Skip to main content

    Team Safety Snapshot now live, 10 founding partner spots at £39. Claim yours →

    CyberSafe Coach+
    Something happening right now?Digital 999
    Your privacy matters

    Privacy Policy

    Last updated: August 2026

    CyberSafe Coach+ helps individuals, families, charities, small businesses, schools and care providers understand and improve their digital safety. This policy explains what data we collect, how we use it, and your rights, in plain English.

    What we collect

    Account information

    Email address for login, plus optional profile details (first name, display name, organisation name)

    Assessment results

    Your safety score and recommendations, only stored if you create an account

    Progress tracking

    Which fixes you've completed, your score history, and improvements over time

    Badges and streaks

    Achievement badges earned, weekly task completion streaks, and gamification progress

    Weekly tasks

    Personalised security tasks generated based on your assessment results

    Anonymous usage patterns

    Which features are used (not who uses them)

    Feedback

    Thumbs up/down responses, anonymous and voluntary

    What we don't collect

    • Scam Check message content, analysed then immediately discarded
    • Images you upload, processed then deleted
    • Your browsing history outside our site
    • Location data
    • Payment card data, we use Stripe to process subscription payments for paid plans. Payment card data is handled directly by Stripe and is never stored on our servers. See Stripe's privacy policy at stripe.com/gb/privacy for details

    How AI processing works

    Our Scam Check feature uses AI to analyse messages and images you share. Here's what happens:

    • • Content is sent securely to our AI service
    • • It's analysed and a response is generated
    • • Your content is immediately discarded, we don't store it
    • • We don't train AI models on your submissions
    • • No human reviews your submissions

    Email communications

    We send emails for essential account functions and optional reports. Our email service is provided by Resend.

    • Account emails, password resets, email verification
    • Results emails, your assessment results (only when you request them)
    • Compliance reports, PDF reports sent to your email (only when you request them)
    • Guest reports, one-time reports for users without accounts

    We do not send marketing emails or newsletters. Your email address is only used for service-related communications you explicitly request.

    Business contacts and outreach

    This section applies if you have heard from us about our services, rather than having signed up for an account.

    We hold limited business contact information about people who work at charities, schools, care providers, small businesses and other organisations we believe our services may help. This is normally a name, job title, organisation, work email address, and notes about any conversation we have had.

    Where it comes from

    • • Our own professional network, including LinkedIn connections
    • • Contact details published on an organisation’s own website
    • • Public registers, including the Care Quality Commission, the Charity Commission, Get Information about Schools, and the NHS Data Security and Protection Toolkit

    Why we are allowed to hold it

    Our lawful basis is legitimate interests, under Article 6(1)(f) of the UK GDPR: contacting organisations in a professional capacity about services relevant to their work. We have carried out and recorded a balancing test. We contact people only in their professional role, only about matters relevant to that role, and we say who we are and why we are writing every time.

    Telling you where we got your details

    Where we obtained your details from a source other than you, we will tell you which kind of source when we first contact you, and this page sets out the categories we use.

    Your right to object

    You can tell us to stop at any time, by replying to any email or by contacting us directly. We do not need a reason and we will not ask for one. We keep a suppression list of everyone who has asked not to be contacted. That list is held separately from our contact records, so it keeps working even if we delete everything else we hold about you, and so you cannot be contacted again by mistake.

    We do not sell or share this information, we do not use it for automated decision-making, and we do not build profiles beyond deciding whether our services are relevant to an organisation. Business contact details are kept for 24 months from our last meaningful contact with you and are then deleted. Suppression records are kept indefinitely, because keeping them is the only way to honour an objection.

    Cookies & Analytics

    We use cookies to understand how visitors interact with our site. Here's what we use:

    Essential Cookies

    Required for basic site functionality like remembering your preferences and login state. These cannot be disabled.

    Analytics Cookies (Google Analytics 4)

    We use Google Analytics to understand how visitors use our site. This helps us improve the experience. Data collected includes:

    • • Pages visited and time spent
    • • Device type and browser
    • • General location (country/region)
    • • How you arrived at our site

    Your choice: You can accept or decline analytics cookies. We use Google's Consent Mode, so if you decline, no analytics data is collected about your visit.

    You can change your cookie preferences at any time from the homepage footer.

    Anonymous usage tracking

    As the service is actively evolving, we track how features are used to understand what's most helpful. This tracking is:

    • Anonymous, not linked to your identity
    • Session-based, uses a random ID that changes each visit
    • Limited, only tracks feature usage, not personal details
    • Optional, you can clear your browser storage to reset

    Your rights

    Under applicable data protection laws (including GDPR), you have the right to:

    • Access, request a copy of your data
    • Delete, remove your account and all associated data
    • Export, receive your data in a portable format
    • Withdraw consent, at any time
    • Object, tell us to stop contacting you or to stop using your data for outreach
    • Correct, have anything we hold about you that is wrong put right
    • Restrict, ask us to pause using your data while a query is sorted out

    You can also complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first, but you do not have to.

    Data retention

    We retain your data only as long as necessary:

    • Account data, retained while your account is active
    • Assessment results, retained while your account is active
    • Progress & badges, retained while your account is active
    • Analytics data, aggregated and anonymised after 90 days
    • Scam Check content, not retained (processed and immediately discarded)
    • Business contact details, 24 months from our last meaningful contact with you
    • Suppression records, kept indefinitely, so that a request not to be contacted keeps being honoured

    When you delete your account, all your personal data is permanently removed within 30 days.

    Account deletion

    You can request deletion of your account and all associated data at any time by contacting us. When you delete your account:

    • • Your profile information is permanently removed
    • • All assessment results are deleted
    • • Progress tracking, badges, and streaks are removed
    • • Weekly tasks and score history are deleted
    • • Your login credentials are permanently deleted

    This process is irreversible. Anonymised, aggregated analytics data may be retained as it cannot be linked back to you.

    Administrative access

    A limited number of authorised administrators have access to:

    • Aggregated analytics, anonymous usage patterns and trends
    • User lookup, ability to find accounts by ID for support purposes
    • Account management, ability to reset or delete accounts upon user request

    Administrative access is logged and restricted to essential support and service improvement purposes only.

    Data security

    • • All data is encrypted in transit (TLS) and at rest
    • • Hosted on secure infrastructure with industry-standard protections
    • • Email services provided by Resend with secure transmission
    • • Role-based access controls for administrative functions
    • • No third-party advertising or marketing trackers
    • • We will never sell your data

    Questions?

    If you have questions about this policy or want to exercise any of your rights, including asking us to stop contacting you, email admin@cybersafecoach.co.uk. We aim to respond within 5 working days.

    CyberSafe Coach Plus Ltd is the data controller and is registered with the Information Commissioner’s Office under reference ZC111800.