1. Controller
CYBER CLUSTER LLC, 1209 MOUNTAIN ROAD PL NE STE R Albuquerque, NM 87110, is the controller for the processing described in this policy.
Privacy requests may be submitted through the contact form by selecting “Privacy request”.
2. Scope and business users
This policy covers visitors, professional users, purchasers, contacts and individuals whose business contact details are included in support or billing records. SecuTest is not directed to children or consumers.
3. Data we process
| Category | Examples |
|---|---|
| Technical request data | Submitted domain or URL, scan identifier, timestamps, status, public findings and errors. |
| Security and anti-abuse data | IP-derived pseudonymous client key, rate-limit events, domain, decisions, logs and security events. |
| Purchase data | Stripe session and payment references, amount, currency, status, purchaser email, company name, billing address and tax identifier where supplied. |
| Contact data | Name, business email, company, topic, message, submitted target and Formspree metadata. |
| Usage data | Server logs, user agent, referrer, request path, response status and performance data where logged. |
Do not submit credentials, private keys, special-category data or unnecessary personal information.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide scans, reports, checkout, invoicing and support | Contract and steps requested before contract. |
| Prevent abuse, fraud and service disruption | Legitimate interests in service and network security. |
| Maintain logs, diagnose failures and improve reliability | Legitimate interests in operating a secure and effective service. |
| Accounting, tax, disputes and legal compliance | Legal obligations and legitimate interests in establishing or defending claims. |
| Respond to privacy, legal, security and abuse requests | Legal obligations and legitimate interests. |
5. Sources
We receive data directly from users and purchasers, from Stripe and Formspree, from our hosting and security infrastructure, and from publicly accessible internet services queried during an assessment.
6. Recipients, subprocessors and providers
Access is limited to authorised personnel and providers that need data to operate the service.
| Provider | Purpose | Data categories | Primary location |
|---|---|---|---|
| Stripe, Inc. and affiliates | Checkout, payment processing, fraud prevention and invoices. | Purchaser identity, company, billing, tax and transaction data. | United States and provider locations. |
| Formspree, Inc. | Contact-form delivery and spam prevention. | Contact identity, company, email, topic, target and message. | United States and provider locations. |
| OVH SAS | Website, API, storage and infrastructure hosting. | Technical request data, scans, reports, logs and purchase references. | France, European Union |
| OVHcloud | Encrypted or access-controlled backups. | Backup copies of application data. | European Union |
| OVHcloud | Authoritative DNS and related security infrastructure. | DNS request metadata and service logs as applicable. | Global Anycast network operated by OVHcloud; OVH SAS is established in France |
We select providers based on operational need, security, reliability and contractual protections. Where a provider acts as a processor, we seek terms addressing confidentiality, security, incident notification, deletion and lawful international transfers. We may update this provider list as infrastructure changes; material changes are reflected by updating the effective date or version.
7. International transfers
CYBER CLUSTER LLC is established in the United States. Data may be processed in the United States and other countries where providers operate. Where required, transfers are governed by an adequacy decision, approved contractual safeguards, another lawful transfer mechanism or a permitted derogation.
8. Retention
| Data | Standard period |
|---|---|
| Free scan reports | Up to 30 days. |
| Paid scan reports and generated files | Up to 365 days; download access is contractually guaranteed for at least 30 days. |
| Anti-abuse event data and pseudonymous client keys | Up to 48 hours under the current production policy. |
| Application and security logs | Up to 90 days unless needed for an incident or claim. |
| Contact-form submissions | Up to 24 months after the last relevant interaction. |
| Purchase, invoice, tax and legal-acceptance records | Up to 10 years or the applicable statutory period. |
| Backups | Rolling copies for up to 14 days. |
Data may be retained longer where reasonably necessary for security incidents, disputes, fraud prevention, legal holds or mandatory law. The internal retention tool enforces operational deletion schedules for scan and cache data.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. We may need to verify identity and authority. Some records must be retained for legal, security or contractual reasons.
Individuals in France may lodge a complaint with the CNIL; individuals elsewhere may contact their competent supervisory authority.
10. Automated assessment
SecuTest automatically scores technical signals, but does not make decisions that produce legal or similarly significant effects about natural persons. Customers must perform human review before acting on a report.
11. Security
We use access controls, least privilege, bounded execution, transport encryption, signed payment webhooks, tokenised report access, rate limiting, backups and logging. No system is completely secure, and users must protect report links and downloaded files.
Security vulnerabilities affecting SecuTest may be reported under the vulnerability disclosure policy.
13. Changes and contact
We may update this policy prospectively. The effective date and version identify the current policy. Submit privacy, provider or data-transfer questions through the contact form.