Privacy Policy
Protecting your personal data is a priority for us — especially as a cybersecurity company.
Last updated: September 11, 2026
1. Data Controller
CYBERISK LLC, with its principal place of business in Carol Stream, Illinois (USA), is the data controller responsible for the personal data collected through this site. For any questions, contact us at contact@cyberisk.company.
2. Data We Collect
Depending on how you use the site, we may collect:
- Member account: full name, email address, and password (stored as an irreversible hash, never in plain text).
- Contact form: name, email address, subject, and message content.
- Payment information: card details are entered and processed directly by our payment processor, Stripe. CYBERISK LLC never has access to your full card number.
- Browsing data: essential session cookies, IP address, and security logs (WAF console) used to protect against fraudulent activity.
- Member reviews: name, role/title, and testimonial content you voluntarily submit, published after moderation.
3. Purpose of Processing
- Creating and managing your member account and your access to PDF courses and video tutorials.
- Processing your payments and subscriptions through Stripe.
- Responding to inquiries submitted through our contact form.
- Maintaining site security (intrusion detection, fraud prevention).
- Improving our services and educational content.
4. Legal Basis
We process your data based on the performance of our contract with you (access to paid courses and services), your consent (contact form, member reviews), and CYBERISK LLC's legitimate interest in keeping its platform secure.
5. Data Sharing
We never sell your data to third parties. It may be shared with:
- Stripe, for secure payment processing.
- Our hosting and infrastructure providers, who are bound by confidentiality obligations.
- Government authorities, where required by law.
6. Retention Period
Your account data is retained for as long as your account remains active. If you delete your account or it becomes inactive for an extended period, your data is deleted or anonymized within a reasonable timeframe, unless a longer retention period is required by law (e.g., billing records).
7. Security
As a cybersecurity company, we apply rigorous technical safeguards: hashed passwords (BCrypt), encrypted connections, CSRF protection, a web application firewall (WAF), and the principle of least privilege for administrator access.
8. Cookies
This site uses a session cookie that is strictly necessary for member account functionality (authentication) and an anti-CSRF token to secure forms. These essential cookies do not require prior consent and are never used for advertising or third-party tracking purposes.
9. Your Rights
You may request access to, correction of, or deletion of your personal data at any time by contacting us at contact@cyberisk.company. We respond to all requests within a reasonable timeframe.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The date of the most recent update appears at the top of this page.