Privacy Policy
- Last updated:
- November 6, 2025
- Effective:
- November 20, 2025
This Privacy Policy explains how CyberRank (“we”, “us”) collects, uses, shares, and protects personal information when you use our website, sign up for an account, or interact with our vendor risk assessment platform. Our role is typically that of a processor for Customer Data submitted by our customers, and a controller for account and marketing data we collect directly.
What We Collect
We collect three categories of information:
- Information you provide. Account details (name, work email, company), billing information, support requests, and any content you upload to the workspace (assessment responses, evidence files, vendor records).
- Information collected automatically. Device and browser metadata, IP address, pages visited, feature usage, and crash diagnostics. We use cookies and similar technologies as described in our Cookie Policy.
- Information from third parties. Identity verification providers, single sign-on directories you connect (such as Okta or Google Workspace), and publicly available business information used to enrich vendor profiles.
How We Use Information
We use personal information to:
- Provide, maintain, and improve the Service;
- Authenticate users, prevent fraud, and protect account security;
- Generate aggregated, de-identified insights about questionnaire performance;
- Communicate with you about your account, billing, and product updates;
- Comply with our legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not use Customer Data to train third-party AI models without your prior agreement.
International Data Transfers
CyberRank operates globally. Where we transfer personal data across borders, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or your explicit consent, depending on the jurisdiction.
Data Retention
We retain personal information for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to your workspace settings; when you cancel your account, we will delete or return Customer Data within a reasonable period unless retention is legally required.
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, port, or object to processing of your personal information. To exercise these rights, contact us at privacy@cyberrank.example. If you are using CyberRank through your employer, please contact them first, as they control your workspace data.
Security
We maintain a layered information security program aligned with ISO/IEC 27001 and SOC 2. Controls include encryption in transit and at rest, least-privilege access, continuous monitoring, and regular penetration testing. No system can be guaranteed perfectly secure; you can read more about our controls on our Compliance page.
Children's Privacy
CyberRank is intended for business users and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.
Contact Us
If you have questions about this Privacy Policy or how we handle your information, please contact our privacy team at privacy@cyberrank.example. Customers in the EU/UK may also contact our designated representative through the same address.
Need legal evidence?
We can share audit reports, DPAs, or country-specific addenda under NDA.