Privacy
Privacy notice
This notice explains what personal data Cyberact processes, why and on what legal basis, how long it is kept, who can see it and who processes it for us, and how you can use your rights. It is given under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
Version 7 October 2026
1. Controller and contact
- Cyberact, Business ID 3493670-4, VAT number FI34936704
- Email: support@cyberact.io
Send any question or request about your personal data to support@cyberact.io.
2. What this notice covers
The public site cyberact.io, the shop at cart.cyberact.io, the help centre at docs.cyberact.io and the service at app.cyberact.io. It also covers the pre-release copy at demo.cyberact.io, which only Cyberact's own administrators can use.
Anyone can sign up for the free plan. Paid plans are bought as subscriptions, and Stripe processes the payments. An organisation can add users to the service and invite them.
We use no analytics, no tracking, no advertising, and no third-party scripts or fonts. Everything on these pages is served from our own server.
The service is not intended for children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, write to support@cyberact.io and we will delete it.
3. When Cyberact is the controller, and when the processor
When an organisation, such as your employer, has taken Cyberact into use and added or invited you, we process your account and your training data on the organisation's behalf and on its instructions. The organisation is then the controller and Cyberact the processor. This is agreed in the data processing agreement (https://cyberact.io/dpa), which is part of the terms for organisation customers. The organisation decides why, and on what legal basis, it trains its people; ask your organisation about that.
Cyberact is the controller itself when you use the service with your own account (the free plan or the Individual plan), when you buy a subscription, when you join the waitlist and when you use the public site. We are also the controller of the data we use to protect the service against misuse, and of a business customer's billing and contact details.
What follows applies in both cases. Where Cyberact is the processor, the organisation has the final say on the legal basis and on how long data is kept; the periods given here are the service's defaults.
4. User accounts and sign-in
You can sign up yourself with an email address, or an organisation adds you and sends you an invitation. For each account we store:
- email address
- name, if one was given
- organisation, department if the organisation uses departments, role (learner, manager or admin), and whether the account is active or disabled
- when the account was created and when you last signed in
- invitations: who was invited, with which role, who sent the invitation, and when it was sent, accepted or withdrawn
You sign in with a one-time code sent to your email. The code is valid for 10 minutes, and the server keeps only a keyed hash of it. There are no passwords, and none are stored. When you sign up yourself, nothing is written to the database until you have confirmed your address with the code.
We use the details to run your account, sign you in, manage who may see what, and send messages about the service.
Legal basis: when you use the service with your own account, the processing is necessary to perform our agreement with you (GDPR Article 6(1)(b)). When your organisation added you, we process the data on the organisation's behalf under the data processing agreement.
The details are kept in a database on our server, outside the web root.
5. Training data and progress
Your progress is saved on our server, so that it follows you from one device to another and so that your organisation can show that its people have been trained. We store:
- completed lessons, with their results, attempts and dates
- answers to questions: the lesson and question, whether the answer was right, how long it took and the day. Answers are graded on the server.
- the memory bank's review data: when a question is next due for review and how its reviews have gone
- daily quiz results
- the profile: XP, the streak, streak freezes, boss battle results, settings, and whether you have joined the leaderboard
- when you ask for a paid plan in the app: which feature you asked at, and which plan
Who can see it: you see your own progress. The organisation's main admin manages its users and can export one person's data, for a data protection request, for example. On the Platform + manager console + audit and Enterprise plans, the organisation's managers see each person's completions and results in the manager console. They can export the training log, which the organisation keeps as its training record and as evidence for audits. The leaderboard shows, within your own organisation only, the people who have joined it themselves: name, points and streak, never an email address. Cyberact's administrators see the data when that is needed to run the service or to help a customer.
We use the data to open lessons, grade answers, schedule reviews, run the leaderboard and produce the manager console's reports. We do not use training data for marketing. Your organisation decides how it uses its training record.
The legal basis is the same as for the account: the data of your own account is processed under our agreement with you (Article 6(1)(b)), and the data of users an organisation added is processed on the organisation's behalf.
Your browser keeps a copy of your progress, so that the app keeps working through a short loss of connection. Answers given offline wait in the browser and go to the server when the connection is back.
6. Manager console summaries and AI
The manager console's summary is put together from the organisation's figures, such as the numbers of people and completions, trends, areas of competence and coverage of the regulations. The aggregate contains no names, email addresses, user identifiers or text written by learners. Groups of fewer than five people are merged, and the management body's figures are sent only when it has at least three members.
When AI is in use, the aggregate is sent to Anthropic's language model, which writes the summary from it. AI is on by default for organisations and off for personal accounts. An organisation can ask for it to be switched off at support@cyberact.io, and the change is recorded in the organisation's access log. The summary is then compiled from the same figures by fixed rules, and nothing is sent.
7. Content made with AI
The content of the service is produced wholly or partly with artificial intelligence (AI): the lesson texts, questions and explanations, the narration, the images, animations and videos, and the manager console's summaries. The narration voices are synthetic, AI-generated voices, not recordings of real people.
The lessons, narration and other content are made in advance, before anyone studies them. No user's personal data, answers or progress go into making them, and none is sent to the AI tools used to make them. We do not use your personal data or your answers to train AI models.
The terms of use explain what this means for the accuracy of the content (https://cyberact.io/terms).
8. Emails
We send email only about using the service:
- sign-in and confirmation codes, and a welcome message
- invitations to an organisation
- reminders: a manager's reminder to a learner who has not used the service for 30 days, and reminders that a trial or access is ending or that a 12-month subscription is about to renew
- billing messages: the order confirmation, notice that a subscription was cancelled, continues or has ended, and instructions when a payment fails
- notices before deletion: to the main admin 30 days before an organisation's data is deleted, and to the holder of a personal account 30 days before an unused account is deleted
The messages go through Hostinger's mail server from support@cyberact.io and noreply@cyberact.io. We send no newsletters or marketing email. For reminders we record when they were sent, so that the same message is not sent twice.
The legal basis is our agreement with you (Article 6(1)(b)). For users an organisation added, we send the messages on the organisation's behalf.
9. The daily quiz reminder
In your profile you can turn on a browser notification that reminds you of a daily quiz you have not done. It is off by default and applies to one device at a time. When you turn it on, we store your browser's push service address and encryption keys, the reminder's time, time zone and language, and when the reminder was turned on and last sent.
The notification travels through the push service of your browser's maker (for example Google, Mozilla, Apple or Microsoft). Its content is encrypted with your browser's key and contains no name, email address or results.
You can turn the reminder off at any time in your profile, and the details are then deleted. They are also deleted when you sign out and clear the device, or when your account is deleted.
The legal basis is your consent (Article 6(1)(a)), which you give by turning the reminder on and allowing notifications in your browser. This holds even when an organisation has added you to the service: the reminder is always your own choice, and the organisation cannot turn it on for you.
10. Subscriptions and payments
Paid plans are bought as subscriptions in Stripe's checkout. When you buy a subscription, we store:
- the buyer's name and email address, and the company's name
- the plan, the billing period, the amount, the subscription's status and period, and Stripe's reference numbers (customer, subscription, invoice and payment)
- whether the address or the organisation has had a subscription before, because the free trial is given only once
You give your card details, billing address and VAT number directly to Stripe: Cyberact never sees or stores card details. Stripe sends us event notifications, which we keep for 60 days so that each event is handled only once.
We use the data to deliver access, bill, manage the subscription and keep our accounts. The legal basis is our agreement (Article 6(1)(b)) and the legal obligation to keep accounts (Article 6(1)(c)).
Stripe's checkout page (checkout.stripe.com) is Stripe's own service, and it sets Stripe's own cookies. Stripe's Cookies Policy applies to them (https://stripe.com/legal/cookies-policy). Cyberact's own pages load nothing from Stripe.
11. The waitlist
When you join the waitlist, we store:
- your email address
- your company's name, if you give it
- how many people the training would be for, if you choose an option
- the language of the page (Finnish or English)
- the time you joined
We use these details to tell you by email when the service opens, and to plan the places in the pilot. We do not pass them on to anyone for their marketing.
The legal basis is your consent (GDPR Article 6(1)(a)), which you give by ticking the box on the form. You can withdraw it at any time by writing to support@cyberact.io, and we will remove you from the list. Withdrawing does not affect the lawfulness of what was done before.
The details are stored in a file on our server, outside the web root, so no web address reaches it. A notification with the same details goes to Cyberact's waitlist mailbox waitlist@cyberact.io for each new signup. The form never sends anything to the address that was entered.
Your browser also remembers that you joined: the details you entered are kept in your own browser's local storage, so the page can show on your next visit that you are already on the list. They do not leave your device, and you can remove them by clearing the site's data in your browser.
12. Security and preventing misuse
We protect the service against misuse, such as spam and guessing sign-in codes, and keep a record of who has signed in and who has changed access rights. For this we process:
- Waitlist rate limit: a hash of your IP address, never the address itself. Entries expire after an hour.
- Sign-in and sign-up rate limits: a keyed hash of your IP address and the email address a code was requested for. Entries are removed after a day.
- Known networks: when you sign in successfully, we store a keyed hash of the IP address and your organisation, so that sign-ins from a familiar network are not limited as tightly. The entry is removed 30 days after the last successful sign-in.
- Access log: sign-ins, failed sign-ins, code requests, invitations, sign-outs, changes to access rights, and data exports and deletions. Each entry holds the time, the event, the email address of whoever did it and of the account it concerned, and a keyed hash of the IP address. An address that asked for a code without having access is logged only as a keyed hash, not as the address itself. An organisation's managers see their own organisation's log.
- Server logs: our hosting provider Hostinger processes technical data, such as IP addresses and the times of requests, to deliver and protect the service. What the logs contain and how long they are kept is determined by Hostinger under its terms of service.
A keyed hash means the IP address is not stored as such, and it cannot be worked out from the hash without the server's secret key.
The legal basis is our legitimate interest in keeping the service and its users' data secure (GDPR Article 6(1)(f)).
13. Cookies and browser storage
The public site cyberact.io sets no cookies. The service uses:
- Session cookie (app.cyberact.io): keeps you signed in. It is set when you open the sign-in page. It is strictly necessary for the service you asked for, so it needs no consent. A session ends after a week unused, at the latest 30 days after you signed in, or when you sign out.
- Local storage: your language choice, a copy of your progress and settings, answers waiting to be sent to the server, and the fact that you joined the waitlist.
- Session storage: technical details, such as whether the page has already reloaded itself after an error. It is gone when you close the tab.
- The app's offline cache (service worker): the app's files, the narration and lessons you have opened, so the app works without a connection. No personal data goes into that cache.
- Stripe's checkout page (checkout.stripe.com) is Stripe's own service, and it sets Stripe's own cookies. Stripe's Cookies Policy applies to them (https://stripe.com/legal/cookies-policy). Cyberact's own pages load nothing from Stripe.
Signing out clears the app's cache from your device. Once every answer has reached the server, it clears the storage as well. We use no analytics, tracking or advertising cookies.
14. Processors and sub-processors
We do not sell personal data or give it to anyone for their marketing. We use these processors. For organisation customers they are sub-processors, and the same list is annex 2 of the data processing agreement.
- Hostinger — server, database, backups and email. The server is in Hostinger's data centre in Germany (Frankfurt), in the EU. Under Hostinger's terms of service and data processing addendum, the contracting party is Hostinger International Ltd, 61 Lordou Vironos, 6023 Larnaca, Cyprus. Hostinger describes its data integrity and backups on its own page (https://www.hostinger.com/support/the-most-frequently-asked-questions-about-hostinger/#h-data-integrity-and-backups).
- Stripe — payments, subscriptions, invoices and the calculation of VAT (Stripe Tax). The contracting party is Stripe Payments Europe, Limited, Ireland. Stripe processes only the buyer's and billing data: name, email address, billing address, the company's VAT number and payment method details. Stripe receives no training data. Stripe describes its security at https://docs.stripe.com/security and its privacy practices at https://stripe.com/privacy
- Anthropic — the language model that writes the manager console's summary when AI is in use. Anthropic receives only the organisation's aggregated figures, such as numbers of people and completions and shares: no names, email addresses, user identifiers, organisation name or text written by learners. Figures for a group are sent only for groups of five or more, and the management body's figures only when it has at least three members. Because the figures of a small group can sometimes say something about one person, Anthropic is listed as a sub-processor. AI is on by default for organisations, and it can be switched off for the whole service or for one organisation. Under Anthropic's commercial terms, the contracting party for customers in the EEA is Anthropic Ireland, Limited, Ireland. Anthropic may also process the data outside the EU and EEA, for example in the United States. Anthropic's data processing addendum: https://www.anthropic.com/legal/data-processing-addendum
Hostinger processes the data only on our behalf, under its data processing addendum. Sign-in codes, invitations and other messages are sent through Hostinger's mail server, and waitlist notifications arrive in a Hostinger mailbox.
Stripe processes payment data on our behalf under its Data Processing Agreement. For some purposes of its own, Stripe processes data as an independent controller, for example to prevent fraud and money laundering, to meet its other legal obligations, and to analyse and improve its services; Stripe's own privacy policy applies to that processing. The same applies to the VAT calculation in Stripe Tax.
The daily quiz reminder is delivered by the push service of the browser's maker (for example Google, Mozilla, Apple or Microsoft). Its content is encrypted with the browser's key and contains no name, email address or results. The user's browser chooses that push service, not Cyberact, so it is not a sub-processor.
We disclose data to authorities only when the law requires it.
15. Transfers outside the EU and EEA
Account and training data is stored on a server in the EU, in Germany. Hostinger's data processing addendum does, however, list sub-processors in the United States, among them Cloudflare and MailChannels. Where data is transferred outside the EU or EEA through them, the transfer is based on the European Commission's standard contractual clauses.
Stripe may transfer payment data outside the EU and EEA, for example to Stripe, LLC in the United States. Under Stripe's Data Processing Agreement, such transfers are based on the European Commission's standard contractual clauses and the EU-U.S. Data Privacy Framework, under which Stripe, LLC is certified.
Anthropic may process the manager console's aggregate outside the EU and EEA, for example in the United States. Under Anthropic's data processing addendum, such transfers are based on the European Commission's standard contractual clauses. The aggregate holds no names or other identifiers.
16. Users outside the EU, including the United States
We give every user the protection of the GDPR, wherever they live. If you use the service from outside the EU and EEA, for example from the United States, your data is transferred to the EU and stored in Germany, as described above.
We do not sell or share personal information, as those terms are defined in US state privacy laws such as the California Consumer Privacy Act, and we do not use it for targeted advertising or for profiling. Because we do no tracking, nothing is tracked whether or not your browser sends a Do Not Track or Global Privacy Control signal.
You can use the rights described below wherever you live, and we will not treat you differently for using them. Where the law of your home country or state gives you further rights, we honour them too.
17. How long we keep data
The service's and the waitlist's deletions run every night as a scheduled job.
- A company's user accounts and training data (completions, answers, review data, departments, invitations and the organisation's summaries): for as long as your organisation's agreement lasts. When its paid access ends, the data is kept for 12 months, so that there is evidence for a full annual audit cycle and the organisation can subscribe again and carry on. The main administrator gets a reminder email 30 days before deletion, and then the data is deleted, unless a longer period has been agreed. If the organisation is disabled at its own request or by us, the data is deleted 90 days after it was disabled. Your organisation can also delete your account and data at any time.
- A personal account and its training data: for as long as the account is used. When a personal subscription ends, the account moves to the free plan and keeps its progress. A personal account with no sign-in for 24 months is deleted; we send a warning email 30 days before. An account is never deleted while it has a subscription running.
- An invitation that is withdrawn or expires unused: 90 days, if the person has not joined the organisation.
- The daily quiz reminder: until you turn it off, sign out and clear the device, or your account is deleted.
- Subscriptions and payments: Stripe's event notifications for 60 days. When an account or organisation is deleted, the buyer's name and email address are removed from our order records. Invoices and payment vouchers are kept at Stripe and in our accounts for at least six years from the end of the year in which the financial year ended, as the Finnish Accounting Act requires.
- Waitlist and its notification emails: until we have told you the service is open, at most 24 months after you joined, or until you withdraw your consent.
- Sign-in code: valid for 10 minutes; a used or expired code no longer works.
- Session: at most 30 days.
- Rate limits: an hour on the waitlist, a day at sign-in and sign-up.
- Known networks: 30 days from the last successful sign-in.
- Access log: 24 months from the event. When a user is deleted, their email address in the log is replaced with an identifier.
- Backups: the database is backed up every day, and each backup is kept for 14 days. Deleted data is gone from the backups within 14 days at the latest.
- Browser storage: on your device until you clear it or sign out.
18. Your rights
Under the GDPR you have the right to:
- know whether we process your data, and get a copy of it (Article 15)
- have inaccurate data corrected (Article 16)
- have your data erased (Article 17)
- have the processing restricted (Article 18)
- receive the data you gave us in a machine-readable format and have it moved elsewhere, when the processing is based on consent or an agreement (Article 20)
- object to processing based on our legitimate interest (Article 21)
- withdraw your consent at any time (Article 7(3))
We make no automated decisions about you and do no profiling that has legal or similarly significant effects on you.
19. How to use your rights
Send your request to support@cyberact.io from the email address it concerns. We may ask for more information to confirm who you are. We answer within one month. If requests are many or complex, the period can be extended by two further months, and we will tell you if it is.
If your organisation added you to the service, the organisation is the controller, so address your request to it first. If you send it to us, we will pass it to your organisation and help it answer.
You can remove the copy of your progress in your browser yourself, in your browser's settings or by signing out.
20. Right to complain
If you consider that the processing of your personal data breaks data protection law, you can complain to the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, https://tietosuoja.fi). We would appreciate the chance to put things right first, so please contact us too.
21. How we protect the data
- All traffic is encrypted (HTTPS), and browsers are told to use encrypted connections only (HSTS).
- The database, the sessions, the lesson content and the waitlist are kept outside the web root, where no web address reaches them.
- There are no passwords; sign-in codes and IP addresses are stored only as keyed hashes.
- Access is based on roles, and the organisation is always read from the session, so nobody sees another organisation's data.
- Answers are graded on the server, and the server decides which lessons a user may open.
- Sign-ins, changes to access rights, exports and deletions are recorded in the access log.
- Sign-in, sign-up, exports and deletions are rate-limited.
- The database is backed up every day, and backups are kept for 14 days.
- The pages load nothing from third parties.
The full list is annex 1 of the data processing agreement (https://cyberact.io/dpa).
22. Changes to this notice
We update this notice when the service or the processing changes. The current version is always on this page, with the date of the last update at the top.