Privacy Policy
Last updated: August 2025
1. Who we are
Hebrides Cyber (“we”, “us”, “our”) provides automated security scanning, penetration testing advisory, and CI/CD hardening services. We are based in the Isle of Lewis, Scotland, UK. For data protection purposes we act as the data controller of the personal data we collect via this website.
Questions about this policy: hello@hebridescyber.co.uk
2. What data we collect
2a. Account data
When you sign up or sign in we collect:
- Email address (used for authentication and service communications)
- Full name and company name (optional, entered in your profile)
- Authentication metadata (sign-in timestamps, MFA enrolment) managed by Supabase Auth
2b. Scan data
When you run a security scan we record the target URL, scan results (TLS grade, header findings, DNS records, exposed paths, vulnerability findings), a computed score, and an AI-generated summary. Scan targets must be domains you own or are authorised to test — by submitting a scan you confirm this.
2c. Contact enquiries
If you use the contact form we store your name, email address, website URL (if provided), and your message. We use this to respond to your enquiry.
2d. Subscription and billing
Subscription status and plan tier are stored in our database. Payment card details are handled entirely by Stripe; we never see or store full card numbers.
2e. Usage analytics
We use Google Analytics 4 to understand how the site is used (page views, session duration). Analytics cookies are only set after you accept the cookie consent banner. You can opt out at any time by withdrawing consent (click “Cookie settings” in the site footer).
2f. Server logs
Our hosting provider (Microsoft Azure) retains standard server access logs (IP address, request path, timestamp, HTTP status) for up to 30 days for security and operational purposes.
3. Why we process your data (legal basis)
| Data | Purpose | Lawful basis |
|---|---|---|
| Account & authentication | Providing the service | Contract |
| Scan data | Delivering scan results and reports | Contract |
| Contact enquiries | Responding to your enquiry | Legitimate interests |
| Billing | Processing subscription payments | Contract |
| Analytics | Improving the site | Consent |
| Server logs | Security and operations | Legitimate interests |
4. Who we share data with
We do not sell personal data. We share data with the following service providers:
- Supabase — database and authentication (hosted in EU region)
- Stripe — payment processing
- Microsoft Azure — hosting, compute, and blob storage
- Google Analytics — usage analytics (only with your consent)
- Resend — transactional email (contact form notifications)
All processors are bound by data processing agreements and process data only on our instructions.
5. International transfers
Some of our processors operate outside the UK/EEA. Where data is transferred internationally we rely on standard contractual clauses or adequacy decisions in place between the UK and the relevant countries to ensure equivalent protection.
6. How long we keep data
- Account data: for as long as your account is active, then deleted within 30 days of account closure.
- Scan results: retained for 12 months then purged automatically.
- Contact enquiries: retained for 12 months, then deleted.
- PDF reports stored in Azure Blob Storage: deleted after 90 days.
- Server logs: up to 30 days.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data (“right to be forgotten”) where no overriding legal obligation requires us to keep it
- Restrict processing in certain circumstances
- Data portability — receive a copy of your data in a structured, machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent for analytics at any time without affecting prior processing
To exercise any of these rights, email hello@hebridescyber.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).
8. Cookies
We use the following cookies:
| Cookie | Purpose | Duration | Consent required |
|---|---|---|---|
hc-theme | Saves your light/dark theme preference | 1 year | No (functional) |
hc-cookie-consent | Records your cookie consent choice | 1 year | No (functional) |
| Supabase auth cookies | Maintains your signed-in session | Session / 7 days | No (essential) |
Google Analytics (_ga, _gid) | Usage analytics | Up to 2 years | Yes |
9. Security
We apply TLS encryption in transit, row-level security on all database tables, and regular automated security scanning against our own infrastructure. Sensitive credentials are stored as environment variables, never in source code. Despite these measures, no system is completely secure — if you believe you've found a vulnerability in our platform, please disclose it responsibly to hello@hebridescyber.co.uk.
10. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will reflect any changes. Material changes will be communicated by email to registered users.
11. Contact
Hebrides Cyber
Isle of Lewis, Scotland, UK
hello@hebridescyber.co.uk