1. Introduction and Data Controller
This Privacy Policy applies to the consumer applications published by CISOAIA. It currently covers CyRep — a gamified cybersecurity awareness and training application available at cyrep.cisoaia.com that helps individuals build lasting cybersecurity habits through interactive learning, quizzes, and AI-assisted coaching — and will be extended to cover additional CISOAIA consumer apps as they are released, since they share the same account, engine, and data practices.
Data Controller
Reutlingerstrasse 18
8472 Seuzach
Switzerland
Privacy contact: privacy@cisoaia.com
CISOAIA is currently operated by Adrian Pojar as a sole proprietor. A CISOAIA GmbH is being formed; this policy will be updated to name it as the data controller upon its registration in the Swiss commercial register.
EU Representative (GDPR Art. 27): CISOAIA is established in Switzerland, which is outside the EU/EEA. As a controller that offers services to individuals in the European Union, we have designated the following representative in an EU member state under GDPR Article 27. Data subjects and supervisory authorities in the EU/EEA may contact the representative on all matters relating to the processing of their personal data, in addition to or instead of the controller:
Str. Oborului nr. 2, Bl. 80, Sc. A, ap. 9
315400 Lipova, Jud. Arad
Romania
Contact: eu-representative@cisoaia.com
This designation does not affect your right to take action directly against CISOAIA.
UK Representative (UK GDPR Art. 27): Whether a UK representative is required depends on the extent to which CyRep actively targets UK users. [To be confirmed based on UK market activity before UK launch.]
Applicable law: We are committed to compliance with:
- The Swiss Federal Act on Data Protection (nFADP), effective 1 September 2023;
- The EU General Data Protection Regulation (GDPR), where applicable to users in the European Economic Area (EEA);
- The UK General Data Protection Regulation (UK GDPR), as retained in UK law by the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018, for users habitually resident in the United Kingdom.
Where these frameworks differ, we apply the highest standard of protection.
Swiss–EU adequacy: The European Commission has recognised Switzerland as providing an adequate level of data protection. For EU/EEA users, this means your personal data can be lawfully transferred to CISOAIA in Switzerland without additional safeguards on the basis of that adequacy decision.
This Privacy Policy explains what personal data we collect when you use a CISOAIA consumer app, why we collect it, how we process and protect it, who we share it with, and what rights you have. It applies to CISOAIA's consumer applications — currently CyRep (cyrep.cisoaia.com). It does not cover the CISOAIA website or CISOAIA's compliance-product offerings, which are governed by a separate privacy notice.
2. What Data We Collect and Why
We collect only the data necessary to provide and improve the CyRep service. The categories below describe what we collect, the specific data points involved, and the purpose of each.
2.1 Account Data
When you register for CyRep or sign in using a third-party provider, we collect:
| Data point | Source | Purpose |
|---|---|---|
| Email address | Provided by you or by Apple/Google Sign-In | Account creation, authentication, transactional communications (magic links, notifications) |
| Display name / full name | Provided by you or by Apple/Google Sign-In | Personalising your in-app experience |
| Authentication method | Determined at sign-up (email, Apple, Google) | Managing your login method |
| Profile settings: role, preferred language, daily learning goal | Set by you | Customising the learning experience to your needs |
If you use Apple Sign-In, Apple may provide a relay email address instead of your real address. We store and use whatever Apple provides. Apple's own privacy policy governs their processing of your data.
If you use Google Sign-In, Google provides your name, email address, and profile picture. Google's own privacy policy governs their processing of your data.
2.2 Learning and Gamification Data
As you use CyRep, we collect data about your learning activity:
| Data point | Purpose |
|---|---|
| Quiz answers and scores | Assessing learning outcomes; personalising content difficulty |
| Module completion status | Tracking your progress through the curriculum |
| Streak count (consecutive learning days) | Supporting daily learning habits; gamification |
| Badges and achievements earned | Recording milestones; gamification |
| XP (experience points) and level | Gamification; motivating continued engagement |
| Virtual shop purchases | Tracking use of virtual currency within the app |
This data is stored in your user profile in our database (Supabase). It is never sold or used for advertising purposes.
2.3 Device and Technical Data
When you access CyRep, our infrastructure automatically collects:
| Data point | Purpose |
|---|---|
| IP address | Security, fraud prevention, rate limiting, geographic access control |
| Browser type and version | Ensuring compatibility; error diagnosis |
| Operating system and device type | Ensuring compatibility; error diagnosis |
| Screen resolution | Responsive design optimisation |
| HTTP request logs (URL, timestamp, status code) | Infrastructure monitoring and security |
2.4 Analytics Data
With your consent (where required), we collect behavioural analytics:
| Data point | Purpose |
|---|---|
| Pages and features visited | Understanding how users navigate the app; product improvement |
| Session duration | Measuring engagement |
| Feature interaction events (e.g., quiz started, badge earned) | Identifying what features are valuable or underused |
| Onboarding completion | Improving the new user experience |
| Device and browser information | Segmenting usage by platform |
Analytics are processed by PostHog on its EU instance (eu.posthog.com). Events are associated with a pseudonymous identifier, not directly with your name or email address. You may opt out at any time; see Section 5.
2.5 Payment Data (Paid Tier Only)
If you subscribe to CyRep's paid tier, payment processing is handled entirely by Stripe. We do not collect or store your payment card number, CVV, or full card details.
We store only:
| Data point | Purpose |
|---|---|
| Subscription status (active, cancelled, lapsed) | Controlling access to paid features |
| Plan type | Displaying correct feature set |
| Stripe customer ID | Linking your CyRep account to your Stripe record for support and billing queries |
Stripe acts as an independent data controller for payment data and is subject to its own privacy policy (available at stripe.com/privacy). We process payment-related personal data jointly with Stripe only to the extent necessary to fulfil your subscription contract.
2.6 Communication Data
If you contact us for support or send feedback, we process:
- Your email address
- The content of your message
- Correspondence history
This data is used solely to respond to your inquiry and is not used for marketing.
2.7 AI Coach Interaction Data
CyRep includes an AI coaching feature. Before you interact with the AI coach for the first time, you will be informed that you are interacting with an AI system, as required by EU AI Act Art. 50 (applicable from August 2026). All AI-generated responses are labelled as AI-generated within the app interface.
When you use the AI coach, your message and relevant learning context — such as your current module, recent quiz performance summary, and your stated learning goal — are sent to the following AI processors to generate a response in real time: OpenAI, L.L.C. (United States) to compute a semantic embedding of your message, DeepL SE (Germany, EU) to translate your message where needed, and Groq, Inc. (United States) to generate the answer.
We take the following steps to minimise risk:
(a) No direct identifiers sent: We do not send your name, email address, or account ID to these AI processors. Only a pseudonymous session context is included in the request.
(b) No model training: We rely on the API terms of OpenAI, DeepL, and Groq, under which data submitted via their APIs is not used to train, fine-tune, or improve their models.
(c) AI labelling: All responses generated by the AI coach are clearly labelled as AI-generated within the app.
(d) Data Protection Impact Assessment: We have conducted a DPIA under GDPR Art. 35 for the AI coach feature, given that it involves systematic processing using new AI technologies. The DPIA concluded that the risks are manageable with the safeguards described in this policy. A summary is available upon request at privacy@cisoaia.com.
AI coach interaction data (your messages and the session context sent to the inference provider) is retained for 90 days from creation, after which it is permanently deleted.
3. Legal Bases for Processing
We process your personal data only where we have a valid legal basis. The table below identifies the basis under GDPR (Article 6) and the equivalent basis under the Swiss nFADP for each processing activity.
| Processing activity | GDPR basis (Art. 6) | Swiss nFADP basis | Details |
|---|---|---|---|
| Account creation and authentication | Art. 6(1)(b) — contract | Necessity for contract performance | Processing is necessary to provide the service you signed up for |
| Delivering learning content, tracking progress, gamification | Art. 6(1)(b) — contract | Necessity for contract performance | Core functionality of the CyRep service |
| Subscription management and billing | Art. 6(1)(b) — contract | Necessity for contract performance | Required to fulfil paid subscription agreements |
| Transactional emails (magic links, account alerts) | Art. 6(1)(b) — contract | Necessity for contract performance | Required to deliver the service (passwordless login) |
| AI coach inference | Art. 6(1)(b) — contract | Necessity for contract performance | The AI coach is a core feature of the service; processing is necessary to deliver the AI response you request. Enhanced transparency is provided in Section 2.7. |
| Security, fraud prevention, abuse detection | Art. 6(1)(f) — legitimate interest | Overriding legitimate interest | We have a legitimate interest in protecting our users and service from abuse; this does not override your fundamental rights |
| Error tracking and service reliability (Sentry) | Art. 6(1)(f) — legitimate interest | Overriding legitimate interest | Balancing assessment: CISOAIA's interest in maintaining application stability and diagnosing errors is genuine and necessary for the functioning of the paid service. Error data is minimised (PII redaction where technically feasible), retained for only 90 days, and is not used for any purpose other than error diagnosis. The impact on users is limited: error logs do not contain behavioural profiles, are not shared with third parties for other purposes, and users would reasonably expect a software provider to conduct error monitoring. This interest is not overridden by users' privacy interests given these safeguards. |
| Product analytics (PostHog) | Art. 6(1)(a) — consent | Consent | Analytics cookies and tracking require your prior consent, which you may withdraw at any time |
| Retaining financial records | Art. 6(1)(c) — legal obligation | Legal obligation | Swiss Code of Obligations (OR Art. 958f) requires retention of accounting records for 10 years |
| Responding to support inquiries | Art. 6(1)(f) — legitimate interest | Overriding legitimate interest | We have a legitimate interest in assisting users who contact us; we process only the data you voluntarily provide |
CyRep uses limited automated processing as described in Section 7.5 (Automated Decision-Making Disclosure). None of these processes constitute solely automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Article 22.
4. Data Processors and International Transfers
We use carefully selected third-party service providers ("data processors") to operate CyRep. Each processor is bound by a Data Processing Agreement (DPA) or equivalent contractual obligation ensuring they process your data only on our instructions and with appropriate safeguards.
Transfer mechanism for US-based processors: Switzerland has not designated the United States as providing an adequate level of data protection under the nFADP. For transfers to US-based processors, we rely on Standard Contractual Clauses (SCCs) — specifically the EU Commission SCCs (2021 version), which Switzerland's Federal Data Protection and Information Commissioner (FDPIC) accepts as a valid transfer mechanism under the nFADP.
The complete list of processors is set out below.
4.1 Supabase
| Provider | Supabase, Inc. |
| HQ location | San Francisco, California, USA |
| Data hosting | AWS eu-central-1 (Frankfurt, Germany) — data is stored and processed in the EU |
| Role | Data processor |
| Data processed | Email address, authentication tokens, user profiles (role, language, daily goal), quiz progress, scores, badges, streaks, XP, virtual shop data |
| Purpose | Authentication, database, user profile storage, progress tracking |
| Transfer mechanism | Data stored in the EU (Frankfurt). Any incidental access from US headquarters is governed by EU SCCs (Controller-to-Processor, 2021 version). |
Supabase's DPA and security documentation are available at supabase.com/security.
4.2 PostHog
| Provider | PostHog, Inc. |
| HQ location | San Francisco, California, USA |
| Data hosting | EU instance at eu.posthog.com (EU-based infrastructure) |
| Role | Data processor |
| Data processed | Pageviews, feature usage events, session data, device and browser information, pseudonymous behavioural events |
| Purpose | Product analytics; understanding how users interact with the app to improve it |
| Transfer mechanism | Data processed within the EU. No international transfer applicable to stored data. |
PostHog events are pseudonymised and not linked to your name or email address in the analytics system. You may opt out through the cookie consent banner. PostHog's privacy policy is available at posthog.com/privacy.
4.3 Sentry
| Provider | Functional Software, Inc. (operating as Sentry) |
| Location | San Francisco, California, USA |
| Role | Data processor |
| Data processed | Error logs, stack traces, browser type, OS, device type; may incidentally contain IP addresses or session identifiers |
| Purpose | Error monitoring and application stability; diagnosing and fixing bugs |
| Transfer mechanism | EU SCCs (Controller-to-Processor, 2021 version) |
| Legal basis | Legitimate interest (see balancing assessment in Section 3) |
Error data is minimised: we configure Sentry to redact personally identifiable information from error payloads where technically feasible. The Sentry browser SDK may set a client-side session identifier; this is classified as strictly necessary (used solely for error reporting, with no cross-session behavioural tracking or profiling). Sentry's DPA and privacy policy are available at sentry.io/privacy.
4.4 Vercel
| Provider | Vercel, Inc. |
| Location | San Francisco, California, USA |
| Role | Data processor |
| Data processed | IP addresses, HTTP request logs, edge function execution logs |
| Purpose | Hosting and deployment of the CyRep web application |
| Transfer mechanism | EU SCCs (Controller-to-Processor, 2021 version). Vercel serves traffic from edge nodes globally, including EU locations. |
Vercel's DPA is available at vercel.com/legal/dpa. Request logs are retained for approximately 30 days per Vercel's standard infrastructure logging policy.
4.5 Stripe
| Provider | Stripe, Inc. |
| Location | San Francisco, California, USA |
| Role | Independent data controller (for payment data); data processor (for subscription status passed to us) |
| Data processed | Payment method details (card number, expiry — held by Stripe only), billing address, transaction history, billing email |
| Purpose | Payment processing and subscription management for the paid tier |
| Transfer mechanism | EU SCCs and Stripe's EU-US Data Privacy Framework certification |
Because Stripe is an independent data controller for payment processing, your payment data is governed by Stripe's privacy policy (stripe.com/privacy). We store only subscription status, plan type, and Stripe customer ID on our own infrastructure. Stripe's DPA is available at stripe.com/legal/dpa.
4.6 Apple Sign-In
| Provider | Apple Inc. |
| Location | Cupertino, California, USA |
| Role | Independent data controller (for their portion of authentication) |
| Data processed | Name, email (may be a relay address), authentication token |
| Purpose | OAuth authentication — enabling you to sign in to CyRep using your Apple ID |
| Transfer mechanism | Apple's own transfer mechanisms under their privacy policy |
Apple's processing of your Apple ID data is governed by Apple's Privacy Policy (apple.com/legal/privacy). We receive only the data Apple provides at sign-in.
4.7 Google Sign-In
| Provider | Google LLC |
| Location | Mountain View, California, USA |
| Role | Independent data controller (for their portion of authentication) |
| Data processed | Name, email address, profile picture |
| Purpose | OAuth authentication — enabling you to sign in to CyRep using your Google account |
| Transfer mechanism | Google's own transfer mechanisms under their privacy policy |
Google's processing of your Google account data is governed by Google's Privacy Policy (policies.google.com/privacy). We do not request access beyond basic profile information.
4.8 Resend
| Provider | Resend, Inc. |
| Location | United States |
| Role | Data processor |
| Data processed | Email address, email content (e.g., magic link URLs, notification text), email delivery metadata (sent, delivered, bounced status) |
| Purpose | Sending transactional emails, including passwordless login links, account notifications, and account deletion confirmations |
| Transfer mechanism | EU SCCs (Controller-to-Processor, 2021 version) |
We use Resend exclusively for transactional communications. We do not send marketing emails through Resend. Resend's privacy policy is available at resend.com/legal/privacy-policy.
4.9 OpenAI / Groq (AI Inference)
| Provider | OpenAI, L.L.C. (semantic embedding of your message) and Groq, Inc. (response generation) |
| Location | United States |
| Role | Data processor |
| Data processed | Your messages to the AI coach; pseudonymous session context (current module, quiz performance summary, learning goal). No name, email address, or account ID is sent. |
| Purpose | Computing message embeddings and generating AI coach responses in real time |
| Transfer mechanism | EU SCCs (Controller-to-Processor, 2021 version); DPA executed before AI coach feature launch |
OpenAI's privacy policy is available at openai.com/policies/privacy-policy. Groq's privacy policy is available at groq.com/privacy-policy.
4.10 Windmill (Workflow Automation)
| Provider | Self-hosted (Windmill CE v1.664.0 on Hetzner CX22, Falkenstein, Germany) |
| Location | EU (Germany — Hetzner datacenter) |
| Role | Data processor (self-hosted) |
| Data processed | Triggered by internal events; may process email addresses, subscription events, or pseudonymous user identifiers depending on workflow configuration |
| Purpose | Internal workflow automation (monitoring, retention policy enforcement, content pipeline, compliance reporting) |
| Transfer mechanism | EU-hosted; no international transfer. Secrets synced from Infisical Cloud EU. |
Automation workflow execution logs are retained for 90 days. Windmill is self-hosted open-source software (windmill.dev).
4.11 Crisp (Customer Support)
| Provider | Crisp IM SAS |
| Location | France (EU) |
| Role | Data processor |
| Data processed | Name, email address, in-app chat messages, pseudonymous user ID, device info |
| Purpose | In-app customer support chat and knowledge base |
| Transfer mechanism | None required — EU-native (France + Germany datacenters) |
Crisp is used for chat-based support and support automation only. We do not use Crisp for email marketing campaigns or behavioural advertising. Crisp is a French company with all data hosted in EU datacenters (France and Germany). No cross-border data transfers outside the EEA. Crisp's privacy policy is available at crisp.chat/en/privacy. Support conversation data is retained for 2 years from last communication.
4.12 DeepL (Translation)
| Provider | DeepL SE |
| Location | EU (Germany) |
| Role | Data processor |
| Data processed | Text strings submitted for translation; not expected to include personal data unless user-generated content is translated |
| Purpose | Translation of UI strings and content into supported languages |
| Transfer mechanism | EU-hosted; no international transfer |
DeepL's privacy policy is available at deepl.com/privacy.
4.13 Bunny.net (CDN)
| Provider | BunnyWay d.o.o. |
| HQ location | EU (Slovenia) |
| Role | Data processor |
| Data processed | IP addresses, HTTP request logs, cached content delivery metadata |
| Purpose | Content delivery network (CDN) for static assets and media files |
| Transfer mechanism | EU-based. Bunny.net's global Points of Presence (PoPs) may serve cached content from locations outside the EU; IP addresses may be logged at edge nodes outside the EU in the process of content delivery. |
Bunny.net's privacy policy is available at bunny.net/privacy.
4.14 Bexio (Accounting)
| Provider | bexio AG |
| Location | Switzerland |
| Role | Data processor |
| Data processed | Name, billing address, email address, invoice amounts (passed from Stripe or entered by the operator for invoicing purposes) |
| Purpose | Swiss accounting, bookkeeping, and invoicing compliance |
| Transfer mechanism | Switzerland (no international transfer; adequacy-covered for EU data) |
Bexio processes billing data to generate invoices and maintain accounting records as required by Swiss law (OR Art. 958f). Bexio's privacy policy is available at bexio.com/en/privacy.
4.15 GoDaddy (Domain Registrar)
| Provider | GoDaddy Inc. |
| Location | United States |
| Role | Service provider / limited data processor |
| Data processed | Domain registration data (registrant name, address, email — this is the operator's data, not end-user data). WHOIS data is subject to ICANN policies. |
| Purpose | Domain name registration and management for cisoaia.com and cyrep.cisoaia.com |
| Transfer mechanism | EU SCCs; domain registrant data is the operator's own data, not your personal data as a CyRep user |
GoDaddy's privacy policy is available at godaddy.com/legal/agreements/privacy-policy.
4.16 RevenueCat (Subscription Management)
| Provider | RevenueCat, Inc. |
| Location | United States |
| Role | Data processor |
| Data processed | Anonymous app user ID (Supabase UUID), Apple App Store purchase receipts, subscription status, entitlement data |
| Purpose | In-app purchase and subscription management — receipt validation, subscription status tracking, entitlement checking |
| Transfer mechanism | EU SCCs (Controller-to-Processor, 2021 version) |
RevenueCat does not receive your email, name, or any personal information beyond an anonymous user identifier. Purchase receipts are validated directly with Apple. RevenueCat's privacy policy is available at revenuecat.com/privacy.
4.17 Infisical (Secrets Management)
| Provider | Infisical Inc. |
| Location | EU (Frankfurt, Germany — dedicated AWS EU account) |
| Role | Data processor |
| Data processed | No personal data. Manages API keys, service credentials, and configuration secrets only. |
| Purpose | Centralized secrets management with auto-sync to Windmill and Supabase Edge Functions |
| Transfer mechanism | None required — EU-hosted (Frankfurt). SOC 2 Type II certified. |
Infisical does not process end-user personal data. It stores and syncs encrypted service credentials (API keys, webhook secrets) used by our infrastructure. Infisical's privacy policy is available at infisical.com/privacy.
4.18 Hetzner (Server Hosting)
| Provider | Hetzner Online GmbH |
| Location | Falkenstein, Germany (EU) |
| Role | Infrastructure provider (IaaS) |
| Data processed | Server logs only (IP addresses in web server logs, retained < 7 days) |
| Purpose | Hosts self-hosted Windmill automation server |
| Transfer mechanism | None required — Germany (EU) |
Hetzner provides the virtual private server (CX22) for our Windmill automation platform. Hetzner is ISO 27001 certified. No end-user personal data is stored on the Hetzner server — it processes only automation workflows. Hetzner's privacy policy is available at hetzner.com/privacy-policy.
5. Cookies and Analytics
CyRep uses a small number of cookies and similar technologies. We do not use cookies for advertising or cross-site tracking.
5.1 Essential Cookies
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
sb-* (Supabase auth session) | Supabase | Maintains your authenticated session. Without this cookie, you cannot remain logged in. | Session duration (access token) + 7 days (refresh token, default) |
| Sentry session ID | Sentry | Links client-side errors to a browser session for error diagnosis. No cross-session behavioural tracking. Not used for profiling. | Session duration (cleared on tab/browser close) |
Essential cookies are strictly necessary for the service to function and are exempt from consent requirements under the ePrivacy Directive Article 5(3). They do not require your consent under GDPR (Recital 47) or the nFADP. These cookies cannot be disabled without breaking core functionality.
5.2 Analytics Cookies (Consent Required)
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
ph_* (PostHog distinct ID) | PostHog | Identifies your pseudonymous session and feature interactions for product analytics. | 1 year (persistent) |
| PostHog session ID | PostHog | Groups page views and events into a single browsing session for funnel analysis. | 30 minutes (session, resets on activity) |
Analytics cookies require prior consent under GDPR Article 6(1)(a) and ePrivacy Directive Article 5(3). They are placed only after you provide consent through the cookie consent banner displayed on your first visit to CyRep. Both the "Accept All" and "Essential Only" options are presented with equal visual weight. You may change your preference at any time by clicking the Cookie Preferences link in the app footer.
Withdrawing consent: Withdrawal of consent does not affect the lawfulness of analytics processing carried out before withdrawal. Previously collected analytics events will be retained for the stated 12-month period and then deleted. Withdrawal stops all future analytics collection immediately. You can withdraw consent at any time via Cookie Preferences in the app footer.
5.3 No Marketing or Advertising Cookies
CyRep does not use any marketing, retargeting, or advertising cookies. We do not share behavioural data with advertising networks.
5.4 Browser Privacy Signals
CyRep honours the Global Privacy Control (GPC) and Do Not Track (DNT) signals. When either signal is detected, analytics tracking is not initialised and no analytics cookies are placed, regardless of any prior consent.
5.5 Opting Out of Analytics
You may opt out of PostHog analytics at any time by:
- Clicking the Cookie Preferences link in the app footer and selecting "Essential Only"; or
- Enabling the Global Privacy Control (GPC) or Do Not Track (DNT) signal in your browser.
Withdrawing consent for analytics cookies does not affect the functionality of CyRep.
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy or as required by applicable law.
| Data category | Retention period | Rationale |
|---|---|---|
| Account data (email, name, authentication method, profile settings) | Duration of account, plus 30 days after account deletion | Allows account recovery within a short grace period; data is purged after the grace period expires |
| Learning data (quiz results, scores, progress, streaks, badges, XP) | Duration of account, plus 30 days after account deletion | Integral to account; deleted in the same cascade as the account |
| AI coach interaction data (messages and session context) | 90 days from creation | Sufficient for support and debugging purposes; minimises retention of AI-processed content |
| Analytics data (PostHog events) | 12 months from collection | Sufficient for trend analysis; older data provides diminishing value |
| Error logs (Sentry) | 90 days from capture | Sufficient for diagnosing and resolving bugs; minimises unnecessary retention of incidental personal data |
| Server/infrastructure request logs (Vercel) | 30 days (Vercel default) | Short-term operational and security monitoring |
| Automation workflow logs (Windmill) | 90 days | Operational monitoring; short retention minimises exposure |
| Payment and billing records (subscription history, invoices) | 10 years from the date of transaction | Mandatory retention under Swiss Code of Obligations (OR Art. 958f) and Swiss VAT law |
| Support and communication data (Crisp, email) | 2 years from last communication | Reasonable period for resolving follow-up inquiries; unless an ongoing legal matter requires longer retention |
| Consent records (cookie consent log, terms acceptance) | 3 years from the date of consent | Demonstrates compliance with consent obligations (GDPR Art. 7(1)); not deleted on account deletion |
| Audit logs | 1 year (hot/active), then archived | Security monitoring and compliance; anonymised subscription events survive account deletion under Swiss bookkeeping law |
When a retention period expires, data is deleted securely or anonymised where deletion is not technically feasible. If you request erasure before the end of a retention period, we will delete your data promptly unless a legal retention obligation prevents us from doing so; in that case, we will inform you of the specific obligation and restrict processing to the minimum necessary.
Note on account deletion: When you delete your account, subscription events are anonymised (rather than deleted) and retained to satisfy Swiss bookkeeping requirements under OR Art. 958f. The anonymised records contain no name, email, or other identifying information.
7. Your Rights
You have the following rights regarding your personal data under GDPR, UK GDPR, and the Swiss nFADP. These rights apply regardless of whether you are resident in the EU/EEA, the UK, or Switzerland.
7.1 Summary of Rights
| Right | Description |
|---|---|
| Right of access (GDPR Art. 15; nFADP Art. 25) | You may request a copy of all personal data we hold about you, along with information about how it is processed. |
| Right to rectification (GDPR Art. 16; nFADP Art. 32) | You may request correction of inaccurate or incomplete personal data. Much of your profile data can be updated directly within the app. |
| Right to erasure ("right to be forgotten") (GDPR Art. 17; nFADP Art. 32) | You may request deletion of your personal data. See Section 7.4 for the in-app deletion process. We may be unable to delete data we are legally required to retain (e.g., financial records). |
| Right to data portability (GDPR Art. 20; nFADP Art. 28) | You may request your personal data in a structured, commonly used, machine-readable format (JSON or CSV). We will provide your data export within 30 days of receiving your request, delivered to your registered email address. This applies to data you provided to us that we process based on contract or consent. |
| Right to restriction of processing (GDPR Art. 18) | You may request that we temporarily restrict processing of your data — for example, while a dispute about its accuracy is resolved. |
| Right to object (GDPR Art. 21; nFADP Art. 32) | You may object to processing based on legitimate interest (e.g., error tracking). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. |
| Right to withdraw consent | Where processing is based on your consent (e.g., analytics cookies), you may withdraw consent at any time without affecting the lawfulness of prior processing. |
| Rights related to automated decision-making (GDPR Art. 22) | CyRep uses adaptive difficulty algorithms and automated leaderboard rankings (see Section 7.5). These do not constitute solely automated decisions with legal or similarly significant effects under GDPR Art. 22. You may contest rankings or difficulty adjustments via Crisp in-app chat or by emailing privacy@cisoaia.com. |
7.2 How to Exercise Your Rights
To exercise any of the above rights, please contact us at privacy@cisoaia.com with:
- Your name and email address (to verify your identity); and
- A clear description of the right you wish to exercise and the data concerned.
We will respond within 30 days of receiving your request. Where a request is complex or numerous, we may extend this period by up to 60 days, in which case we will notify you within the initial 30-day period with an explanation of the delay.
We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act (and will explain why).
7.3 Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the relevant supervisory authority:
Swiss residents can lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).
Feldeggweg 1, 3003 Berne, Switzerland
Website: www.edoeb.admin.ch
EU residents can lodge a complaint with their local supervisory authority — the data protection authority in your EU member state of habitual residence, place of work, or the place where an alleged infringement occurred. A directory of EU data protection authorities is available at: edpb.europa.eu/about-edpb/about-edpb/members_en
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk | Tel: 0303 123 1113
We encourage you to contact us first at privacy@cisoaia.com before lodging a formal complaint, as we can often resolve concerns directly and promptly.
7.4 In-App Account Deletion
You can delete your account directly from within CyRep:
Settings → Account → Delete My Account
When you click "Delete My Account":
- Your account is immediately marked as pending deletion, with a scheduled deletion date 30 days in the future.
- Login is disabled for the account.
- You receive a confirmation email with a cancellation link valid for 30 days — you can click this link at any time within the 30-day period to cancel the deletion and restore your account.
- After 30 days, all personal data is permanently and irreversibly deleted across all systems, including: Supabase (all profile, learning, and auth data), Stripe (subscription cancelled, customer record deleted), PostHog (person record deleted), Sentry (user data deleted), and Crisp (user deleted).
- Anonymised subscription events are retained to satisfy Swiss bookkeeping obligations (OR Art. 958f) — these records contain no name, email, or identifying information.
You may also request deletion by emailing privacy@cisoaia.com, in which case we will initiate the cascade deletion process without the 30-day in-app grace period.
7.5 Automated Decision-Making Disclosure
CyRep uses the following automated processing:
- Adaptive difficulty algorithms: Quiz difficulty adjusts automatically based on your accuracy performance. Your quiz answers and scores are used to determine whether you receive beginner, intermediate, or advanced questions in subsequent sessions.
- Leaderboard rankings: Leaderboard positions are computed automatically based on your rank (accuracy-based tier) and level (XP-based progression). Rankings are recalculated as users complete quizzes.
These automated processes are integral to the gamified learning experience and do NOT constitute solely automated decisions with legal or similarly significant effects within the meaning of GDPR Article 22. They affect only your in-app experience (question difficulty and leaderboard position) and have no legal, financial, or other significant consequences outside the application.
Right to contest: If you believe your difficulty level or leaderboard ranking is inaccurate or unfair, you may contest the outcome at any time by contacting us via:
- Crisp in-app chat (available in the app footer); or
- Email: privacy@cisoaia.com
We will review your concern and, where appropriate, manually adjust your settings.
8. Children's Privacy
CyRep is intended for users who are 18 years of age or older. We do not knowingly collect personal data from individuals under 18.
If you are under 18, please do not create an account or use CyRep. If you are a parent or guardian and believe your child under 18 has registered with CyRep, please contact us immediately at privacy@cisoaia.com. We will promptly investigate and, if confirmed, delete the account and all associated personal data.
CyRep does not conduct automated age verification beyond the user's declaration during registration. If a user under 18 creates an account by misrepresenting their age, the operator cannot be held responsible for that misrepresentation; however, we will promptly delete the account and data upon notification.
9. Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration.
Technical measures:
- All data in transit is encrypted using TLS 1.2 or higher.
- Database data at rest is encrypted using AES-256 (provided by Supabase/AWS in Frankfurt, Germany).
- Authentication uses industry-standard mechanisms, including short-lived JWT tokens, bcrypt password hashing, and OAuth 2.0 for third-party sign-in.
- Row-level security (RLS) policies on the Supabase database ensure users can only access their own data.
- Access to production systems is restricted to authorised personnel using least-privilege access controls and multi-factor authentication.
Organisational measures:
- We conduct regular reviews of third-party processor security practices and certifications (SOC 2 Type II, ISO 27001 where available).
- We maintain a data breach response procedure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware (as required by GDPR Art. 33 and the nFADP). Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (GDPR Art. 34; nFADP Art. 24).
- We practice data minimisation: we collect only data that is necessary for the identified purposes.
Despite these measures, no system is completely secure. If you become aware of a security vulnerability or incident related to CyRep, please notify us immediately at privacy@cisoaia.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, technology, legal requirements, or business operations.
When we make material changes, we will:
- Update the "Last updated" date at the top of this Policy;
- Display a prominent notice within the CyRep application; and
- Where required by law, seek your renewed consent (including for consent-based processing such as analytics).
We encourage you to review this Policy periodically. Older versions of this Privacy Policy will be archived and made available upon request at privacy@cisoaia.com.
11. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact:
Reutlingerstrasse 18
8472 Seuzach
Switzerland
Email: privacy@cisoaia.com
App: cyrep.cisoaia.com
We aim to respond to all privacy-related inquiries within 5 business days.
12. California Residents (CCPA/CPRA)
This section applies to users who are residents of California, USA.
We do not sell or share your personal information. CyRep does not sell personal information, and does not share personal information for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).
Global Privacy Control (GPC): CyRep honours the GPC browser signal. If we detect a valid GPC signal from your browser, we treat it as a valid opt-out of any sharing of personal information for cross-context behavioural advertising purposes and will not initialise analytics tracking for that session.
No cross-context behavioural advertising: We do not use personal information collected on CyRep for advertising on other websites or services.
California rights: California residents may exercise any of the rights described in Section 7 of this Policy by contacting us at privacy@cisoaia.com. We will acknowledge your request within 10 business days and respond substantively within 45 calendar days (extendable by a further 45 days with notice for complex requests).
We do not discriminate against users who exercise their California privacy rights.