Privacy Policy
What Cyber VK collects, why each item is collected, how long it is kept, who else sees it, and how to get a copy or have it deleted.
- Effective from
- Last updated
The principle this policy follows
Collect what the feature needs and nothing else, keep it only as long as the reason for collecting it lasts, and make it easy to see and to remove. Everything below is a consequence of that rather than a separate promise.
What we collect and why
| Data | Why | Retention |
|---|---|---|
| Email address | Account identity, sign-in, and transactional messages such as receipts and security alerts | Life of the account, then 30 days |
| Guest checkout email | Delivering a voucher, receipt, order status and essential support messages without requiring an account | Retained with the order for tax, fraud prevention and customer support obligations |
| Password hash | Authentication. The password itself is never stored and cannot be recovered from the hash | Life of the account |
| Display name and optional profile | Attribution on community posts, writeups and leaderboards | Until you change or remove it |
| Learning progress | Resuming where you left off, and issuing certificates that mean something | Life of the account |
| Lab and CTF session records | Enforcing concurrency and quota limits, and investigating abuse | 90 days |
| Payment records | Billing, refunds, and the tax and accounting records we are required to keep | As required by tax law, typically 7 years |
| Security and audit logs | Detecting account takeover, abuse of the sandbox plane, and platform attacks | 180 days |
| Analytics events | Understanding which parts of the product are used, in aggregate | 14 months |
Card numbers and security codes are never collected by Cyber VK. PayHere hosts the payment page and handles payment credentials directly. We receive the order and payment references, status, amount, currency, method and, where supplied for account billing, masked card details needed to recognise a payment method.
The basis for each use
- Performing the contract: account, progress, sandbox provisioning, billing. Without these there is no service.
- Legitimate interests: security logging, abuse detection, and aggregate product analytics. Each of these is balanced against your interests and is documented internally.
- Legal obligation: tax and accounting records.
- Consent: optional marketing email, which is off by default and is withdrawn with one click.
Who else sees your data
Processors only, each under a contract that limits them to acting on our instructions: the hosting provider, the payment provider, the transactional email provider, and the error and performance monitoring service. We do not sell personal data, we do not share it with advertisers, and we do not use it to train models offered to anyone else.
Where you use the AI features, the conversation is sent to a model provider under a contract that prohibits training on it. What you type into the AI tutor is not used to improve anyone model.
Your rights, and how to use them
- Access and portability: export your account data from the account page as a machine-readable file, without contacting anyone.
- Correction: change your profile and account details directly.
- Deletion: delete your account from the account page. Public content you posted is removed from view immediately, and the underlying records are erased within 30 days except where tax law requires a payment record to be kept.
- Objection and restriction: contact support and we will action it. Where we decline, we will say why.
- Complaint: contact support first so we can investigate, and you may also complain to the data protection or consumer authority that has jurisdiction where you live or where the operating entity is established.
Cookies
A session cookie to keep you signed in, a preference cookie for your theme choice, and a CSRF token. That is the entire list. There are no advertising cookies and no third-party trackers, which is also why there is no consent banner: a banner that asks permission for cookies you are entitled to set regardless is theatre.
Where your data is held
The service may use infrastructure and processors in more than one country. Where personal data crosses borders, we use the contractual and technical safeguards required by applicable law. Current processor and hosting-region information is available from support because it may change without changing what data we collect or why.
Children
The platform is not intended for anyone under 16. If we learn that an account belongs to someone younger, we close it and delete the data.
If something goes wrong
If a breach affects your personal data and is likely to be a risk to you, we will tell you directly and promptly, with what happened, what was affected, and what we are doing about it. We will do that even where the notification threshold in law is arguably not met, because a security education platform that hedges on its own disclosure has no standing to teach anyone else about theirs.