Your personal data which we collect and obtain
1.This Privacy Statement (Statement) sets out the basis on which Cyber Cert Labs Limited (Cyber Cert Labs, we, us, our) of 2 Knockrabo Drive, Mount Anville Road, Dublin 14, Dublin 14, D14 N2T6, Ireland, processes personal data which we collect relating to you or which you provide to us. The information provided by you will be held by Cyber Cert Labs as a data controller unless otherwise stated.
2.This Statement applies to Cyber Cert Labs' website and to the Attestra AI Platform and the Attestra Academy (referred to collectively as the “Platform”). The Attestra AI Platform is a software-as-a-service platform that provides tools and workflows to assist manufacturers with compliance under the Cyber Resilience Act. The Attestra Academy is an online training platform that delivers training content relating to the Cyber Resilience Act, including video lessons, platform demonstrations, knowledge-check quizzes, and also functions as a Resource Hub with guidance and links to official sources. Where an individual accesses or uses the Platform on behalf of their employer or another organisation, Cyber Cert Labs will ordinarily process that individual's personal data as a data processor on behalf of the relevant organisation (as data controller) in accordance with our Data Processing Agreement. In such circumstances, the relevant organisation's privacy notice will govern the processing of your personal data and you should direct any queries or requests regarding your personal data to that organisation. Cyber Cert Labs acts as a data controller in respect of personal data collected through our websites, and in limited circumstances where an individual subscribes to the Platform in their own capacity and not on behalf of an employer or other organisation.
3.Cyber Cert Labs collects personal data from website users, as well as users of the Platform. We may also collect personal data from those who do business with us. In some cases, this means also processing personal data relating to former/prospective employees/directors or agents, suppliers, business contacts and shareholders. If the data we collect are not listed in this Statement, we will give individuals (when required by law) appropriate notice of which other data will be collected and how they will be used.
4.We may collect and process the following personal data about you:
Category of Personal Information | Types of Personal Information |
|---|
Contact, Identity and Business Role Data | We may collect the following contact, identity and business role data about you, whether provided directly by you (including via forms on the website or correspondence with us) or obtained in the course of our business relationship with you: - Name;
- pronoun;
- email address;
- telephone number (business and, where provided, personal);
- job title, professional role and seniority;
- organisation/company name;
- business address;
- username and online identifiers;
- current employer and business location;
- records of business interactions,
- meetings and correspondence;
- referral or introduction source;
- client profiling data; and
- miscellaneous other personal identifiers.
|
Commercial Information | - Account management information;
- Project support and delivery related personal data;
- Commercial history of service delivery; and
- commercial emails between you and us when sent to a dedicated mailbox or via other electronic communication means such as for administering payments and billing related issues, including follow-up; and records of services delivered or proposed.
|
Supplier and Contractor Data | - Contact, identity and business role data as described above, together with the following data specific to the supplier or contractor relationship:
- bank account or payment details (for invoicing purposes);
- Contract and engagement terms;
- Insurance and compliance documentation details;
- Professional qualifications or certifications (where relevant to the engagement);
- Supplier and contractor due diligence records;
- Performance review data;
- Subcontractor appointment; and
- Procurement records.
|
Marketing, Communications and Third-Party Source Data | - Mailing list subscription data;
- marketing consent records and opt-out records;
- event and webinar registration data (including name, job title, organisation and contact details);
- social media profile data used for business development purposes;
- information received from analytics and advertising partners; and
- marketing lead data obtained from third-party sources.
- From time to time, we may also obtain personal data from other sources aside from you, such as through recruitment platforms, analytics and advertising partners, event partners, references you provide, or marketing leads.
|
Website Usage Data | - Device information (where you access the website via a mobile device or other device);
- Log information including traffic data, weblogs, analytical data and the resources you access.
- Approximate location information inferred from your IP address or device settings; and
- Cookies and similar tracking technology data. See our Cookie Policy at https://attestra.ai/legal/cookie-policy for further information.
|
Attestra AI Platform Data | - user account data (including names, email addresses and professional roles);
employer or organisation name. |
Attestra Academy Data | - Learner Names;
- Email Addresses;
- Employer or Organisation Name;
- Training Progress Data;
- Quiz Results; And
- Completion Records.
|
How and why we process your personal data
The following table demonstrates what legal basis Cyber Cert Labs Limited relies on when we process personal data, and for what purpose we process personal data:
Legal bases and purposes
Purpose(s) | Legal Basis | Indicative Personal Data Processed |
|---|
Managing our Commercial Relationship Standard email communications with you relating to work and work products including support incidents. Personal data may be ingested through meeting notes, on calls with you, or when we visit your business locations. | Necessary for the performance of a contract to which you are a party The personal data processing is necessary for the purpose of us providing our services to you or your organization. | - Contact, Identity and Business Role Data
- Commercial Information
- Marketing, Communications and Third-Party Source Data
- Supplier and Contractor Data
- Attestra AI Platform Data
- Attestra Academy Data
|
Access to the website To provide you with access to the website and to enable you to use the website. Improving website functionality and efficiency To provide, improve, test and monitor the effectiveness of the website. To monitor metrics such as total number of visitors, traffic data and demographic patterns. Responding to Queries and Complaints To process and respond to any queries or complaints you submit to us via the website. Client Profiling To build up a profile of you as a client and assess your suitability for certain services which we offer. Advertising and Marketing To provide you with advertising and marketing material relating to services which we offer. | Necessary for the purposes of the legitimate interests pursued by us The processing of these categories of personal data are necessary for the purposes of providing our services. | - Website Usage Data
- Marketing, Communications and Third-Party Source Data
- Contact, Identity and Business Role Data
- Commercial Information
|
Special Category Personal Data Cyber Cert Labs Limited may process a limited amount of special category personal data when permitted by data protection laws with your consent. | Consent You give your full express consent to have your data processed by us. | Health/medical information (such as disability or dietary requirements/allergies such as for events). |
Legal Claims To file legal proceedings. To investigate, establish, exercise or defend a legal claim. To settle legal claims. | To Defend, Establish or be a Party to Legal Claims We may process your personal data as necessary in order for us to establish, investigate, exercise or defend a legal claim to which you are a party. | - Website Usage Data
- Marketing, Communications and Third-Party Source Data
- Contact, Identity and Business Role Data
- Commercial Information
- Attestra AI Platform Data
- Attestra Academy Data
|
AI, Analytics and Improvement
1.Use of Artificial Intelligence: The Platform utilises artificial intelligence technologies to process data, including personal data, for the purposes of providing and improving our services. AI is used to analyse data (including personal data) which is ingested into the Platform to generate insights, reports, and recommendations for you.
2.Notwithstanding the use of AI within the Platform, we do not engage in automated decision-making (including profiling) which produces legal effects concerning you or similarly significantly affects you, as contemplated by Article 22 of the General Data Protection Regulation. All decisions of material significance are subject to meaningful human oversight and intervention.
3.Product Analytics: We process usage data collected through PostHog Inc on the basis of our legitimate interest in understanding how users interact with the Platform and improving the service. You may opt out of product analytics data collection by contacting us at the address set out below. Enterprise customers may request that product analytics be disabled for their organisation's user accounts.
4.AI Model Improvement: We may use Platform usage and interaction data in aggregated and anonymised form (such that it no longer constitutes personal data) to improve the performance and accuracy of our AI models. Customer data is not used in identifiable form to train AI models without the customer's prior consent.
Who we share your personal data with
We may disclose your personal data to some or all of the following recipients:
Recipient(s)
- Regulatory authorities and law enforcement agencies (where we are under a duty to disclose or share your personal data in order to comply with any legal or regulatory obligation or request)
- External advisors e.g., lawyers, accountants and auditors (as necessary or desirable to protect our legitimate and legal interests).
- Service providers for logistical and IT service purposes, including hosting, security, analytics, marketing, communications, CRM, applicant-tracking, and professional advisers, bound by contracts and confidentiality obligations.
- Subconsultants, subcontractors and other project delivery partners, to the extent necessary for the delivery of the services engaged by our clients.
- Insurance providers and brokers, to the extent necessary for the management of professional indemnity and other insurance arrangements.
- Client organisations and their representatives, where personal data relating to project stakeholders, site visitors or building occupants is shared in connection with project delivery.
- Event management and registration platforms, where you register for a Cyber Cert Labs event or webinar.
- Marketing and CRM platform providers, where we use third-party software to manage our business development and marketing activities.
- Product analytics provider, called PostHog Inc., as our product analytics sub-processor, which processes usage data on our behalf to provide product analytics services. PostHog hosts data within the European Union (PostHog Cloud EU). PostHog's data processing agreement is available at posthog.com/dpa.
Storage and transfers of your personal data
5.Platform data is hosted exclusively within the European Union, on servers located in Germany (Hetzner) and Finland (Helsinki). Where we transfer your personal data outside the European Economic Area ("EEA") or United Kingdom in connection with other processing activities, we ensure an adequate level of protection by relying on one or more of the following: adequacy decisions recognised by the European Commission (including, where applicable, the EU-US Data Privacy Framework); Standard Contractual Clauses adopted by the European Commission, together with transfer impact assessments and supplementary safeguards as required; or any other mechanism approved by competent data protection authorities. We hold all of our personal data in accordance with appropriate standards of IT security. If you would like to find out more about the appropriate safeguards that we have in place, you can contact us at privacy@cybercertlabs.com or by writing to us at 2 Knockrabo Drive, Mount Anville Road, Dublin 14, Dublin 14, D14 N2T6, Ireland
6.Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to or from the website; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access.
How long we keep your personal data for
7.In general, we expect to keep your personal data for as long as is necessary for the purposes for which it was collected. However, please note that in certain circumstances we may hold certain of your personal data for a longer period, for example, (a) if we are processing an ongoing claim or dispute; (b) if we reasonably believe that a law or regulator may require or expect us to preserve your personal data; (c) if we have a valid contractual obligation to do so; or (d) if we have obtained your consent to a longer retention period. The retention period applicable to your personal data will depend on the nature of the data and the purpose for which it was collected. As a guide, the following retention periods generally apply:
8.Project and client engagement records: Personal data forming part of project records, client contracts, technical deliverables and related correspondence is generally retained for 12 years from practical completion of the relevant project. This reflects the limitation period for claims arising under deed and our professional indemnity insurance requirements.
9.Financial and regulatory records: Invoicing, payment, tax and customer due diligence records are retained for 5 to 6 years from the end of the relevant financial year, relationship or transaction, in line with applicable tax, anti-money laundering and company law obligations.
10.Marketing and business development records: Contact details, CRM records, mailing list data and marketing consent records are retained for up to 3 years from your last interaction with us or from the withdrawal of your consent, whichever is earlier.
11.Event and webinar records: Registration and attendee data is retained for up to 2 years from the date of the relevant event. Any special category data (such as dietary or accessibility requirements) is deleted as soon as reasonably practicable after the event.
12.Website and digital data: Website usage data, analytics data and cookie data is retained for up to 13 months from the date of collection. Website contact form submissions are retained for 12 months.
13.Platform subscription data: Where Cyber Cert Labs acts as a data controller in respect of Platform user account data, such data is retained for the duration of the subscription and for a period of 30 days following termination or expiry of the subscription to facilitate data export. After the 30-day export window, customer data is scheduled for permanent deletion. Data is purged from backups within 90 days of deletion. Cyber Cert Labs does not provide long-term data archival services. Customers requiring extended retention (including to satisfy the 10-year retention obligation under Article 13 of the Cyber Resilience Act) are responsible for exporting and retaining their own data.
14.Product analytics data: Usage data collected through PostHog is retained for a maximum period of 24 months from the date of collection, after which it is automatically deleted.
15.Security, access and visitor records: CCTV footage, visitor logs and building access records are retained for short periods (typically 30 days to 12 months), unless linked to a security incident or investigation, in which case they are retained until the matter is resolved.
16.We may retain your personal data for longer than the periods indicated above where: (a) we are processing an ongoing claim or dispute; (b) we reasonably believe that a law or regulator may require or expect us to preserve your personal data; (c) we have a valid contractual obligation to do so; or (d) we have obtained your consent to a longer retention period.
Linked websites
17.The website or our services may present links to other websites ("Linked Websites"). We are not responsible for the privacy statements or practices on Linked Websites. This Statement governs only personal data which Cyber Cert Labs Limited is a controller of. When accessing Linked Websites, you should read the privacy statement published on the relevant Linked Website. This Statement does not apply to Linked Websites. Please check the statements on such websites before you submit any personal data.
18.Our website contains links to other websites and resources provided by third parties for your convenience and information only. We accept no liability in connection with any Linked Website, or any contract entered into with any third party on or through a Linked Website. We have no control over the content of those websites or resources and accept no responsibility for them or for any loss or damage that may arise from your use of Linked Websites.
Your rights
You have a number of rights in relation to your personal data as set out in the table below subject to the exceptions, set out in applicable law.
Note that in certain circumstances these rights might not be absolute.
Right | Further Information |
|---|
Right of Access | You have the right to request a copy of the personal data held by us about you and to access the information which we hold about you. We will charge you for making such an access request where we feel your request is unjustified or excessive. |
Right to Rectification | You have the right to have any outdated or inaccurate personal data which we hold about you updated or corrected. |
Right to Erasure | In certain circumstances, you may also have your personal data deleted, for example if you exercise your right to object (see below) and we do not have an overriding reason to process your personal data or if we no longer require your personal data for the purposes set out in this Notice. |
Right to Restriction of Processing | You have the right to ask us to restrict processing your personal data in certain cases, including if you believe that the personal data we hold about you is inaccurate or that our use of your personal data is unlawful. If you validly exercise this right, we will store your personal data and will not carry out any other processing, other than processing your data in line with our retention periods until the issue is resolved. |
Right to Data Portability | You may request us to provide you with your personal data which you have given us in a structured, commonly used and machine-readable format and you may request us to transmit your personal data directly to another data controller where this is technically feasible. This right only arises where we process your personal data on the legal bases of your consent or where it is necessary to perform our contract with you. |
Right to Object | You have a right to object at any time to the processing of your personal data where we process your personal data on the legal basis of pursuing our legitimate interests. |
19.You can seek to exercise any of these rights by contacting us at the following address: privacy@cybercertlabs.com or by writing to Cyber Cert Labs Limited, 2 Knockrabo Drive, Mount Anville Road, Dublin 14, Dublin 14, D14 N2T6, Ireland.
20.We will provide you with information on any action taken upon your request in relation to any of these rights without undue delay and at the latest within one month of receiving your request. We may extend this up to 2 months if necessary however we will inform you if this arises.
21.Our lead regulatory Authority is the Irish Data Protection Commission which is based in Ireland. You have the right to lodge a complaint with the Irish Data Protection Commission with regards to us processing your personal data. You can contact the Data Protection Commission directly at:
Data Protection Commission 21 Fitzwilliam Square South Dublin 2 D02 RD28 Ireland | Phone: Email: | +353 57 868 4800 / +353 761 104 800 info@dataprotection.ie |
Changes to this notice
22.We may amend this Statement on occasion, in whole or part, at our sole discretion. Any changes will be posted on this page which will be kept up to date. Please check this Statement regularly for changes.
23.If at any time we decide to use your personal data in a manner significantly different from that stated in this Statement, or otherwise disclosed to you at the time it was collected, we will change this Statement, and you will have a choice as to whether or not we can use your personal data in the new manner.
Questions, comments and requests regarding this Statement are welcomed and should be addressed to our Data Protection Manager: privacy@cybercertlabs.com or by writing to Cyber Cert Labs Limited, 2 Knockrabo Drive, Mount Anville Road, Dublin 14, Dublin 14, D14 N2T6, Ireland.