Legal
Privacy notice
This is an honest, plain-English first draft written to match how this website actually behaves. It has not been reviewed by a lawyer, it does not constitute legal advice, and it is not yet a compliance statement under GDPR, UK GDPR, CCPA/CPRA, or any other regime. Have counsel review and adapt it — particularly the sections on legal basis, retention, international transfers and individual rights — before this page goes live.
1. Who we are
Backstop Cyber is a cybersecurity and compliance consulting practice operated by [FILL: registered legal entity name], [FILL: entity type and jurisdiction of registration], with a registered address at [FILL: registered address]. In this notice, “we”, “us” and “our” mean that entity. “You” means anyone who visits backstopcyber.com or sends us a message through it.
For the purposes of data protection law we are the controller of the personal data described below. Where we act as a processor instead — for example, when handling data inside a client’s environment during an engagement — that relationship is governed by the contract for that engagement, not by this notice. [FILL: confirm whether a Data Protection Officer or EU/UK representative is required and, if so, name them]
2. What we collect, and when
2.1 Information you type into the contact form
The contact form on our homepage is the only place on this website where you can give us information. When you submit it, we receive exactly the following:
| Field | Required | What it is |
|---|---|---|
| Name | Yes | The name you give us, up to 100 characters. |
| Work email | Yes | The address we reply to. We do not use it for anything else. |
| Company | Yes | Your organisation’s name, up to 100 characters. |
| Role | No | Your job title, if you choose to give it. |
| What brings you here | Yes | One of five fixed options, so we can route your message. |
| Message | Yes | Free text, up to 5,000 characters. Please see the warning below. |
Please do not put sensitive information in the message field. This form is an ordinary email pipeline, not a secure channel. Do not send credentials, secrets, personal health information, government identifiers, payment details, or unredacted findings from a live incident. If you are dealing with an active incident, call the number listed on our contact section instead. Once an engagement begins we will agree a secure channel with you.
2.2 Information collected automatically with your submission
When you submit the form we also record, and include in the notification email we send ourselves:
- Your IP address, taken from the
CF-Connecting-IPheader, used for abuse rate-limiting and included so we can investigate abuse. - The country Cloudflare associates with that IP address.
- The timestamp of the submission.
We also run a Cloudflare Turnstile check on the form. Turnstile is an
anti-bot challenge. It is served from
challenges.cloudflare.com and is the only third-party resource
this website loads at runtime. To decide whether you are a human it
inspects signals from your browser, and it sets its own storage on your
device for that purpose. We receive only a pass or fail result — we never
receive the underlying signals. Cloudflare states that Turnstile data is
not used for advertising or cross-site tracking; their description of it
governs, not ours.
2.3 Server and network logs
This site is hosted on Cloudflare Pages. Cloudflare records request logs for every page served — including IP address, timestamp, requested URL, user agent and referrer — as an ordinary part of operating a network and defending it against attack. Those logs are generated by Cloudflare under their own retention policy. We do not export them, aggregate them, build profiles from them, or use them for marketing.
3. Why we collect it
| Purpose | Data used | Basis [FILL: confirm with counsel] |
|---|---|---|
| To read your message and reply to it | Everything in §2.1 | Steps taken at your request prior to entering a contract; legitimate interests in responding to business enquiries |
| To keep the form from being abused by bots and spammers | IP address, country, Turnstile result | Legitimate interests in securing our own systems |
| To keep a record of what was agreed if we go on to work together | Correspondence | Contract; legal obligation where record-keeping is required |
That is the complete list. We do not use anything you send us to build a marketing profile, and submitting the form does not subscribe you to anything.
4. Who processes it on our behalf
We use a deliberately short list of sub-processors. Each one is listed here with what it actually does:
| Processor | Role | What it handles |
|---|---|---|
| Cloudflare, Inc. | Website hosting (Pages), CDN, DNS, bot protection (Turnstile), and the serverless function that receives the form | Request logs; your IP address; the contents of your submission in transit |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | The full contents of your submission, in order to deliver it to our inbox as an email |
| [FILL: mailbox provider, e.g. Google Workspace or Microsoft 365] | The inbox that receives and stores the message | The full contents of your submission, once delivered |
| [FILL: CRM, if you use one — delete this row if you do not] | [FILL] | [FILL] |
We do not sell personal information, and we do not share it with anyone outside this list except where we are legally compelled to. [FILL: confirm data processing agreements are executed with each processor above]
5. How long we keep it
- Enquiries that do not lead to work: kept in our inbox for [FILL: e.g. 24 months], then deleted. We keep them for that period so that a follow-up conversation months later has context.
- Enquiries that become engagements: retained for the life of the engagement and then for [FILL: e.g. 7 years] afterwards, in line with our contractual, tax and professional record-keeping obligations.
- Rate-limiting records: IP-keyed counters expire automatically within 10 minutes and are never written to durable storage unless a key-value store is bound, in which case they expire on the same schedule.
- Cloudflare request logs: retained by Cloudflare under their policy, not ours.
6. Cookies, analytics and tracking
This website sets no cookies of its own. It runs no analytics, no tag manager, no advertising pixels, no session recording, no heatmaps and no A/B testing tools. There is no consent banner because there is nothing to consent to. Fonts are the ones already on your device — nothing is fetched from a font CDN, so no third party learns that you visited.
The single exception is Cloudflare Turnstile, described in §2.2, which stores data on your device in order to tell humans from bots. It is loaded only when you scroll near the contact form, and never on the privacy or terms pages.
7. What we do not do with it
- We do not sell it, rent it, or trade it.
- We do not add you to a mailing list, newsletter or nurture sequence.
- We do not enrich it against third-party data brokers.
- We do not use it to train machine-learning models.
- We do not use it for advertising, retargeting or lookalike audiences.
8. Your rights, including deletion
Depending on where you live you may have the right to access a copy of the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and complain to a supervisory authority. Where we rely on legitimate interests, you can object at any time.
To ask us to delete your enquiry, send a message through the contact form, or write to the address in §13, saying that you want the enquiry deleted and giving us the email address you originally used so we can find it. We will delete it from our inbox and confirm when it is done. We aim to respond within [FILL: e.g. 30 days].
We do not charge for this, and we do not require an account, a form, or a reason. If we have to keep something — for example, a record we are contractually or legally required to retain — we will tell you exactly what and why. [FILL: counsel to confirm identity-verification process and any statutory response deadlines that apply]
9. International transfers
Our processors operate globally, and your submission may be processed on infrastructure located in [FILL: e.g. the United States]. If you are in the UK, EEA or Switzerland, that is a transfer outside your jurisdiction. [FILL: counsel to confirm the transfer mechanism relied upon — Standard Contractual Clauses, the UK Addendum, the EU–US Data Privacy Framework, or another basis — and name it here]
10. How we protect it
The site is served only over HTTPS with HSTS, uses a strict Content Security Policy that permits no arbitrary inline or third-party script, blocks framing entirely, and submits the form to an endpoint on our own origin. Submissions are validated and size-capped on the server, protected by a bot challenge, and rate-limited by IP address. Access to the destination inbox is limited to the people who need it and protected by multi-factor authentication.
None of that makes email a secure channel. Please re-read the warning in §2.1 before you type anything sensitive into the message field.
11. Children
This is a business-to-business website. It is not directed at children, we do not knowingly collect personal data from anyone under 16, and if we learn that we have, we will delete it.
12. Changes to this notice
If we change how the form works, add a processor, or start collecting anything new, we will update this page and change the version and date at the top before the change takes effect. Material changes will be described in a short note here rather than made silently.
13. How to reach us
The fastest route is the contact form. For privacy matters specifically, write to [FILL: privacy contact address, written as plain text — see the note in README about mailto: links and Cloudflare Email Address Obfuscation] or by post to [FILL: postal address].
If you are in the UK or EEA and you are not satisfied with our response, you can complain to your national data protection authority. [FILL: name the lead supervisory authority if one applies]