Privacy Policy

Last updated: 10 September 2026

Who we are

CyberStatus UK is a trading name operated by David Wells, a sole trader in England. David Wells is the data controller for the information described here.

Business and correspondence address (not a customer walk-in location):
The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, United Kingdom

Privacy contact: privacy@cyberstatusuk.co.uk

Information we handle

Account. Your email address, an account identifier and authentication/sign-in information. Your password is handled by our authentication provider; we do not have access to your plaintext password.

Business profile. Industry, employee range, remote-working status, whether the business takes payments, whether it stores customer data, and which productivity platform you use.

Assessments. Your 25 core answers, any optional module answers, your score, points, band and category scores, critical risks, Operational Risk and related timestamps.

Guided Fix. Which fixes you have marked complete and the assessment they relate to.

Report requests and Protect interest. The email address you give us, and marketing consent where you have explicitly provided it.

Protect subscriptions. Payment-provider customer and subscription identifiers, subscription status and tier, and paid-through/cancellation information.

Usage. First-party product events (for example that a results page was viewed) and standard campaign parameters. These events do not contain assessment answers or email addresses.

Our infrastructure providers may also process technical request and log information that is necessary to host and secure the service.

Why we use it, and our lawful bases

  • To provide accounts, assessments, scores, Guided Fix and Protect — performance of a contract, or steps requested by you before entering a contract, as appropriate.
  • To operate, secure and improve the service — our legitimate interests, where appropriate.
  • To administer payments and subscriptions — performance of a contract, and legal obligations where applicable.
  • To meet legal, accounting and security obligations — legal obligation and/or legitimate interests, as appropriate.
  • Marketing — consent, where consent is specifically requested.

Things we do not do

  • Your assessment answers are not sent to an AI model or AI provider.
  • We do not sell personal data.
  • We do not receive or store full payment-card numbers, expiry dates or CVCs. Stripe handles card entry on its own hosted payment pages.

Service providers

  • Lovable / Lovable Cloud — hosting and managed backend services, including database, authentication and server functions.
  • Stripe — subscription and payment processing.

The exact hosting and database region is not represented to you as UK-only. Some service providers may process information internationally, and appropriate safeguards are used where required.

How long we keep information

This section describes our retention policy. Deletion is currently carried out manually rather than automatically.

  • Identifiable assessment, account and service records are normally retained while your account is active, and for up to 12 months after account closure or last meaningful activity, where reasonably necessary to provide the service, resolve queries and maintain security and audit records.
  • Payment and accounting records may be retained longer where required by law.
  • Marketing information is retained until consent is withdrawn or it is no longer reasonably required.
  • Security and technical logs may be retained for shorter operational and security periods.
  • Information may be retained longer where necessary for a legal claim, dispute, fraud or security investigation, or a legal obligation.

Your rights

Under UK data-protection law you may have the right to access your information, have it corrected or erased, restrict or object to certain processing, request portability where applicable, and withdraw consent where processing relies on consent.

To exercise a right, email privacy@cyberstatusuk.co.uk. Requests are currently handled manually, so please allow a little time for us to respond.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Storage in your browser

We use a small amount of browser storage. Not all of it is cookies.

  • Authentication/session storage — keeps you signed in. Strictly necessary.
  • cybercheck_uk_assessment_v1 — local storage holding your in-progress assessment, answers, Guided Fix progress and a private claim token used to link an anonymous check to your account. Strictly necessary for the check to work.
  • Sidebar layout cookie — remembers whether a panel is open.
  • cyberstatus_acquisition_v1 — optional local storage retaining first-party campaign attribution (utm_source, utm_medium, utm_campaign). This is only written if you allow it, and declining does not affect the Cyber Health Check or your account.

CyberStatus UK is a self-assessment readiness tool. It is not a certification, penetration test or vulnerability scan, and it is not a guarantee of security.