Team Safety Snapshot now live, 10 founding partner spots at £39. Claim yours →
Privacy Policy
Last updated: August 2026
CyberSafe Coach+ helps individuals, families, charities, small businesses, schools and care providers understand and improve their digital safety. This policy explains what data we collect, how we use it, and your rights, in plain English.
What we collect
Account information
Email address for login, plus optional profile details (first name, display name, organisation name)
Assessment results
Your safety score and recommendations, only stored if you create an account
Progress tracking
Which fixes you've completed, your score history, and improvements over time
Badges and streaks
Achievement badges earned, weekly task completion streaks, and gamification progress
Weekly tasks
Personalised security tasks generated based on your assessment results
Anonymous usage patterns
Which features are used (not who uses them)
Feedback
Thumbs up/down responses, anonymous and voluntary
What we don't collect
- ✓Scam Check message content, analysed then immediately discarded
- ✓Images you upload, processed then deleted
- ✓Your browsing history outside our site
- ✓Location data
- ✓Payment card data, we use Stripe to process subscription payments for paid plans. Payment card data is handled directly by Stripe and is never stored on our servers. See Stripe's privacy policy at stripe.com/gb/privacy for details
How AI processing works
Our Scam Check feature uses AI to analyse messages and images you share. Here's what happens:
- • Content is sent securely to our AI service
- • It's analysed and a response is generated
- • Your content is immediately discarded, we don't store it
- • We don't train AI models on your submissions
- • No human reviews your submissions
Email communications
We send emails for essential account functions and optional reports. Our email service is provided by Resend.
- • Account emails, password resets, email verification
- • Results emails, your assessment results (only when you request them)
- • Compliance reports, PDF reports sent to your email (only when you request them)
- • Guest reports, one-time reports for users without accounts
We do not send marketing emails or newsletters. Your email address is only used for service-related communications you explicitly request.
Business contacts and outreach
This section applies if you have heard from us about our services, rather than having signed up for an account.
We hold limited business contact information about people who work at charities, schools, care providers, small businesses and other organisations we believe our services may help. This is normally a name, job title, organisation, work email address, and notes about any conversation we have had.
Where it comes from
- • Our own professional network, including LinkedIn connections
- • Contact details published on an organisation’s own website
- • Public registers, including the Care Quality Commission, the Charity Commission, Get Information about Schools, and the NHS Data Security and Protection Toolkit
Why we are allowed to hold it
Our lawful basis is legitimate interests, under Article 6(1)(f) of the UK GDPR: contacting organisations in a professional capacity about services relevant to their work. We have carried out and recorded a balancing test. We contact people only in their professional role, only about matters relevant to that role, and we say who we are and why we are writing every time.
Telling you where we got your details
Where we obtained your details from a source other than you, we will tell you which kind of source when we first contact you, and this page sets out the categories we use.
Your right to object
You can tell us to stop at any time, by replying to any email or by contacting us directly. We do not need a reason and we will not ask for one. We keep a suppression list of everyone who has asked not to be contacted. That list is held separately from our contact records, so it keeps working even if we delete everything else we hold about you, and so you cannot be contacted again by mistake.
We do not sell or share this information, we do not use it for automated decision-making, and we do not build profiles beyond deciding whether our services are relevant to an organisation. Business contact details are kept for 24 months from our last meaningful contact with you and are then deleted. Suppression records are kept indefinitely, because keeping them is the only way to honour an objection.
Cookies & Analytics
We use cookies to understand how visitors interact with our site. Here's what we use:
Essential Cookies
Required for basic site functionality like remembering your preferences and login state. These cannot be disabled.
Analytics Cookies (Google Analytics 4)
We use Google Analytics to understand how visitors use our site. This helps us improve the experience. Data collected includes:
- • Pages visited and time spent
- • Device type and browser
- • General location (country/region)
- • How you arrived at our site
Your choice: You can accept or decline analytics cookies. We use Google's Consent Mode, so if you decline, no analytics data is collected about your visit.
You can change your cookie preferences at any time from the homepage footer.
Anonymous usage tracking
As the service is actively evolving, we track how features are used to understand what's most helpful. This tracking is:
- • Anonymous, not linked to your identity
- • Session-based, uses a random ID that changes each visit
- • Limited, only tracks feature usage, not personal details
- • Optional, you can clear your browser storage to reset
Your rights
Under applicable data protection laws (including GDPR), you have the right to:
- • Access, request a copy of your data
- • Delete, remove your account and all associated data
- • Export, receive your data in a portable format
- • Withdraw consent, at any time
- • Object, tell us to stop contacting you or to stop using your data for outreach
- • Correct, have anything we hold about you that is wrong put right
- • Restrict, ask us to pause using your data while a query is sorted out
You can also complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.
Data retention
We retain your data only as long as necessary:
- • Account data, retained while your account is active
- • Assessment results, retained while your account is active
- • Progress & badges, retained while your account is active
- • Analytics data, aggregated and anonymised after 90 days
- • Scam Check content, not retained (processed and immediately discarded)
- • Business contact details, 24 months from our last meaningful contact with you
- • Suppression records, kept indefinitely, so that a request not to be contacted keeps being honoured
When you delete your account, all your personal data is permanently removed within 30 days.
Account deletion
You can request deletion of your account and all associated data at any time by contacting us. When you delete your account:
- • Your profile information is permanently removed
- • All assessment results are deleted
- • Progress tracking, badges, and streaks are removed
- • Weekly tasks and score history are deleted
- • Your login credentials are permanently deleted
This process is irreversible. Anonymised, aggregated analytics data may be retained as it cannot be linked back to you.
Administrative access
A limited number of authorised administrators have access to:
- • Aggregated analytics, anonymous usage patterns and trends
- • User lookup, ability to find accounts by ID for support purposes
- • Account management, ability to reset or delete accounts upon user request
Administrative access is logged and restricted to essential support and service improvement purposes only.
Data security
- • All data is encrypted in transit (TLS) and at rest
- • Hosted on secure infrastructure with industry-standard protections
- • Email services provided by Resend with secure transmission
- • Role-based access controls for administrative functions
- • No third-party advertising or marketing trackers
- • We will never sell your data
Questions?
If you have questions about this policy or want to exercise any of your rights, including asking us to stop contacting you, email admin@cybersafecoach.co.uk. We aim to respond within 5 working days.
CyberSafe Coach Plus Ltd is the data controller and is registered with the Information Commissioner’s Office under reference ZC111800.
