Cyful is a cyber risk intelligence product operated by Cykube Ltd. ("the Assessment" refers to our Free Cyber Risk Assessment). We are committed to protecting personal data and complying with applicable data protection laws, including the UK GDPR and the Data Protection Act 2018.
01 Scope of This Policy
This Privacy Policy applies to:
- Visitors to the Cyful website
- Users requesting the Assessment
- Communications with Cyful (email, forms, demos)
It does not apply to third-party websites or services linked from Cyful.
02 Information We Collect
Depending on how you use Cyful, we may collect:
- The email address you submit to run the Assessment
- The results generated by your assessment, including your risk score, risk classification, breach and exposure indicators, and related metadata
- Name and business contact details, if provided through a contact or demo request form
- Standard information submitted through website forms
We do not collect or store your actual passwords. Our system checks whether your email appears in known breach records and returns only counts and risk indicators. Plaintext or hashed passwords are never stored in our database.
03 How We Use Your Information
- To run your Assessment and deliver your report
- To communicate reports, updates, and service information
- Security and fraud prevention
- Analytics and performance monitoring, using de-identified data (see Aggregate & Analytics Data below)
We do not sell personal data.
04 Legal Basis for Processing
Where UK GDPR applies, we rely on the following legal bases:
- Consent — from the person submitting the request, given on the basis that they own, or are otherwise authorized to use, the submitted email address. To help protect against misuse, we deliver your report only to the email address you submitted, and we never display results anywhere else.
- Legitimate interest — for basic security monitoring, fraud prevention, and for generating de-identified aggregate analytics that cannot be linked back to you
- Contract — where we are providing a service you have specifically requested, such as a report or a demo
You may withdraw consent at any time; see Your Rights below.
05 Special Category Data
Some breach records may reveal information that constitutes special category data under UK GDPR — for example, where the name of a breached platform itself indicates a person's health condition, sexual orientation, religious belief, or political opinion. Where this is the case, we generalize or suppress the specific source name in your report, rather than disclosing it directly, so that this category of data is not processed without an appropriate legal basis.
06 Data Sharing & Disclosure
To perform your assessment, the email address you submit is checked against records held by third-party breach-intelligence and threat-data providers. We share only the minimum data necessary to return exposure indicators to Cyful.
Data may also be shared with trusted cloud infrastructure providers strictly for service delivery. We do not sell personal data.
07 Automated Assessment & Decision-Making
Your risk score and classification are generated automatically based on the indicators described above. Under the Data (Use and Access) Act 2025, this type of automated assessment is permitted provided appropriate safeguards are in place. Accordingly: we tell you that your report was generated by an automated process; you may request human review of your result; you may make representations about it; and you may contest the outcome, by contacting us using the details below.
In all cases, the Assessment is informational only and must not be used, by Cykube Ltd. or any third party, as the sole or primary basis for an underwriting, credit, employment, insurance, or other significant decision about you.
08 Data Retention
We retain different categories of data for different periods, depending on their purpose:
- Assessment data — your report and the underlying scan data are retained for 7 days from generation, after which they are automatically and permanently deleted from our systems.
- Aggregate analytics — retained indefinitely in de-identified form. See Aggregate & Analytics Data below.
- Contact and business data — retained only as long as necessary to respond to your inquiry or provide the service requested, or as required by law.
09 Aggregate & Analytics Data
We may retain de-identified, aggregated statistics derived from assessments — such as risk-score distributions, breach-exposure trends, or security-hygiene patterns across regions — for research, benchmarking, and product-improvement purposes. This data is stripped of email addresses, names, and any other identifying information before it is retained, cannot be linked back to you, and may be kept indefinitely.
10 Your Rights
Subject to applicable law, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Restrict how we process your data
- Receive your data in a portable format
- Object to certain types of processing
- Withdraw consent at any time
To exercise any of these rights, contact us using the details below. We aim to respond within one month.
You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
11 Minimum Age
Our services are not directed at individuals under 18, and we do not knowingly collect personal data from minors.
12 Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date on this page.
13 Contact Us
For data questions or requests, contact: contact@cyful.net