HebridesCyber
← Back to home

Privacy Policy

Last updated: August 2025

1. Who we are

Hebrides Cyber (“we”, “us”, “our”) provides automated security scanning, penetration testing advisory, and CI/CD hardening services. We are based in the Isle of Lewis, Scotland, UK. For data protection purposes we act as the data controller of the personal data we collect via this website.

Questions about this policy: hello@hebridescyber.co.uk

2. What data we collect

2a. Account data

When you sign up or sign in we collect:

  • Email address (used for authentication and service communications)
  • Full name and company name (optional, entered in your profile)
  • Authentication metadata (sign-in timestamps, MFA enrolment) managed by Supabase Auth

2b. Scan data

When you run a security scan we record the target URL, scan results (TLS grade, header findings, DNS records, exposed paths, vulnerability findings), a computed score, and an AI-generated summary. Scan targets must be domains you own or are authorised to test — by submitting a scan you confirm this.

2c. Contact enquiries

If you use the contact form we store your name, email address, website URL (if provided), and your message. We use this to respond to your enquiry.

2d. Subscription and billing

Subscription status and plan tier are stored in our database. Payment card details are handled entirely by Stripe; we never see or store full card numbers.

2e. Usage analytics

We use Google Analytics 4 to understand how the site is used (page views, session duration). Analytics cookies are only set after you accept the cookie consent banner. You can opt out at any time by withdrawing consent (click “Cookie settings” in the site footer).

2f. Server logs

Our hosting provider (Microsoft Azure) retains standard server access logs (IP address, request path, timestamp, HTTP status) for up to 30 days for security and operational purposes.

3. Why we process your data (legal basis)

DataPurposeLawful basis
Account & authenticationProviding the serviceContract
Scan dataDelivering scan results and reportsContract
Contact enquiriesResponding to your enquiryLegitimate interests
BillingProcessing subscription paymentsContract
AnalyticsImproving the siteConsent
Server logsSecurity and operationsLegitimate interests

4. Who we share data with

We do not sell personal data. We share data with the following service providers:

  • Supabase — database and authentication (hosted in EU region)
  • Stripe — payment processing
  • Microsoft Azure — hosting, compute, and blob storage
  • Google Analytics — usage analytics (only with your consent)
  • Resend — transactional email (contact form notifications)

All processors are bound by data processing agreements and process data only on our instructions.

5. International transfers

Some of our processors operate outside the UK/EEA. Where data is transferred internationally we rely on standard contractual clauses or adequacy decisions in place between the UK and the relevant countries to ensure equivalent protection.

6. How long we keep data

  • Account data: for as long as your account is active, then deleted within 30 days of account closure.
  • Scan results: retained for 12 months then purged automatically.
  • Contact enquiries: retained for 12 months, then deleted.
  • PDF reports stored in Azure Blob Storage: deleted after 90 days.
  • Server logs: up to 30 days.

7. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Erase your data (“right to be forgotten”) where no overriding legal obligation requires us to keep it
  • Restrict processing in certain circumstances
  • Data portability — receive a copy of your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent for analytics at any time without affecting prior processing

To exercise any of these rights, email hello@hebridescyber.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).

8. Cookies

We use the following cookies:

CookiePurposeDurationConsent required
hc-themeSaves your light/dark theme preference1 yearNo (functional)
hc-cookie-consentRecords your cookie consent choice1 yearNo (functional)
Supabase auth cookiesMaintains your signed-in sessionSession / 7 daysNo (essential)
Google Analytics (_ga, _gid)Usage analyticsUp to 2 yearsYes

9. Security

We apply TLS encryption in transit, row-level security on all database tables, and regular automated security scanning against our own infrastructure. Sensitive credentials are stored as environment variables, never in source code. Despite these measures, no system is completely secure — if you believe you've found a vulnerability in our platform, please disclose it responsibly to hello@hebridescyber.co.uk.

10. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top will reflect any changes. Material changes will be communicated by email to registered users.

11. Contact

Hebrides Cyber
Isle of Lewis, Scotland, UK
hello@hebridescyber.co.uk