This privacy policy sets out how Cyberwolf processes personal data and how it is used. Cyberwolf consists of two independent data controllers:
- Cyberwolf bv, Guldensporenpark 21C, 9820 Merelbeke-Melle, Belgium, registered with company number BE0768.728.859.
- Cyberwolf INC, 691 John Wesley Dobbs Ave, Atlanta, GA, 30312, United States.
Each entity determines the purposes and means of its own processing independently.
Cyberwolf complies with national and European regulations on the protection of personal data.
Personal data we collect
We collect the following categories of personal data:
- Contact details: name, email address, telephone number, company name, job title, submitted via a contact form or when making an enquiry.
- Communication content: the content of messages and any attachments you send us.
- Technical data: IP address, browser type and referring URL collected automatically as part of normal website operation.
- Website use: only with your consent, which pages you visit, how you arrived and whether you came from one of our advertisements, collected with cookies as described in our cookie notice.
- What you enter in our self-assessment tools: an email address, a domain name or an IP address, used only to give you the result (see “Our website and its service providers” below).
We collect this data directly from you.
From time to time, Cyberwolf receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from a third-party website (e.g. LinkedIn).
Purposes
Personal data is used for the following purposes:
- Responding to enquiries via the contact form(s) – based on our legitimate interest in handling enquiries efficiently.
- Responding to applications – to take pre-contractual steps.
- Processing event registrations – to confirm your registration and keep you informed about the event.
- Sending communications relating to security, networking and privacy – only with your consent.
- Measuring the use of our website and the results of our advertising – only with your consent, which you can withdraw at any time through “Cookie settings” in the footer of every page.
- Providing the self-assessment tools – at your request, when you start a check.
- Compliance with legal obligations – where required by law.
- Data sharing between the Cyberwolf entities – based on legitimate interest, in delivering consistent services.
Retention
Cyberwolf retains personal data for as long as necessary to fulfill the purposes of the processing.
Transfer of personal data
Cyberwolf will not sell, rent, distribute or otherwise make your personal data commercially available to third parties, except with your explicit consent.
Furthermore, we work with trusted service providers. We only transfer personal data to the extent necessary, and they are contractually bound to process it solely on our behalf.
Any transfer of personal data outside the European Economic Area is subject to appropriate safeguards: recipients must be in a country recognized by the EEA as providing adequate protection or must have agreed to the European Commission’s Standard Contractual Clauses.
We may share personal data between our affiliated companies. Both entities act as independent controllers; each entity only receives the data it needs. Personal data that is transferred between the companies is protected by Standard Contractual Clauses.
Disclosure may occur in response to a court order or other binding legal obligation. In the unlikely event of a merger, acquisition or similar restructuring, your data may be transferred as part of that transaction. Where legally permitted, we will make reasonable efforts to notify you before doing so.
Our website and its service providers
The website and the services below process personal data on our behalf, or, where stated, as independent controllers under their own privacy policies.
- Microsoft Azure hosts the website and the back end of the self-assessment tools, in Microsoft’s West Europe region.
- HubSpot receives what you send through a contact form (name, email address, telephone number and message), together with the address and title of the page you sent it from, when you press Send. It is our contact management system. With marketing consent, HubSpot also recognises returning visitors with cookies.
- Google provides Google Tag Manager and Google Analytics (with analytics or marketing consent) and Google Ads conversion measurement (with marketing consent).
- LinkedIn (the LinkedIn Insight tag) and Meta (the Meta pixel) measure the results of our advertising, with marketing consent only. With marketing consent, the Meta pixel also sends these measurements to a server on Amazon Web Services in the United States (Oregon) that is part of our Meta advertising setup.
- The self-assessment tools. The Breach Checker sends the email address you enter to Have I Been Pwned, through our own server, to look up known breaches; we do not keep the address. The Network Scanner sends your IP address, or the one you enter, to Shodan to look up what is publicly known about it. The Domain Security Checker looks up the domain name you enter at Google Public DNS, directly from your browser. The Personal Exposure Assessment runs entirely in your browser and sends nothing. To limit the number of checks, our server keeps a scrambled (hashed) form of your IP address, never the address itself.
Google, LinkedIn and Meta can also connect your visit to an account you hold with them, under their own privacy policies. The cookies each service sets, and how long they last, are listed in our cookie notice.
If you choose to share information from the Cyberwolf website through a third-party service such as LinkedIn, you should review the privacy policy of that service.
Security
As a cybersecurity company, Cyberwolf applies rigorous technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and unlawful processing. For further information, please contact our Privacy Officer.
Privacy Officer
Cyberwolf has appointed a privacy officer for you to contact if you have any questions or concerns about Cyberwolf’s personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Cyberwolf’s privacy officer, who can be contacted via privacy@cyberwolf.io.
Your rights
The European Union’s General Data Protection Regulation (GDPR) and other countries’ privacy laws (e.g. CCPA/CPRA) provide certain rights for data subjects. You have the following rights:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right of data portability
- Right to object
- Right to withdraw consent
To exercise any of these rights, contact us at privacy@cyberwolf.io. We will respond within thirty days of receipt of your request. If access cannot be provided within a reasonable time frame, Cyberwolf will provide you with a date when the information will be provided. Requests are ordinarily handled free of charge; a reasonable administrative fee may apply to manifestly unfounded or excessive requests.
If you believe your rights have not been respected, you may lodge a complaint with the Belgian Data Protection Authority: Drukpersstraat 35, B-1000 Brussels, tel. +32 (0)2 274 48 00 – contact@apd-gba.be – www.gegevensbeschermingsautoriteit.be
Changes to this policy
Cyberwolf may change this privacy policy to reflect current acceptable practices. Your continued use of this site after any changes to this policy will be regarded as acceptance of our practices around privacy and personal information.
If you have any questions, concerns, complaints or would like to exercise your rights, please contact us at privacy@cyberwolf.io.