This policy explains how Cyber Spartans Limited, trading as Cyberspartans ("we", "us", "our"), collects and uses personal data when you use BreachForge, and the rights you have over that data. It should be read alongside our Terms of Service.
Cyber Spartans Limited is the data controller for the personal data described here. Registered office: Unit 1, Derwent Business Centre, Clarke Street, Derby DE1 2BU, United Kingdom. Company number 13735278. You can reach us about privacy at [email protected].
This policy covers the BreachForge platform and the account, billing and support around it. BreachForge is a business tool sold to organisations, so most of the data we hold relates to the people who administer an account rather than to consumers.
| Category | What it includes |
|---|---|
| Account data | Your name and work email, your organisation, and the login credentials used to access the service. |
| Environment data | The estate, crown jewels, controls and other configuration you enter to model your environment. This is information about your organisation. It should not contain personal data, and we ask that you do not enter personal data into it. |
| Billing data | Subscription status and the identifiers our payment processor returns. We do not see or store full card details; those are handled by the payment processor. |
| Technical data | Session cookies that keep you signed in, and standard server logs such as IP address, browser type and request times, used to run and secure the service. |
We use a small number of strictly necessary cookies to keep you signed in and to operate the gate that protects the application pages. These are essential to the service and are not used for advertising or cross site tracking. We set no analytics, advertising or cross site tracking cookies of any kind. There is no Google Analytics, no advertising pixel and no tracker of any sort on this site. One third party can set a cookie here and we would rather name it than claim otherwise: the booking widget on our home and pricing pages is provided by Calendly, and it loads only on those two pages. It is described in section 6.
| Cookie | Purpose | Lifetime |
|---|---|---|
bf_at | Your signed in session. Sent with each request so the application knows who you are. | Short lived, refreshed while you are active. |
bf_rt | Renews your session so you are not signed out mid task. | Longer lived, cleared when you sign out. |
bf_env | Identifies which of your saved environments you are working in. | Cleared when you sign out. |
All three are set with HttpOnly, Secure and SameSite=Lax, and carry no domain attribute, so they are host only and cannot be read by page scripts or sent to another site.
Separately from cookies, a few small preferences are stored by your own browser and are never transmitted to us. They hold no personal data and exist only so the site behaves the way you left it.
| Stored item | What it holds | Where and how long |
|---|---|---|
bf-theme | Whether you chose the light or dark appearance. | Local storage, kept until you clear your browser data. |
bf-rail | Whether the side navigation is expanded or collapsed. | Local storage, kept until you clear your browser data. |
bf_next | The page you were heading to before signing in, so you land there afterwards. | Session storage, cleared when you close the tab. |
Each is written only in response to something you did: choosing a theme, collapsing the navigation, or following a link that required signing in. Clearing your browser storage removes them, and the only effect is that those preferences reset.
Ed is the assistant on our public pages. He is worth describing plainly because people reasonably assume a chat window is sending what they type somewhere.
Ed has no artificial intelligence model behind him and makes no network request. He has no text box: every answer is a fixed piece of text we wrote, and clicking a button shows the next one. Nothing you do with Ed is transmitted, recorded, logged or seen by us, and no third party is contacted. He stores nothing in your browser either: no cookie, no local storage, no session storage, nothing at all. Closing him closes the panel and leaves the small button in the corner, and that is the whole of it.
The signed in part of the product does include an assistant that uses an AI model to explain your own result. That one is described in section 6 and is only available to signed in customers.
We do not sell your data. We use a small set of trusted service providers who process data on our behalf, under contract, only to deliver the service:
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, content delivery and the database that stores account and configuration data. |
| Supabase | Authentication and identity, used to sign you in. |
| Calendly | The booking widget on our home and pricing pages, used only if you choose to book a conversation. Loading those two pages causes your browser to contact Calendly, which may set its own cookies and will see your address and browser details. No other page on this site loads it, and nothing is sent to Calendly unless you interact with the widget. |
| Stripe | Payment processing and subscription billing. |
| Resend | Sending transactional email such as account and service messages. |
We may also disclose data where the law requires it, or to protect our rights, property or safety.
We aim to keep account and configuration data in the United Kingdom or the European Union. Some of our providers may process data outside the UK. Where that happens, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement or the UK addendum to the European Commission standard contractual clauses.
We keep account and configuration data for as long as your account is active, and for a reasonable period afterwards to meet legal, accounting and security needs. We then delete or anonymise it. You can ask us to delete your account at any time.
Access to the application requires a login, secrets and keys are held in encrypted storage and never in our code, and data is held with established providers that maintain their own security controls. No service can be completely secure, but we take reasonable steps to protect your data.
Under UK data protection law you have the right to access your data, to have it corrected or deleted, to restrict or object to how we use it, to data portability, and to withdraw consent where we rely on it. To exercise any of these, contact us at [email protected]. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, although we would welcome the chance to address your concern first.
BreachForge is a business tool and is not intended for or directed at children. We do not knowingly collect data from anyone under 18.
We may update this policy from time to time. We will change the effective date above and, for material changes, let account holders know.
Cyber Spartans Limited, trading as Cyberspartans. Registered office: Unit 1, Derwent Business Centre, Clarke Street, Derby DE1 2BU, United Kingdom. Company number 13735278. Privacy questions: [email protected].
BreachForge is built and maintained by Saleem Yousaf, Cloud Security Architect and Director at Cyber Spartans Ltd.