Privacy Policy

Last Updated: November 29, 2025

Effective Date: December 1, 2025

1. Introduction

Welcome to CoreCyber, a cybersecurity platform operated by Covenant Security Solutions International ("Company," "we," "us," or "our"). We are committed to protecting your privacy and ensuring the security of your personal information in compliance with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website corecyber.io and use our services (collectively, the "Services"). It also describes your privacy rights and how the law protects you.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our Services.

1.1 Data Controller Information:

Company Name: Covenant Security Solutions International

Service Name: CoreCyber

Address: Sheridan, Wyoming, United States

Email: legal@corecyber.io

Data Protection Officer: legal@corecyber.io

EEA/UK/CH Representative: Covenant Security Solutions Intl., 30 N. Gould St. STE 9374, Sheridan Wyoming USA, Email: legal@corecyber.io

2. Information We Collect

We collect information that falls into the following categories under GDPR and CCPA regulations:

2.1 Personal Information You Provide (CCPA Categories: A, B, C, H)

We collect information that you voluntarily provide to us when you:

  • Register or create an account
  • Request a penetration test or vulnerability assessment
  • Subscribe to our newsletter or communications
  • Contact us through our support channels
  • Participate in surveys or promotions
  • Upload documents or files to our platform
  • Make a payment for our services
  • Exercise your privacy rights

This information may include:

  • Full name (GDPR: Identity Data)
  • Email address (GDPR: Contact Data)
  • Company name, role, and business information (GDPR: Professional Data)
  • Phone number (GDPR: Contact Data)
  • Business address (GDPR: Contact Data)
  • Industry, company size, and organizational data (GDPR: Professional Data)
  • IP addresses and network information for security assessments (GDPR: Technical Data)
  • Payment information - processed by Stripe (GDPR: Financial Data, CCPA Category D)
  • Government-issued identification for identity verification via Stripe Identity (GDPR: Identity Data, CCPA Category G)
  • Security clearance information if voluntarily provided (GDPR: Special Category Data)
  • Communication preferences and marketing consents (GDPR: Marketing Data)
  • Any other information you choose to provide

2.2 Automatically Collected Information (CCPA Categories: F, G, K)

When you access our Services, we automatically collect certain information through cookies and similar technologies:

  • Device information: device type, operating system, browser type and version (GDPR: Technical Data)
  • IP address and approximate geolocation data (GDPR: Technical Data)
  • Log data: access times, pages viewed, referring URLs, clickstream data (GDPR: Usage Data)
  • Cookies and similar tracking technologies (see Section 7)
  • Usage data and analytics: features used, time spent, interaction patterns (GDPR: Usage Data)
  • Performance and diagnostic data: errors, crashes, load times (GDPR: Technical Data)
  • Network activity: bandwidth usage, connection quality (GDPR: Technical Data)
  • Inferences drawn from the above to create user profiles (CCPA Category K)

2.3 Information from Third Parties (CCPA Categories: B, C, F, G)

We may receive information about you from third-party sources, including:

  • Business partners and service providers (contact and professional information)
  • Social media platforms if you choose to connect your accounts (profile data)
  • Publicly available databases and data brokers (business information)
  • Marketing and analytics providers (demographic and behavioral data)
  • Threat intelligence feeds and security databases (security-related data)
  • Payment processors (transaction and verification data)
  • Identity verification services (identity confirmation data)

2.4 Sensitive Personal Information (GDPR Special Categories)

We do not intentionally collect sensitive personal information (special category data under GDPR) such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. However, we may collect:

  • Government-issued identification for identity verification purposes (with your explicit consent)
  • Security clearance information if you voluntarily provide it for professional services

Where we collect sensitive personal information, we will obtain your explicit consent and process it only for the specific purposes disclosed at the time of collection.

3. How We Use Your Information

We use the information we collect for the following business purposes under GDPR (legal bases) and CCPA:

3.1 Service Delivery (GDPR: Contract Performance, Legitimate Interests)

  • Provide, operate, and maintain our Services
  • Process your requests, transactions, and service orders
  • Conduct penetration tests and vulnerability assessments
  • Generate security reports, findings, and recommendations
  • Provide customer support and technical assistance
  • Authenticate users and manage access controls
  • Prevent fraud, abuse, and unauthorized access
  • Perform identity verification through Stripe Identity
  • Process payments securely through Stripe

3.2 Communication (GDPR: Consent, Contract Performance, Legitimate Interests)

  • Send you service-related notifications, updates, and confirmations
  • Respond to your inquiries, requests, and support tickets
  • Send marketing communications (with your consent - you can opt-out anytime)
  • Provide security alerts, threat notifications, and vulnerability disclosures
  • Send newsletters, educational content, and security best practices
  • Notify you of changes to our Terms of Service or Privacy Policy
  • Conduct customer satisfaction surveys and feedback requests

3.3 Improvement and Development (GDPR: Legitimate Interests)

  • Analyze usage patterns and user behavior to improve our Services
  • Develop new features, tools, and functionality
  • Conduct research, analytics, and statistical analysis
  • Enhance security measures and threat detection capabilities
  • Troubleshoot technical issues and optimize performance
  • Test and evaluate new technologies and methodologies
  • Create aggregated, anonymized data for industry research

3.4 Legal and Compliance (GDPR: Legal Obligation, Vital Interests)

  • Comply with legal obligations under GDPR, CCPA, and other regulations
  • Enforce our Terms of Service, policies, and agreements
  • Protect our rights, property, safety, and that of our users
  • Respond to legal processes, court orders, and government requests
  • Prevent fraud, security threats, cybercrimes, and illegal activities
  • Investigate and respond to data breaches or security incidents
  • Maintain records required by law or regulation
  • Defend against legal claims and disputes

3.5 Automated Decision-Making and Profiling (GDPR Article 22)

We may use automated processing, including AI and machine learning, to:

  • Detect anomalies and potential security threats in your systems
  • Prioritize and classify vulnerabilities based on risk severity
  • Generate personalized security recommendations
  • Assess the security posture of your infrastructure

You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significantly affects you. You may request human intervention, express your point of view, and contest automated decisions by contacting legal@corecyber.io.

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

  • Consent (GDPR Article 6(1)(a)): You have given clear, affirmative consent for us to process your personal data for specific purposes, such as marketing communications, cookies, or special category data. You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
  • Contract Performance (GDPR Article 6(1)(b)): Processing is necessary to fulfill our contractual obligations to you (e.g., providing security assessments you purchased) or to take steps at your request before entering into a contract (e.g., processing your service inquiry).
  • Legitimate Interests (GDPR Article 6(1)(f)): Processing is necessary for our legitimate business interests or those of a third party, provided these interests do not override your fundamental rights and freedoms. Our legitimate interests include: improving our Services, preventing fraud and abuse, network and information security, internal administration, and direct marketing (where consent is not required).
  • Legal Obligation (GDPR Article 6(1)(c)): Processing is necessary to comply with legal obligations under EU or Member State law, such as responding to lawful requests from authorities, maintaining records required by law, or complying with tax and accounting regulations.
  • Vital Interests (GDPR Article 6(1)(d)): Processing is necessary to protect the vital interests of you or another person, such as in emergency situations involving threats to life or security.
  • Public Interest (GDPR Article 6(1)(e)): Processing is necessary for the performance of a task carried out in the public interest, such as contributing to cybersecurity threat intelligence sharing for public safety.

When relying on legitimate interests, we conduct a balancing test to ensure our interests do not override your rights. You have the right to object to processing based on legitimate interests at any time.

5. How We Share Your Information

We may share your information in the following circumstances. Under CCPA, we disclose the categories of personal information shared with each category of third party:

5.1 Service Providers (CCPA: Disclosed for Business Purposes)

We engage third-party service providers who process personal data on our behalf as data processors (GDPR) or service providers (CCPA). We share Categories A, B, C, F, G, H with:

  • Cloud hosting and infrastructure providers: Vercel (hosting) and a managed cloud database service (database) - Categories A, B, C, F, G, H
  • Email service providers: Resend (email delivery) - Categories A, B, C
  • Payment processors: Stripe (payment processing and identity verification) - Categories A, B, C, D, G, H
  • Analytics and monitoring services: Google Analytics (usage analytics) - Categories F, G
  • Customer support platforms: Support ticket and chat systems - Categories A, B, C
  • Security and vulnerability scanning tools: Security testing platforms - Categories F, G, H
  • Communication platforms: SMS and notification services - Categories A, B

These providers have access to your information only to perform specific tasks on our behalf under written contracts that obligate them to protect your information, not use it for their own purposes, and comply with applicable data protection laws. We conduct due diligence on all service providers to ensure GDPR and CCPA compliance.

5.2 Business Partners (CCPA: Disclosed for Business Purposes) We may share Categories A, B, C with strategic business partners for joint service offerings, co-marketing initiatives, or referral programs. These partners are required to protect your information and use it only for the specified purpose. We will notify you before sharing your information with business partners and obtain your consent where required.

5.3 Business Transfers If we are involved in a merger, acquisition, sale of assets, bankruptcy, reorganization, or other business transaction, your information may be transferred as part of that transaction. In such cases, the acquiring entity will be bound by this Privacy Policy. We will notify you via email and/or prominent notice on our website of any change in ownership, uses of your personal information, and any choices you may have regarding your information.

5.4 Legal Requirements and Protection

We may disclose your information if required to do so by law or if we believe in good faith that such disclosure is necessary to:

  • Comply with subpoenas, court orders, legal processes, or lawful requests from government authorities
  • Enforce our Terms of Service, policies, or other agreements
  • Protect the rights, property, or safety of CoreCyber, our users, or the public
  • Investigate, prevent, or take action regarding suspected fraud, security issues, illegal activities, or violations of our policies
  • Respond to data subject access requests or other privacy rights requests as required by law
  • Protect against legal liability or defend legal claims

We will disclose only the minimum information necessary to fulfill the legal requirement and will challenge overly broad or inappropriate requests where possible.

5.5 With Your Consent We may share your information with third parties when you have given us explicit, informed consent to do so. Examples include: sharing testimonials or case studies (with your permission), participating in third-party integrations you authorize, or any other purpose you specifically approve.

5.6 Aggregated and De-Identified Data We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you for research, analytics, industry benchmarking, marketing, or other purposes. This data is not considered personal information under GDPR or CCPA and is not subject to the restrictions in this Privacy Policy.

5.7 No Sale of Personal Information We DO NOT sell your personal information as defined by the CCPA. We have not sold personal information in the preceding 12 months and do not have plans to do so in the future. We do not share personal information with third parties for their direct marketing purposes without your explicit consent.

6. International Data Transfers

CoreCyber is based in the United States. Your information may be transferred to, stored, and processed in the United States and other countries where we or our service providers operate. These countries may have data protection laws that differ from those in your country of residence.

6.1 GDPR Transfer Mechanisms

When we transfer personal data from the EEA, UK, or Switzerland to countries outside these regions, we implement appropriate safeguards as required by GDPR:

  • Standard Contractual Clauses (SCCs): We use the European Commission's Standard Contractual Clauses (also known as Model Clauses) for transfers to countries without adequacy decisions.
  • Data Processing Agreements (DPAs): We enter into comprehensive DPAs with all service providers that process personal data on our behalf.
  • Adequacy Decisions: We rely on adequacy decisions by the European Commission where available (e.g., transfers to countries deemed to provide adequate protection).
  • Supplementary Measures: We implement additional technical and organizational measures to ensure data protection equivalent to GDPR standards, including encryption, access controls, and contractual commitments.
  • Transfer Impact Assessments (TIAs): We conduct TIAs to assess the laws and practices of destination countries and implement appropriate safeguards.

6.2 U.S. Data Protection Framework For transfers to the United States, we comply with applicable U.S. privacy laws, including CCPA, and implement robust security measures. We monitor developments in EU-U.S. data transfer frameworks and will comply with any applicable certification mechanisms.

6.3 Consent to International Transfers By using our Services, you acknowledge and consent to the transfer of your information to the United States and other countries where we or our service providers operate. If you do not consent to such transfers, please do not use our Services.

7. Cookies and Tracking Technologies

7.1 What Are Cookies? Cookies are small text files stored on your device (computer, tablet, smartphone) when you visit our website. We use cookies and similar tracking technologies (pixels, beacons, local storage) to enhance your experience, analyze usage, provide personalized content, and deliver relevant advertising.

7.2 Types of Cookies We Use

We use the following categories of cookies:

  • Strictly Necessary Cookies (GDPR: Legitimate Interest): Essential for the website to function properly. These cookies enable core functionality such as authentication, security features, and access to secure areas. Without these cookies, services you have requested cannot be provided. These cookies do not require consent under GDPR.
  • Performance/Analytics Cookies (GDPR: Consent Required): Help us understand how visitors use our website by collecting information about pages visited, time spent, errors encountered, and other usage metrics. We use Google Analytics and similar tools. These cookies are anonymized where possible and require your consent.
  • Functional Cookies (GDPR: Consent Required): Remember your preferences and settings, such as language selection, region, font size, and other customization options. These cookies enhance your user experience but are not strictly necessary. They require your consent.
  • Marketing/Targeting Cookies (GDPR: Consent Required): Used to deliver relevant advertisements, track campaign effectiveness, and limit the number of times you see an ad. These cookies may be set by us or third-party advertising partners. They require your explicit consent and you can opt-out at any time.

7.3 Specific Cookies We Use

The following table lists the specific cookies used on our website:

  • _ga (Google Analytics) Distinguish unique users and calculate visitor statistics2 years (Analytics)
  • _gid (Google Analytics) Distinguish unique users in a 24-hour period24 hours (Analytics)
  • cookie_consent Remember your cookie consent preferences1 year (Necessary)
  • session_id Maintain your authenticated sessionSession (Necessary)

7.4 Your Cookie Choices and Consent Management

You have the right to accept or reject cookies. You can manage your cookie preferences through:

  • Our Cookie Consent Banner: When you first visit our website, a banner appears allowing you to accept or customize cookie settings. You can change these preferences at any time by clicking the cookie settings link in our footer.
  • Browser Settings: Most browsers allow you to view, delete, and block cookies. Access your browser's help section for instructions. Common browsers: Chrome (chrome://settings/cookies), Firefox (about:preferences#privacy), Safari (Preferences > Privacy), Edge (edge://settings/privacy).
  • Third-Party Opt-Outs: For third-party advertising cookies, visit the Digital Advertising Alliance (DAA) opt-out page: www.aboutads.info/choices or the Network Advertising Initiative (NAI) opt-out page: www.networkadvertising.org/choices.
  • Google Analytics Opt-Out: Install the Google Analytics Opt-Out Browser Add-on: tools.google.com/dlpage/gaoptout

Note: Blocking or deleting certain cookies may limit your ability to use specific features of our Services. Strictly necessary cookies cannot be disabled as they are essential for the website to function.

7.5 Do Not Track (DNT) Signals Some browsers include a "Do Not Track" (DNT) feature that sends a signal to websites requesting not to be tracked. Currently, there is no industry-wide standard for recognizing and implementing DNT signals. Our Services do not respond to browser DNT signals at this time. However, you can use the cookie management options described above to control tracking. We will update this policy if an industry standard for DNT signals is established.

8. Data Security

We implement appropriate technical and organizational security measures designed to protect your information from unauthorized access, disclosure, alteration, destruction, or loss. Our security measures include:

8.1 Technical Security Measures

  • Encryption of data in transit using HTTPS/TLS and industry-standard security controls.
  • Access controls and authentication safeguards, including support for multi-factor authentication (MFA).
  • Rate limiting and automated abuse-prevention measures on public-facing endpoints and forms.
  • Server-side validation of submitted data and verification of the integrity of payment and webhook events.
  • Role-based access restrictions that limit administrative functions to authorized personnel.
  • Private, access-controlled storage for sensitive documents.
  • Logging and monitoring of key system events to help detect and respond to potential security incidents.

8.2 Organizational and Operational Measures

  • Restricting sensitive capabilities by default to reduce our attack surface.
  • Enforcing the principle of least privilege for administrative and internal access.
  • Data minimization and purpose limitation—collecting only the data necessary to provide the requested service.
  • Secure management of credentials and secrets, kept separate from application code.

8.3 Data Breach Notification (GDPR Article 33-34, CCPA)

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority (for GDPR breaches) within 72 hours of becoming aware of the breach, where feasible.
  • Notify affected individuals without undue delay if the breach is likely to result in high risk to their rights and freedoms.
  • Provide information about the nature of the breach, categories and approximate number of affected individuals, likely consequences, and measures taken or proposed to address the breach.
  • Document all breaches, including facts, effects, and remedial actions taken, in our internal breach register.
  • For California residents, notify affected individuals in accordance with California Civil Code Section 1798.82.

8.4 Security Limitations While we implement the measures above, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security. You are responsible for safeguarding your account credentials, using strong passwords, enabling multi-factor authentication where available, and promptly notifying us of any suspected unauthorized access or security concerns.

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Our retention periods are based on:

9.1 Retention Criteria

  • The nature and sensitivity of the personal data
  • The purposes for which we collected and process the data
  • Whether we have an ongoing relationship with you (active account)
  • Legal, regulatory, tax, accounting, or reporting requirements
  • Whether we need the data for legal claims, compliance, or auditing purposes
  • Guidance from relevant data protection authorities
  • Your requests to delete your data (subject to legal obligations)

9.2 Specific Retention Periods

We apply the following retention periods to different categories of data:

  • Account Data: Retained for the duration of your active account plus 90 days after account closure (to allow for account reactivation). After this period, data is anonymized or deleted.
  • Assessment Reports: Retained for 7 years after service delivery to comply with professional liability and legal requirements. Reports may be retained longer with your consent for longitudinal security analysis.
  • Financial Records: Retained for 7 years to comply with tax, accounting, and audit requirements.
  • Marketing Communications: Retained until you opt-out or withdraw consent, then deleted within 30 days.
  • Support Tickets: Retained for 3 years for quality assurance and training purposes.
  • Analytics and Log Data: Retained for 26 months (Google Analytics default) or anonymized sooner.
  • Security Incident Records: Retained for 7 years for legal and compliance purposes.
  • Backup Copies: Retained for up to 90 days in encrypted backups, then permanently deleted.

9.3 Secure Deletion When we no longer need your information, we securely delete or anonymize it in accordance with industry best practices. Deletion methods include secure overwriting, cryptographic erasure, and physical destruction of media. We maintain records of deletion activities for audit purposes. Please note that deletion from backups may take up to 90 days due to our backup retention schedule.

10. Your Privacy Rights

Depending on your location and applicable laws (GDPR, CCPA, or other privacy laws), you have specific rights regarding your personal information:

10.1 General Privacy Rights (All Users)

All users, regardless of location, have the following rights:

  • Right to be Informed: You have the right to clear, transparent information about how we collect, use, and share your personal information (provided in this Privacy Policy).
  • Right to Access: You have the right to request access to the personal information we hold about you, including details about what data we have, how we use it, and with whom we share it.
  • Right to Correction/Rectification: You have the right to request correction of inaccurate or incomplete personal information we hold about you.
  • Right to Deletion/Erasure: You have the right to request deletion of your personal information, subject to certain legal exceptions (e.g., legal obligations, active legal claims).
  • Right to Opt-Out of Marketing: You have the right to opt-out of receiving marketing communications from us at any time by clicking "Unsubscribe" in emails or contacting us.

10.2 GDPR Rights (EEA, UK, Switzerland Residents)

If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., CSV, JSON) and transmit it to another controller without hindrance from us, where technically feasible.
  • Right to Object (Article 21): You have the right to object to processing based on legitimate interests (Article 6(1)(f)), direct marketing (including profiling), and processing for scientific/historical research or statistical purposes. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests or we need the data for legal claims.
  • Right to Restriction of Processing (Article 18): You have the right to request restriction of processing in certain circumstances: you contest the accuracy of the data; processing is unlawful but you oppose deletion; we no longer need the data but you need it for legal claims; you have objected to processing and await verification of legitimate grounds.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
  • Right Not to Be Subject to Automated Decision-Making (Article 22): You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. You may request human intervention, express your point of view, and contest automated decisions.
  • Right to Lodge a Complaint (Article 77): You have the right to lodge a complaint with your local supervisory authority (data protection authority) if you believe we have violated GDPR. Contact information for EU supervisory authorities: https://edpb.europa.eu/about-edpb/board/members_en. UK Information Commissioner's Office (ICO): https://ico.org.uk/. Swiss Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch/.

10.3 CCPA Rights (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know (CCPA Section 1798.100): You have the right to request information about the personal information we have collected about you in the preceding calendar year. This information includes: categories of personal information collected; categories of sources; business or commercial purposes for collection; categories of third parties with whom we share personal information; specific pieces of personal information collected.
  • Right to Delete (CCPA Section 1798.105): You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, completing transactions, security purposes, internal uses, free speech, research).
  • Right to Opt-Out of Sale (CCPA Section 1798.120): You have the right to opt-out of the "sale" of your personal information. We DO NOT sell personal information and have not sold personal information in the preceding 12 months. We display a "Do Not Sell My Personal Information" link in our footer for transparency.
  • Right to Non-Discrimination (CCPA Section 1798.125): You have the right not to receive discriminatory treatment for exercising your CCPA rights. We will not: deny goods or services; charge different prices or rates; provide a different level of service or quality; suggest you will receive a different price or level of service. However, we may offer financial incentives for the collection or sale of personal information (we do not currently offer such incentives).
  • Right to Correct (CPRA Section 1798.106): You have the right to request correction of inaccurate personal information we maintain about you.
  • Right to Limit Use of Sensitive Personal Information (CPRA Section 1798.121): If we use sensitive personal information (e.g., government-issued IDs, precise geolocation) for purposes other than those specified in CPRA Section 1798.121(a), you have the right to limit such use. We will only use sensitive information for permitted purposes or with your explicit consent.
  • Shine the Light Law (California Civil Code Section 1798.83): California residents may request information about personal information disclosed to third parties for direct marketing purposes in the preceding calendar year. We do not share personal information with third parties for their direct marketing purposes without your explicit consent.

You may designate an authorized agent to submit CCPA requests on your behalf. The authorized agent must provide written authorization signed by you and we may require verification of your identity before processing the request.

10.4 How to Exercise Your Rights

To exercise any of your privacy rights, please use one of the following methods:

  • Email: legal@corecyber.io with the subject line "Privacy Rights Request" or "CCPA Request" or "GDPR Request"
  • Web Form: Visit our Privacy Request Form at corecyber.io/privacy-request (if available)
  • Mail: Covenant Security Solutions International, Attn: Privacy Team, Sheridan, Wyoming, United States

Information Required:

  • Your full name and email address associated with your account
  • Description of your request (e.g., "Request for Access," "Request for Deletion")
  • Proof of identity (we may require government-issued ID for certain requests)
  • If using an authorized agent, provide written authorization

We will respond to your request within the timeframes required by applicable law: GDPR: 1 month (extendable by 2 months for complex requests); CCPA: 45 days (extendable by 45 days with notice). We may need to verify your identity before processing your request to protect your privacy and security. We will acknowledge your request within 10 business days and provide updates on the status. There is no fee for exercising your rights, unless your request is manifestly unfounded, excessive, or repetitive.

11. Children's Privacy

Our Services are not intended for individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at legal@corecyber.io with the subject line "Child Privacy Concern." We will take prompt steps to investigate and delete such information from our systems within 30 days.

We implement age verification measures where appropriate and will refuse service to individuals we know to be under the age of 18. If we learn that we have collected personal information from a child under 18, we will delete that information as quickly as possible and notify the parent or guardian if contact information is available.

12. Third-Party Links and Services

Our Services may contain links to third-party websites, applications, plugins, or services that are not operated by us (e.g., social media platforms, partner websites, payment processors, identity verification services). This Privacy Policy does not apply to third-party websites or services, even if accessed through our Services.

We encourage you to review the privacy policies and terms of service of any third-party sites or services before providing your personal information. We are not responsible for the privacy practices, content, or security of third-party websites or services. Third-party integrations may collect information independently, and their use of your information is governed by their own privacy policies.

When you interact with our social media pages or share content through social media platforms, your interactions are governed by the privacy policies of those platforms (e.g., LinkedIn, Facebook, Twitter). We may receive limited information from these platforms in accordance with your platform privacy settings.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. Material changes will be communicated as follows:

  • Update the "Last Updated" date at the top of this Privacy Policy
  • Notify you by email to the address associated with your account (if you have provided your email address)
  • Post a prominent notice on our website homepage or through a banner notification
  • For material changes affecting GDPR rights, provide notice at least 30 days before the changes take effect
  • For material changes affecting CCPA rights, provide notice in accordance with California law
  • Obtain your explicit consent if required by applicable law (e.g., for new uses of sensitive personal information)

Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using our Services and may request deletion of your account and data. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

We maintain an archive of previous versions of this Privacy Policy, which is available upon request to legal@corecyber.io.

14. Jurisdiction and Governing Law

This Privacy Policy and any disputes arising from or related to your use of our Services or the processing of your personal information shall be governed by and construed in accordance with the laws of the State of Wyoming, United States, without regard to its conflict of law provisions, except where GDPR or CCPA apply, in which case those laws shall govern to the extent they provide greater protection to your rights.

The exclusive jurisdiction and venue for any disputes shall be the state or federal courts located in Sheridan, Wyoming, United States. However, both parties agree that any disputes shall be resolved through binding arbitration as set forth in Section 15, except as otherwise provided by applicable law or where arbitration is prohibited (e.g., certain GDPR rights).

For individuals in the EEA, UK, or Switzerland, you may also have the right to lodge a complaint with your local supervisory authority and bring proceedings in the courts of your EU Member State of residence.

15. Arbitration Agreement and Dispute Resolution

You and Covenant Security Solutions International agree that any dispute, claim, or controversy arising out of or relating to these Terms or your use of our Services shall be resolved through binding arbitration rather than in court, except as provided in Section 12.

PLEASE READ THIS SECTION CAREFULLY. IT AFFECTS YOUR LEGAL RIGHTS, INCLUDING YOUR RIGHT TO FILE A LAWSUIT IN COURT AND YOUR RIGHT TO A JURY TRIAL. THIS SECTION DOES NOT APPLY TO RESIDENTS OF THE EEA, UK, OR SWITZERLAND FOR GDPR-RELATED DISPUTES.

15.1 Arbitration Rules Arbitration shall be conducted in accordance with the Consumer Arbitration Rules of the American Arbitration Association (AAA) in effect at the time of the dispute. The arbitration shall take place in Sheridan, Wyoming, or remotely via video conference if mutually agreed. Each party shall bear its own costs and attorneys' fees unless the arbitrator awards them to the prevailing party. The arbitrator's decision shall be final and binding and may be entered as a judgment in any court of competent jurisdiction.

15.2 Exceptions to Arbitration Either party may bring claims in small claims court if the claim qualifies for small claims court jurisdiction. Additionally, either party may seek injunctive or equitable relief in court to prevent the actual or threatened infringement, misappropriation, or violation of intellectual property rights or to protect confidential information.

15.3 Class Action Waiver YOU AND THE COMPANY AGREE THAT EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY AND NOT AS A CLASS MEMBER OR REPRESENTATIVE IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING, INCLUDING CLASS ARBITRATIONS. Unless both parties agree otherwise in writing, the arbitrator may not consolidate more than one person's claims and may not otherwise preside over any form of representative or class proceeding. This class action waiver does not apply to residents of jurisdictions where such waivers are prohibited by law.

15.4 Opt-Out of Arbitration You may opt-out of this arbitration agreement by sending written notice to legal@corecyber.io within 30 days of first accepting this Privacy Policy. Your notice must include your name, address, email, and a clear statement that you wish to opt out of the arbitration agreement. If you opt out, you and CoreCyber agree to resolve disputes through the courts as specified in Section 14.

16. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us using the methods below. We are committed to resolving your inquiries promptly and transparently.

Company Name: Covenant Security Solutions International

Service Name: CoreCyber

Address: Sheridan, Wyoming, United States

General Inquiries: legal@corecyber.io

Data Protection Officer: legal@corecyber.io

GDPR-Related Inquiries (EEA, UK, Switzerland):

Email: legal@corecyber.io with subject "GDPR Inquiry"

EEA/UK/CH Representative: Covenant Security Solutions Intl., 30 N. Gould St. STE 9374, Sheridan Wyoming USA, Email: legal@corecyber.io

CCPA-Related Inquiries (California Residents):

Email: legal@corecyber.io with subject "CCPA Request" or use our toll-free number: 1-800-XXX-XXXX (to be implemented)

Security and Data Breach Inquiries:

Email: legal@corecyber.io

We aim to respond to all privacy inquiries within 10 business days. For formal data subject access requests (GDPR/CCPA), we will respond within the legally required timeframes (30-45 days).

Regional Annex A — European Economic Area, United Kingdom & Switzerland (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, this Annex supplements the Policy. We process your personal data under the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection (FADP).

Controller & EU/UK representative: Covenant Security Solutions International is the controller. Our representative for these purposes is Covenant Security Solutions Intl., 30 N. Gould St. STE 9374, Sheridan, Wyoming, USA — legal@corecyber.io.

Legal bases: We rely on consent, performance of a contract, legal obligation, vital interests, and legitimate interests (Article 6), as detailed in Section 4.

Your rights: Access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions (Articles 15–22), plus the right to withdraw consent at any time.

International transfers: Transfers outside the EEA/UK/Switzerland rely on the EU Standard Contractual Clauses, the UK IDTA/Addendum, and the Swiss-adapted clauses, with supplementary measures and transfer impact assessments (Section 6).

Complaints: You may lodge a complaint with your local supervisory authority — in the EEA via edpb.europa.eu, in the UK with the ICO (ico.org.uk), and in Switzerland with the FDPIC (edoeb.admin.ch).

Regional Annex B — United States (CCPA/CPRA & U.S. State Privacy Laws)

If you are a resident of a U.S. state with a comprehensive privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas, Oregon and Montana — this Annex supplements the Policy.

Your rights: To know and access, correct, delete, and obtain a portable copy of your personal information; to opt out of the sale or sharing of personal information and of targeted advertising; and to limit the use of sensitive personal information.

No sale of data: We do not sell your personal information, and we have not done so in the preceding 12 months.

Sensitive information: We use government-ID and similar sensitive data only for the limited purposes permitted by law, such as identity verification and fraud prevention.

Non-discrimination: We will not discriminate against you for exercising your privacy rights.

How to exercise & appeal: Email legal@corecyber.io with the subject "US Privacy Request." You may use an authorized agent; we verify identity and respond within the statutory timeframe (generally 45 days). Where state law provides an appeal (e.g., Virginia, Colorado, Connecticut), you may appeal a refusal by replying to our decision, and may contact your state Attorney General.

Regional Annex C — Brazil (LGPD) & Latin America

If you are located in Brazil, this Annex applies the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018). For other Latin American countries — including Mexico (LFPDPPP), Argentina (Law 25.326), Colombia (Law 1581/2012), Chile (Law 21.719, in force from December 2026, replacing Law 19.628), Peru and Uruguay — we honor equivalent rights under applicable local law.

Legal bases: We process personal data on the LGPD legal bases in Article 7 (including consent, performance of a contract, legal obligation, and legitimate interests), as detailed in Section 4.

Your rights (LGPD Art. 18): Confirmation of processing, access, correction, anonymization or deletion, portability, information about data sharing, and revocation of consent.

DPO / Encarregado: You may contact our data protection officer at legal@corecyber.io for any LGPD request or question.

International transfers: Cross-border transfers rely on appropriate safeguards (such as standard contractual clauses) consistent with ANPD guidance.

Authority: In Brazil you may petition the Autoridade Nacional de Proteção de Dados (ANPD, gov.br/anpd). Residents of other Latin American countries may contact their national data-protection authority.

Regional Annex D — Africa (South Africa POPIA, Nigeria NDPA, Kenya DPA)

If you are located in South Africa, Nigeria, or Kenya, this Annex applies your country's data-protection law in addition to the Policy.

South Africa (POPIA): We process personal information in line with the eight conditions for lawful processing under the Protection of Personal Information Act, 2013. You have rights of access, correction, deletion, and objection, and may complain to the Information Regulator (inforegulator.org.za). Our Information Officer is reachable at legal@corecyber.io.

Nigeria (NDPA 2023): We process personal data consistent with the Nigeria Data Protection Act, 2023. You have rights of access, rectification, erasure, restriction, portability, and objection, and may complain to the Nigeria Data Protection Commission (ndpc.gov.ng).

Kenya (DPA 2019): We process personal data consistent with the Kenya Data Protection Act, 2019. You have rights of access, correction, deletion, and objection, and may complain to the Office of the Data Protection Commissioner (odpc.go.ke).

International transfers: Where we transfer personal information outside your country, we apply appropriate safeguards and rely on your consent or another lawful basis as your local law requires.

Regional Annex E — India (Digital Personal Data Protection Act, 2023)

If you are located in India, this Annex applies the Digital Personal Data Protection Act, 2023 (DPDP Act) together with the Digital Personal Data Protection Rules, 2025 (notified 14 November 2025), which operationalize the Act on a phased timeline.

Notice & consent: We process your personal data on the basis of your consent or for legitimate uses permitted by the DPDP Act, and give notice of the personal data collected and the purpose of processing.

Your rights: Access to a summary of your personal data and its processing; correction, completion, updating and erasure; grievance redressal; and nomination of another person to exercise your rights in the event of death or incapacity.

Withdrawing consent: You may withdraw consent at any time, as easily as it was given, by contacting legal@corecyber.io.

Grievance & Board: Submit grievances to legal@corecyber.io; if unresolved, you may approach the Data Protection Board of India.

Children: We do not process children's personal data in a manner likely to cause harm, and we obtain verifiable parental consent where the DPDP Act requires it.

17. Acknowledgment and Acceptance

BY USING OUR SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY THIS PRIVACY POLICY. YOU FURTHER ACKNOWLEDGE THAT YOU UNDERSTAND YOUR PRIVACY RIGHTS UNDER GDPR (IF APPLICABLE), CCPA (IF APPLICABLE), AND OTHER APPLICABLE PRIVACY LAWS.

If you are located in a jurisdiction that requires explicit consent for certain data processing activities (e.g., marketing communications, non-essential cookies, sensitive personal information), you will be presented with consent mechanisms within our Services. You may withdraw your consent at any time as described in this Privacy Policy.

This Privacy Policy was last updated on November 29, 2025. We reserve the right to modify this Privacy Policy at any time in accordance with applicable laws and will notify you of material changes as described in Section 13.