Privacy notice
What we collect, why, how long we keep it, and how to have it deleted. Written from what our code actually does.
Last updated:
What we collect, and when
- Free cyber assessment
- Your organisation name and your answers to the assessment questions. These are sent to our server as soon as you begin — before the email screen — so we can compute your score. If you stop partway, they remain stored without being linked to an email.
- Diagnostic request
- Company, sector, city, name, role, work email, phone, preferred channel, and the problem description you type.
- Operator application
- Name, email, phone, city, professional profile, certifications, motivation, then your quiz, training and exam results.
- Incident report
- What you describe about the incident, your contact details, and any file you attach.
- All pages
- An anonymous session identifier and the channel you arrived through, so we can tell which channels work. No advertising, no resale, no third-party trackers.
Why
To reply to you, prepare a quote, compute your score, process an application, or handle an incident. We do not use this data for advertising and we do not sell it.
Who processes it
- Cloudflare (D1, R2, Workers)
- Hosting, database, and storage of attached files.
- SuiteDash
- Client relationship tracking and the client portal.
- Resend
- Transactional email (reports, acknowledgements).
These providers operate outside Cameroon. Transfers of personal data out of Cameroon are governed by Law 2024/017; we document these transfers and adapt our agreements as the implementing texts and the Authority become clearer.
How long
- Leads and diagnostic requests
- While the commercial relationship is active, then 24 months.
- Unfinished assessments
- 12 months, then deleted.
- Operator applications
- 24 months after last activity, so we can contact you if a territory opens.
- Incident files
- As set by the engagement contract; otherwise 24 months.
Your rights
You can ask for access, correction, deletion, or a copy of your data, and object to its commercial use. Write to [email protected]; we respond within 30 days and tell you what was done.
Security
Data travels over HTTPS. Attached files are stored without being served publicly. Administrative access is restricted. We do not claim to be invulnerable: if a breach affects you, we will tell you and notify the Authority as Law 2024/017 requires.
What is still open
Law 2024/017 provides for a data-protection Authority. As at the date above, we could not publicly confirm that it is operational. We apply the law's obligations regardless, and will update this page once the position is established.