. Contact

Questions? Email privacy@thezybersecurity.com.


This policy is a template ready to be reviewed and finalized by your privacy counsel before publication.