Privacy Policy

LegalCyberReady Limited · Last updated 15 August 2026

1. Who We Are

CyberReady Limited is a company registered in England and Wales. We operate the CyberReady platform at cyberready.dev. For the purposes of UK GDPR and the Data Protection Act 2018, we are the controller of personal data collected through the Service.

If you have questions about this policy or our data practices, please contact us at info@cyberready.dev.

2. Data We Collect

  • Account data: name, email address, and password (managed via AWS Cognito).
  • Questionnaire data: your answers to the questionnaire, including information about your business, IT infrastructure, and security posture.
  • Payment data: billing details processed by Stripe. CyberReady does not store card numbers.
  • Usage data: IP address, browser type, pages visited, and timestamps.
  • Communications: emails you send to us and delivery email interactions.

3. Lawful Basis

We rely on the following lawful bases for processing your personal data:

  • Contract: processing necessary to deliver the Service you have purchased.
  • Legitimate interests: fraud prevention, security monitoring, and service improvement.
  • Legal obligation: compliance with applicable laws, including tax and anti-money laundering requirements.
  • Consent: for optional marketing communications (where applicable).

4. How We Use Your Data

  • To create and manage your account.
  • To generate your document package based on your questionnaire answers.
  • To process payment and issue receipts.
  • To send you your delivery package and support communications.
  • To detect and prevent fraud and abuse.
  • To improve the Service.

5. Who We Share Your Data With

We do not sell your data and we do not share it for advertising. We use a small number of service providers to run the Service. Each processes your data only on our instructions.

  • Anthropic— generates your documents from your questionnaire answers. Your answers are sent to Anthropic's API for this purpose. This is the core of how the Service works: without it we cannot produce your documents.
  • Amazon Web Services (AWS)— hosting, database, document storage, account sign-in and email delivery. Our infrastructure runs in AWS's Europe (Ireland) region.
  • Stripe — payment processing. Stripe collects your card details directly; they never reach our servers.
  • Sentry — error monitoring, so we can find and fix faults.
  • Inngest — schedules the background jobs that generate and deliver your documents.

Some of these providers are based outside the UK, which means your data may be transferred internationally. Where that happens we rely on the safeguards permitted under UK GDPR, such as the UK International Data Transfer Agreement or an approved addendum to the EU Standard Contractual Clauses.

We may also disclose data where we are required to by law, or to establish or defend a legal claim.

6. How We Protect Your Data

Your questionnaire answers describe where your security stands, including its weak points. We treat that as sensitive and hold it accordingly.

  • Encrypted in transit. The whole site is served over HTTPS, and plain HTTP requests are redirected to it.
  • Encrypted at rest. Both the database and your generated documents are encrypted in storage.
  • Documents are not public. Your document storage blocks public access entirely. Download links are individually signed and expire.
  • We never see your card details.Payment is handled on Stripe's own checkout; no card number reaches our systems.
  • We never see your password. Sign-in is managed by AWS Cognito, which stores credentials rather than us.
  • Staff access is logged.When a member of our team views or downloads an order's data, that access is recorded against the order.
  • Hosted in the EU.Our application, database and document storage run in AWS's Europe (Ireland) region.

No system is perfectly secure, and we will not claim otherwise. We hold no security certification at this time. If you believe you have found a vulnerability in our platform, please tell us at info@cyberready.dev — see our contact page for how we handle disclosures.

7. Data Retention

We retain your account and questionnaire data for as long as you have an active account and for a period of up to seven years thereafter, to comply with legal obligations and to support any renewal or dispute. You may request deletion of your data at any time by contacting info@cyberready.dev. Note that some data may be retained where required by law.

8. Your Rights

Under UK GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Request deletion of your personal data.
  • Object to or restrict processing.
  • Data portability.
  • Lodge a complaint with the Information Commissioner's Office (ICO).

To exercise any of these rights, please contact info@cyberready.dev.

9. Contact

For all data protection queries: info@cyberready.dev. If you already have an order, you can also raise a ticket from the Support tab in your portal and we will reply there.