Privacy Policy

Last updated: October 2026

This Privacy Policy explains how Cyberlab Security Limited collects, uses, and protects your personal data when you use the HackRisk platform. We are committed to transparency and your rights under UK GDPR.

1. Who We Are

The data controller for the HackRisk platform is Cyberlab Security Limited (Company No. 12392586), registered in England and Wales, with its registered office at Mereside, Alderley Park, Congleton Road, Macclesfield, SK10 4TG. We are registered with the Information Commissioner's Office (ICO). For all privacy enquiries, please contact [email protected].

2. What Data We Collect

We collect and process the following categories of data: (a) Account data - name, email address, job title, and organisation details provided when you create an account; (b) Technical data - IP addresses, browser type, device identifiers, and usage logs collected automatically when you use the Service; (c) Scan data - domain names, IP ranges, and related technical information you submit for monitoring; (d) Communication data - messages and correspondence you send to us via email or in-app; (e) Payment data - billing address and transaction records (payment card details are processed directly by our payment provider and are not stored by us).

3. How We Use Your Data

We use your data to: (a) provide, maintain, and improve the HackRisk platform; (b) process payments and manage your subscription; (c) send service notifications, security alerts, and account-related communications; (d) send marketing communications where you have given consent or where we have a legitimate interest in doing so (you may opt out at any time); (e) comply with legal obligations; (f) investigate and prevent fraud, abuse, or security incidents; (g) generate anonymised, aggregated statistical insights about platform usage. The legal bases for processing are contract performance, legitimate interests, legal obligation, and consent (where indicated).

4. Data Retention

We retain account data for as long as your subscription is active, plus a further 12 months to handle any post-termination queries. Scan data and reports are retained for the duration of your subscription and deleted within 90 days of account closure. We retain financial records for 7 years to comply with HMRC requirements. Accounts with no purchasing activity are retained for 2 years. You may request earlier deletion subject to our legal obligations.

5. Your Rights (GDPR / UK GDPR)

Under UK GDPR, you have the right to: be informed about how we use your personal data, as this policy is designed to explain; access a copy of the personal data we hold about you; rectify inaccurate data; request erasure of your data in certain circumstances; restrict or object to processing; object at any time to processing of your personal data for direct marketing; object to decisions being taken by automated means which produce legal effects concerning you or similarly significantly affect you; request data portability in a structured, commonly used and machine-readable format and receive your personal information in a portable format; withdraw consent where processing is consent-based; and lodge a complaint with the ICO (ico.org.uk). To exercise any of these rights, email [email protected]. We will respond within 30 days.

6. Cookies

We use the following categories of cookies, which are the same four you are offered in our cookie banner: (a) Strictly necessary - required for the service to work (e.g. keeping you signed in), always on and not something you can switch off; (b) Analytics - used to understand how the site is used; (c) Advertising - used to measure our campaigns and to identify the organisations visiting the site; (d) Partner attribution - used to credit the partners who refer customers to us. The essential cookies required for the platform to function (session management, authentication) are Functional cookies, and do not require consent. Subject to your consent, we also use Google Analytics to understand how visitors use the website, Microsoft Clarity to see how pages are used, the LinkedIn Insight Tag to measure our campaigns, Leadfeeder to identify the organisations visiting the site, and Refersion, PartnerStack and Impact to credit the partners who refer customers to us. Of those, Google Analytics and Microsoft Clarity fall into the Analytics category, LinkedIn and Leadfeeder into the Advertising category, and Refersion, PartnerStack and Impact into the Partner attribution category. Google's tags are loaded with analytics and advertising storage denied until you accept, so declining is honoured rather than ignored: measurement continues without cookies. The others are not loaded at all unless you accept. You can change your mind at any time using the Cookie Settings link in the footer of any page, which reopens these choices and lets you turn any category on or off; or by clearing this site's data in your browser. We also use PostHog, hosted in the EU, to understand how the website is used. For every visitor it runs without cookies and stores nothing in your browser, so the banner does not ask about it: it receives the address of the page you are viewing, how quickly the page loaded and responded, the forms you submit and checkouts you start (never what you type into them), and your IP address, which PostHog anonymises as it arrives. If you accept Analytics cookies, PostHog also sets a first-party cookie and stores a small amount of data in your browser so that it can recognise a return visit, and it records how you use the site, including clicks and a replay of your session with anything you type into a form hidden. If you later turn Analytics off, PostHog stops recording, clears what it stored in your browser and goes back to running without cookies. Separately from cookies, this website stores a small amount of information in your own browser that is never sent to a third party: your cookie choice and your light or dark theme preference, so both are remembered, and, if you arrived from a campaign or a partner link, the details of that link for the duration of your visit so we can attribute the enquiry correctly. Our website also offers a chat assistant, provided by ElevenLabs. It is not loaded at all until you press the chat button: if you never open a chat, nothing is requested from ElevenLabs and nothing is stored. Once you do open it, it stores a randomly generated conversation reference in your browser for the current tab only, which is deleted when you close the tab and is never linked to you or to any other visit. Where the chat software would ordinarily identify your device by its characteristics - a technique known as fingerprinting - we supply that random reference instead, specifically so that it does not. Opening the chat also loads a typeface from Google Fonts, which means your IP address is visible to Google in order to serve it. Third-party services embedded in the platform (such as the interactive product demo provided by Storylane) may set their own cookies subject to their own privacy policies. We also use Cloudflare Turnstile on our forms to tell people from automated abuse; it runs on the contact and free report pages without setting cookies of its own.

7. Third-Party Services

We share data with the following categories of third-party sub-processors: cloud hosting providers (data hosted in the UK/EEA); payment processors (Chargebee); email delivery providers (Postmark); analytics providers (Google Analytics, Microsoft Clarity and PostHog, hosted in the EU); advertising and partner attribution providers (LinkedIn, Leadfeeder, Refersion, PartnerStack and Impact); form abuse prevention (Cloudflare Turnstile); our website content management system (Sanity); our website chat assistant (ElevenLabs, and the large language model provider it uses to generate replies), which receives the messages you type into the chat and is instructed never to ask you for personal details - if you want to be contacted, it directs you to our contact form instead; and our customer relationship system (Pipedrive), which receives the details you submit through our enquiry and free report forms. Chat conversations are processed in the United States and are deleted after 30 days. We ensure all sub-processors provide adequate data protection guarantees. We do not sell personal data to third parties. Where data is transferred outside the UK/EEA, we rely on approved transfer mechanisms such as UK IDTA or Standard Contractual Clauses.

8. Changes to This Policy

We may change this Privacy Policy from time to time. Where we do, we will update the "last updated" date at the top of this page and, where the change is material, tell you about it by a notice on this website and, for customers, by email or by a notice on invoices raised to you. We keep this policy under regular review.

9. Contact the Data Controller

For any privacy-related questions, requests, or concerns, please contact our Data Protection lead, Sandra Lovell-Struthers, Head of Compliance, at [email protected]. You may also write to the Data Protection Officer, Cyberlab Security Limited, Mereside, Alderley Park, Congleton Road, Macclesfield, SK10 4TG. For formal complaints, you may also contact the ICO at ico.org.uk, by calling 0303 123 1113, or by writing to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.