For organisations
Data processing agreement
This agreement covers the personal data Cyberact processes on behalf of an organisation customer when the customer trains its people in the service. It is an agreement under Article 28 of the GDPR and part of the terms of use for organisation customers: when an organisation buys the service or takes it into use, it accepts this agreement too.
Version 5 October 2026
1. Parties and roles
The customer is the organisation that uses Cyberact and adds or invites users to it. The customer is the controller. The processor is:
- Cyberact, Business ID 3493670-4, VAT number FI34936704
- Email: support@cyberact.io
This agreement does not cover data of which Cyberact is itself the controller: individuals' own accounts, the waitlist, the public site, or the data used to protect the service against misuse. These are described in the privacy notice (https://cyberact.io/privacy). Nor does it cover the customer's buyer and billing details, such as name, email address, billing address and VAT number: Cyberact is the controller of those. Stripe is in annex 2 for transparency.
Terms in this agreement have the meaning they have in the GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter: the personal data of the customer's users needed to provide security and AI training.
- Duration: for as long as the customer uses the service, and after that for the retention period in section 11.
- Nature: storing, organising, grading answers, combining into reports, sending emails and notifications, exporting, backing up and deleting.
- Purpose: sign-in and access rights, delivering lessons and reviews, grading answers, the leaderboard, reminders, and the customer's training record and audit evidence.
3. Data subjects and personal data
The data subjects are the customer's employees and other people the customer adds or invites to the service, including the customer's managers and main admins. The personal data processed is:
- account: email address, name, organisation, department, role, status, when created and last sign-in
- invitations: address, role, sender and dates
- training data: completions with results, answers (right or wrong, time taken and day), the memory bank's review data, daily quiz results, the profile (XP, streak, streak freezes, settings) and the leaderboard choice
- the daily quiz reminder, if the user turns it on: push service address and keys, time, time zone and language
- access log: sign-ins, changes to access rights, exports and deletions, the email address of who did it and of whom it concerned, and a keyed hash of the IP address
- manager console summaries of the organisation's aggregated figures
The service is not meant for special categories of personal data (GDPR Article 9), and the customer does not store them in it.
4. The customer's instructions
Cyberact processes personal data only on the customer's documented instructions. The instructions are this agreement, the terms of use, the customer's choices in the service, such as adding, deleting and exporting users, and the customer's written requests to support@cyberact.io. The same applies to transfers outside the EU and EEA.
If Union or Member State law requires Cyberact to process the data otherwise, Cyberact tells the customer before processing, unless that law forbids telling.
Cyberact tells the customer immediately if, in its opinion, an instruction infringes the GDPR or other data protection law.
The customer is responsible for having a legal basis for the processing and for having informed its users of it.
5. Confidentiality of personnel
Cyberact gives access to the customer's personal data only to those who need it to run the service or to help the customer. Cyberact ensures that each of them has committed to confidentiality or is under a statutory obligation of confidentiality.
6. Security
Cyberact implements the technical and organisational measures required by Article 32 of the GDPR. They are listed in annex 1. Cyberact may improve them but will not lower the level of protection during the agreement.
7. Sub-processors
The customer gives general prior authorisation to use the sub-processors listed in annex 2.
Cyberact tells the customer's main admin by email at least 14 days in advance of any intended addition or replacement of a sub-processor. The customer may object to the change on reasonable data protection grounds by notifying Cyberact in writing within that notice period. If the matter cannot be resolved, the customer may cancel its subscription before the change takes effect. The subscription then ends at the end of the paid period, and the paid period is not refunded unless the law requires it.
Cyberact imposes data protection obligations equivalent to this agreement on each sub-processor by contract, and remains liable to the customer for the sub-processor meeting them.
8. Data subjects' rights
Cyberact helps the customer answer data subjects' requests (Chapter III of the GDPR) insofar as the nature of the processing allows. In the service, the customer can itself:
- export all of one person's data as a machine-readable file (JSON)
- delete a person and all of their data
- export the training log and the list of people as CSV files from the manager console
Other requests, such as correcting data, Cyberact carries out at the customer's request. If a data subject sends a request directly to Cyberact, Cyberact passes it to the customer without delay and does not answer it itself unless the customer asks it to.
9. Help with other obligations
On request, Cyberact gives the customer the information it needs for assessing security, notifying personal data breaches, data protection impact assessments and prior consultation (GDPR Articles 32 to 36), taking into account the nature of the processing and the information available to Cyberact. This agreement, its annexes and the privacy notice are written partly for this purpose.
10. Personal data breaches
Cyberact notifies the customer of a personal data breach without undue delay after becoming aware of it and confirming that it concerns the customer's personal data. The customer is responsible for its own notification to the supervisory authority (GDPR Article 33). The notice goes to the customer's main admin by email.
The notice says what happened, which people and what data it concerns and roughly how many, its likely consequences, what has been done about it, and whom to contact. Where not everything is known yet, the information is given in phases as it becomes available.
Cyberact acts at once to limit the harm of a breach and records every breach.
11. Returning and deleting data
The customer can export its data at any time: the training log and the list of people from the manager console, and one person's data from the users page. All of the organisation's data as one file is available on the users page once access has ended, and before that on request at support@cyberact.io.
When paid access ends, the data is kept for 12 months, so that there is evidence for a full annual audit cycle and the customer can carry on if it subscribes again. The main admin gets a reminder email 30 days before deletion. After that the customer's personal data is deleted, unless a longer period has been agreed or the law requires the data to be kept. If the customer asks for its data to be returned after the agreement has ended, Cyberact delivers it within a reasonable time, and in any case within 30 days of the request. If the organisation is disabled, the data is deleted after 90 days.
The customer can ask for the data to be deleted sooner at support@cyberact.io. Deleted data is gone from the backups within 14 days at the latest. In the access log a deleted person's email address is replaced with an identifier, and the buyer's name and email address are removed from the order records.
12. Audits
On request, Cyberact gives the customer the information needed to show that the obligations of this agreement are met, such as a description of the security measures, the sub-processors and the processing.
If that information is not enough, the customer, or an auditor it mandates who is bound by confidentiality, may audit the processing. An on-site audit is only by separate agreement, with at least 30 days' notice, and at the customer's cost, including Cyberact's reasonable costs. It takes place during normal business hours, at most once every 12 months unless a data breach or an authority requires otherwise, and must not put other customers' data or the security of the service at risk.
13. Transfers outside the EU and EEA
The customer's account and training data is kept in the EU, in Hostinger's data centre in Germany. Cyberact does not itself transfer it outside the EU or EEA. Hostinger's own sub-processors, such as its content delivery network and mail relay, may however process technical data and messages outside the EU and EEA, and those transfers are based on the European Commission's standard contractual clauses. The transfers below apply as well.
Stripe may transfer the buyer's and billing data to the United States. Those transfers are based on the European Commission's standard contractual clauses and the EU-U.S. Data Privacy Framework.
For the manager console's AI summary, Anthropic receives only the organisation's aggregated figures (annex 2). Anthropic may process them outside the EU and EEA, for example in the United States, and such transfers are based on the European Commission's standard contractual clauses. The customer can ask for AI to be switched off, and nothing is sent after that.
14. Liability
The parties' liability to each other follows the limits of liability in the terms of use (https://cyberact.io/terms). This does not limit data subjects' right to compensation under Article 82 of the GDPR.
15. Term and precedence
This agreement is in force for as long as Cyberact processes personal data on the customer's behalf. Where this agreement and the terms of use conflict on the processing of personal data, this agreement prevails.
Cyberact may update this agreement in the same way as the terms of use, but a change must not lower the protection of personal data. We tell the main admin of changes by email at least 30 days before they take effect.
16. Annex 1: Technical and organisational measures
- The server and database are at Hostinger in the EU, in a data centre in Germany.
- All traffic is encrypted (HTTPS), and browsers are told to use encrypted connections only (HSTS).
- Sign-in is by one-time code, with no passwords. A code is valid for 10 minutes, only a keyed hash of it is stored, and guesses are limited.
- The session cookie cannot be read by scripts (HttpOnly) and is sent only over encrypted connections. A session ends after a week unused, and after 30 days at the latest.
- Access is based on roles (learner, manager, admin). The organisation is always read from the session, never from the request, so a user cannot see another organisation's data.
- The access log records sign-ins, failed sign-ins, changes to access rights, invitations, exports and deletions. It is kept for 24 months.
- IP addresses are stored only as keyed hashes.
- The database, the sessions and the lesson content are outside the web root, where no web address reaches them.
- The database is backed up every day. Each backup's integrity is checked, it is readable only by the server account, and backups are kept for 14 days.
- Answers are graded on the server, correct answers are never sent to the browser in advance, and the server decides which lessons a user may open.
- Sign-in, sign-up, the APIs, exports and deletions are rate-limited, and every change needs a CSRF token and the same origin.
- The pages load no scripts, fonts or other content from third parties, and there is no analytics or tracking.
- Deleted data is overwritten in the database.
17. Annex 2: Sub-processors
- Hostinger — server, database, backups and email. The server is in Hostinger's data centre in Germany (Frankfurt), in the EU. Under Hostinger's terms of service and data processing addendum, the contracting party is Hostinger International Ltd, 61 Lordou Vironos, 6023 Larnaca, Cyprus. Hostinger describes its data integrity and backups on its own page (https://www.hostinger.com/support/the-most-frequently-asked-questions-about-hostinger/#h-data-integrity-and-backups).
- Stripe — payments, subscriptions, invoices and the calculation of VAT (Stripe Tax). The contracting party is Stripe Payments Europe, Limited, Ireland. Stripe processes only the buyer's and billing data: name, email address, billing address, the company's VAT number and payment method details. Stripe receives no training data. Stripe describes its security at https://docs.stripe.com/security and its privacy practices at https://stripe.com/privacy
- Anthropic — the language model that writes the manager console's summary when AI is in use. Anthropic receives only the organisation's aggregated figures, such as numbers of people and completions and shares: no names, email addresses, user identifiers, organisation name or text written by learners. Figures for a group are sent only for groups of five or more, and the management body's figures only when it has at least three members. Because the figures of a small group can sometimes say something about one person, Anthropic is listed as a sub-processor. AI is on by default for organisations, and it can be switched off for the whole service or for one organisation. Under Anthropic's commercial terms, the contracting party for customers in the EEA is Anthropic Ireland, Limited, Ireland. Anthropic may also process the data outside the EU and EEA, for example in the United States. Anthropic's data processing addendum: https://www.anthropic.com/legal/data-processing-addendum
The daily quiz reminder is delivered by the push service of the browser's maker (for example Google, Mozilla, Apple or Microsoft). Its content is encrypted with the browser's key and contains no name, email address or results. The user's browser chooses that push service, not Cyberact, so it is not a sub-processor.
The same list is in the privacy notice (https://cyberact.io/privacy).
18. Contact
Questions, requests and notices about this agreement: support@cyberact.io.