The Cyber Empowerment Hub

The Cyber Empowerment Hub Ltd

Privacy notice

What we collect, why we collect it, how long we keep it, and what we will never do with it. If anything here is unclear, ask us and a person will answer in plain words.

Who we are

We are The Cyber Empowerment Hub Ltd, registered in England and Wales, company number 15572204. Our registered office is 82 James Carter Road, Mildenhall, IP28 7DE. You can check our record at Companies House. For anything in this notice, write to hello@cyberempowermenthub.co.uk.

We are the data controller for everything described below. That is the legal way of saying the responsibility for looking after this data is ours, and we accept it.

What we collect

Five things, and that is the whole list.

  1. 01

    The addresses on your plan

    On an individual plan, that is your email address. On a business plan, it is every address you choose to add. We use them to send the practice emails, which is the whole service.

  2. 02

    Our record of your subscription

    Payment happens on Stripe's own checkout page, never on this site, and your card and billing details stay with Stripe. We never see your card number. All we keep is your email address, which plan you chose, how many seats, and Stripe's reference numbers for your subscription, because without those we cannot tell who has paid.

  3. 03

    What the practice shows

    Which practice emails went to each address on the plan and what happened to them. That record is what the training reports are made of; without it there is nothing to learn from.

  4. 04

    Anything you send us

    If you email us, we keep the correspondence for as long as it is useful, then delete it.

  5. 05

    Emails you forward to the scam checker

    If you forward a suspicious email to our scam checker, we have to receive the email to be able to check it. It is stored while we look at it and deleted automatically 30 days later. We do not read it for any purpose other than answering you, we never open attachments, and we do not use it to train anything.

    We keep a separate short record of the forwards we handled: your address, the time, and what we decided. That record holds no part of the message. No subject, no wording, no sender. It is what tells us the service is working, and it is deleted on the same 30 day clock, so it never outlives the email it describes.

What we never collect

No passwords, ever. Our practice pages only teach. They never ask for credentials, card details or anything else worth stealing, and they never capture what you type. That is commitment 02 of our pledge.

No analytics and no tracking on this site. We do not know you visited unless you tell us. The cookies section below has the detail.

And we never sell or rent personal data to anyone, at any price. The product here is the practice, and it costs £2.

Why we're allowed to

UK GDPR asks every business to name its lawful basis for handling personal data. Ours are these. We handle the email addresses on your plan and our record of your subscription because that is the contract you pay us for. We keep that record after you leave because tax law obliges us to. And we hold what we need to keep the service safe, answer complaints and defend ourselves if something goes wrong, because we have a legitimate interest in still existing next year.

Adding other people

On a business plan you can put other people's addresses on the plan. Only add someone who knows about the training and has agreed to it. Consent first is commitment 01 of our pledge, and it is a condition of the terms, not a suggestion.

If someone has added you to a plan, everything in this notice applies to you exactly as it does to the person paying. Email hello@cyberempowermenthub.co.uk at any time to see what we hold about you or to come off the plan, and we will do it without going through the account holder first.

Where it lives

Four companies process data on our behalf, each under contract, and none of them allowed to use your data for their own purposes.

Stripe takes the payments. Stripe is an American company, and where your data reaches the United States it travels under the UK's approved safeguards for international transfers. Their own notice is at stripe.com/gb/privacy.

Cloudflare hosts this site and holds our record of who has subscribed. Amazon Web Services, in Ireland, runs the platform that sends the practice emails.

Google does two jobs for us. It runs our mailbox, so anything you email us sits there. It also runs the link check in our scam checker: when an email is forwarded to us to be checked, the web addresses inside it go to Google's Web Risk service, one at a time, and Google says whether each one is a known dangerous site. The message itself never goes, and neither does who sent it or who received it. One honest caveat: a scam link sometimes carries the target's email address inside the link itself, and where that happens the address travels with it. Google's notice is at policies.google.com/privacy.

One more, not switched on yet. The scam checker can also send a forwarded email to Anthropic to have the wording read, which catches the persuasion a link check cannot see. That is switched off today, so nothing has ever been sent, and every answer so far comes from our own checks alone. We are naming it here in advance rather than quietly turning it on later. When we do switch it on, the message content goes with it, it is not used to train their models, and we will say so on this page with the date. Their notice is at anthropic.com/legal/privacy.

How long we keep it

Billing records stay for up to six years after your last payment, because tax law says so. The addresses on your plan and the practice results stay while your plan is active and are deleted within 90 days of cancellation. Correspondence stays for as long as it is useful.

Anything you forward to the scam checker goes on a 30 day clock. The email itself and our record of having checked it are both deleted automatically once the 30 days are up, whether you ask or not, and whether or not you are still a customer.

If you want something gone sooner, ask. Unless a law obliges us to keep it, we delete it.

Cookies

This site sets no cookies.

No analytics, no trackers, no fingerprinting, and no cookie banner, because there is nothing to consent to. We checked the site line by line before writing that sentence.

Two honest caveats. If you subscribe, payment happens on Stripe's own checkout page, and Stripe sets the cookies it needs to take payment securely. Those live on Stripe's domain, under Stripe's privacy policy, not ours. And Cloudflare, which hosts this site, can set a strictly necessary security cookie of its own if the site comes under attack; it exists to tell humans from bots and identifies nobody.

If we ever add cookies of our own, this section will say so before it happens, and anything that is not strictly necessary will ask your permission first.

Your rights

UK GDPR gives you the right to see the data we hold about you, to correct it, to have it deleted, to restrict or object to what we do with it, and to take a copy somewhere else. To use any of them, email hello@cyberempowermenthub.co.uk. The law gives us a month to answer; we aim for a lot less.

If you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, so we can put it right, but you do not have to.

Changes to this notice

This notice is versioned and dated in the footer below. If we change what we collect or why, the change appears here before it happens, and if it is a change that matters we email everyone subscribed.