BreachForge, a Cyberspartans product

Privacy Policy

Effective date: 5 June 2026 · Version 1.0

This policy explains how Cyber Spartans Limited, trading as Cyberspartans ("we", "us", "our"), collects and uses personal data when you use BreachForge, and the rights you have over that data. It should be read alongside our Terms of Service.

1. Who we are

Cyber Spartans Limited is the data controller for the personal data described here. Registered office: Unit 1, Derwent Business Centre, Clarke Street, Derby DE1 2BU, United Kingdom. Company number 13735278. You can reach us about privacy at [email protected].

2. What this policy covers

This policy covers the BreachForge platform and the account, billing and support around it. BreachForge is a business tool sold to organisations, so most of the data we hold relates to the people who administer an account rather than to consumers.

3. The data we collect

CategoryWhat it includes
Account dataYour name and work email, your organisation, and the login credentials used to access the service.
Environment dataThe estate, crown jewels, controls and other configuration you enter to model your environment. This is information about your organisation. It should not contain personal data, and we ask that you do not enter personal data into it.
Billing dataSubscription status and the identifiers our payment processor returns. We do not see or store full card details; those are handled by the payment processor.
Technical dataSession cookies that keep you signed in, and standard server logs such as IP address, browser type and request times, used to run and secure the service.

4. How we use your data, and our lawful basis

5. Cookies and browser storage

We use a small number of strictly necessary cookies to keep you signed in and to operate the gate that protects the application pages. These are essential to the service and are not used for advertising or cross site tracking. We set no analytics, advertising or cross site tracking cookies of any kind. There is no Google Analytics, no advertising pixel and no tracker of any sort on this site. One third party can set a cookie here and we would rather name it than claim otherwise: the booking widget on our home and pricing pages is provided by Calendly, and it loads only on those two pages. It is described in section 6.

CookiePurposeLifetime
bf_atYour signed in session. Sent with each request so the application knows who you are.Short lived, refreshed while you are active.
bf_rtRenews your session so you are not signed out mid task.Longer lived, cleared when you sign out.
bf_envIdentifies which of your saved environments you are working in.Cleared when you sign out.

All three are set with HttpOnly, Secure and SameSite=Lax, and carry no domain attribute, so they are host only and cannot be read by page scripts or sent to another site.

Separately from cookies, a few small preferences are stored by your own browser and are never transmitted to us. They hold no personal data and exist only so the site behaves the way you left it.

Stored itemWhat it holdsWhere and how long
bf-themeWhether you chose the light or dark appearance.Local storage, kept until you clear your browser data.
bf-railWhether the side navigation is expanded or collapsed.Local storage, kept until you clear your browser data.
bf_nextThe page you were heading to before signing in, so you land there afterwards.Session storage, cleared when you close the tab.

Each is written only in response to something you did: choosing a theme, collapsing the navigation, or following a link that required signing in. Clearing your browser storage removes them, and the only effect is that those preferences reset.

5a. Ed, our assistant

Ed is the assistant on our public pages. He is worth describing plainly because people reasonably assume a chat window is sending what they type somewhere.

Ed has no artificial intelligence model behind him and makes no network request. He has no text box: every answer is a fixed piece of text we wrote, and clicking a button shows the next one. Nothing you do with Ed is transmitted, recorded, logged or seen by us, and no third party is contacted. He stores nothing in your browser either: no cookie, no local storage, no session storage, nothing at all. Closing him closes the panel and leaves the small button in the corner, and that is the whole of it.

The signed in part of the product does include an assistant that uses an AI model to explain your own result. That one is described in section 6 and is only available to signed in customers.

6. Who we share data with

We do not sell your data. We use a small set of trusted service providers who process data on our behalf, under contract, only to deliver the service:

ProviderPurpose
CloudflareHosting, content delivery and the database that stores account and configuration data.
SupabaseAuthentication and identity, used to sign you in.
CalendlyThe booking widget on our home and pricing pages, used only if you choose to book a conversation. Loading those two pages causes your browser to contact Calendly, which may set its own cookies and will see your address and browser details. No other page on this site loads it, and nothing is sent to Calendly unless you interact with the widget.
StripePayment processing and subscription billing.
ResendSending transactional email such as account and service messages.

We may also disclose data where the law requires it, or to protect our rights, property or safety.

7. International transfers

We aim to keep account and configuration data in the United Kingdom or the European Union. Some of our providers may process data outside the UK. Where that happens, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement or the UK addendum to the European Commission standard contractual clauses.

8. How long we keep data

We keep account and configuration data for as long as your account is active, and for a reasonable period afterwards to meet legal, accounting and security needs. We then delete or anonymise it. You can ask us to delete your account at any time.

9. How we protect data

Access to the application requires a login, secrets and keys are held in encrypted storage and never in our code, and data is held with established providers that maintain their own security controls. No service can be completely secure, but we take reasonable steps to protect your data.

10. Your rights

Under UK data protection law you have the right to access your data, to have it corrected or deleted, to restrict or object to how we use it, to data portability, and to withdraw consent where we rely on it. To exercise any of these, contact us at [email protected]. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, although we would welcome the chance to address your concern first.

11. Children

BreachForge is a business tool and is not intended for or directed at children. We do not knowingly collect data from anyone under 18.

12. Changes to this policy

We may update this policy from time to time. We will change the effective date above and, for material changes, let account holders know.

13. Contact

Cyber Spartans Limited, trading as Cyberspartans. Registered office: Unit 1, Derwent Business Centre, Clarke Street, Derby DE1 2BU, United Kingdom. Company number 13735278. Privacy questions: [email protected].

BreachForge, a Cyberspartans product. This policy applies to personal data we process in connection with the platform.

BreachForge is built and maintained by Saleem Yousaf, Cloud Security Architect and Director at Cyber Spartans Ltd.

saleemyousaf.co.uk cyberspartans.co.uk LinkedIn GitHub