In effect from 1 August 2026
Set out below is the information gathered when you buy from CyberThreat Help, what it gets used for, and what it never will be. CyberThreat Help is a brand run by Fortify 24x7, which acts as the data controller here.
What we collect from you
- Contact and account details: your name, business name, email address, and the details you give us when raising a case.
- Purchase records: which lines you bought, in what quantity, and when. Payment card details are collected and held by Stripe, not by us. What reaches us is the card type and its final four digits, the same detail printed on a receipt.
- Site usage: standard web server records including address, browser type, and pages requested. No advertising trackers run on these pages, and no audience data is sold.
What we collect from the services
Operating the services means processing technical information from the systems you have asked us to protect. Depending on the lines you buy, that can include device names and health, user account identifiers, security event records, mail metadata and, where a message is judged malicious, its content, plus the backups themselves.
Backup content is your data. We hold it encrypted, we restore it when you ask us to, and we do not read it. Access by our staff to the content of a backup happens only when you request a restore or when investigating a fault, and it is logged.
Why we hold it
- To deliver the services you have bought and to keep them working.
- To detect and respond to security events on your behalf.
- To bill you, and to keep the accounting records the law requires.
- To answer your cases and improve how we run the desk.
Who else sees it
The platforms that deliver these services process data on our instruction as our subprocessors. Those are SentinelOne, Fluency, ThreatLocker, Ironscales, N-able, Addigy, Zimperium, Actifile, and Dropsuite. Payment processing is handled by Stripe. Support cases are recorded in our service management system.
Selling personal information is not something we do, nor sharing it for advertising. We disclose it to law enforcement only where we are legally required to, and where we are permitted to tell you that we have, we will.
How long we keep it
Account and billing records stay with us while you remain a customer, and afterwards for the span our bookkeeping and tax obligations require. Security event records are retained for the window described on the relevant manual entry. Backup content is held for the retention set on your subscription, then removed after cancellation on the schedule we put in writing to you.
Your rights
You may ask what we hold about you, ask for it to be corrected, ask for it to be deleted where we are not required to keep it, and ask for a copy in a portable form. Write to support@cyberthreat.help and we will respond within thirty days. California residents have specific rights under the CCPA, including the right not to be discriminated against for exercising them, which we honour.
Security of what we hold
Data in transit is encrypted. Backups are encrypted before they leave your systems. Access by our staff is role based, individually accountable, and logged. If we suffer a breach affecting your data, we will tell you promptly and tell you what we know rather than waiting until the account is tidy.
Cookies
This site uses only what is needed to make it work. Your selected coverage is held in your own browser storage so it survives a page reload, and your portal session token is held the same way. Neither is used to profile you and neither is shared.
Contact
Privacy questions go to support@cyberthreat.help.