Privacy Policy
Last updated: June 2025
01Overview
CipherTest, Inc. ("CipherTest", "we") respects your privacy. This policy describes what data we collect through ciphertest.com, how we use it, and the choices you have. It does not cover data handled under an engagement agreement, which is governed by the master services agreement and any mutual NDA in place with your organization.
We operate as a data controller for website data and as a data processor for data shared during paid engagements. If you have questions about this policy, contact privacy@ciphertest.com.
02Data We Collect
Contact form submissions: name, company, email, phone, service of interest, and your message. We use this data to scope and respond to your inquiry.
Newsletter subscriptions: your email address, used only to send the CipherTest research dispatch.
Operational data: standard server logs and analytics that do not identify individuals, such as aggregated page views and approximate region.
Cookies: essential cookies required to operate the site, plus analytics cookies if you accept them in the cookie banner.
03How We Use Data
To respond to assessment inquiries and provide quotes.
To send the newsletter you explicitly subscribed to.
To improve the website through aggregated, de-identified analytics.
We do not sell personal data. We do not use personal data to train external models.
04Legal Bases (GDPR)
We process contact-form data under our legitimate interest in responding to your inquiry and entering into a potential contract.
We process newsletter data on the basis of your consent, which you may withdraw at any time using the unsubscribe link in every dispatch.
05Data Retention
Contact submissions are retained for 24 months after our last correspondence and then deleted.
Newsletter subscriptions are retained until you unsubscribe.
Engagement data retention is governed by your engagement agreement.
06Your Rights
You may request access to, correction of, or deletion of your personal data by emailing privacy@ciphertest.com.
If you are in the European Economic Area or United Kingdom, you have additional rights including the right to object, restrict processing, data portability, and to lodge a complaint with your supervisory authority.
07Security
We apply industry-standard technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and regular security testing of our own systems.
Questions about this policy? Email contact@ciphertest.com.