Privacy Policy
How I protect your personal information and respect your privacy rights
Sole Proprietorship Notice
CyberGapAudit is operated as a sole proprietorship. This means I personally handle all data processing activities and am directly responsible for protecting your privacy and security.
- email us
- Monday–Friday, 9:00 AM – 5:00 PM CET
Sole Proprietorship • Personal Data Protection Commitment
Introduction
Welcome to CyberGapAudit, a cybersecurity gap analysis platform designed to help organizations assess their cybersecurity posture against industry frameworks. This Privacy Policy explains how Devon Waller, operating as CyberGapAudit (“I,” “me,” “my,” or “CyberGapAudit”), collects, uses, processes, and protects your personal information when you use my website, platform, and services.
I am committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy applies to all users of my services, including visitors to my website, registered users, and customers who purchase my assessment services.
This Privacy Policy is designed to comply with applicable data protection laws, including the EU GDPR, California Consumer Privacy Act (CCPA), and Swiss FADP. I regularly review and update this policy to ensure continued compliance.
Information I Collect
I collect personal information that you voluntarily provide to me when you use my services. As a sole proprietorship, I personally handle all data collection and processing activities.
- Personal Information You ProvideName, email, company, billing details when you register, purchase, or contact me.
- Information Collected AutomaticallyIP address, browser/device metadata, pages viewed, and session identifiers via cookies and analytics.
- Information from Third PartiesAuthentication providers (Supabase), payment processors (Stripe), and email deliverability providers (Resend).
How I Use Your Information
I use your personal information primarily to provide, maintain, and improve my cybersecurity assessment services.
- Primary Service DeliveryRun assessments, generate reports, and deliver purchased outputs.
- Platform Improvement and AnalyticsAggregate usage metrics to improve quality and reliability.
- Legal and Compliance PurposesInvoicing, tax obligations, fraud prevention, and regulatory compliance.
- Marketing and CommunicationsTransactional emails always; marketing only with explicit opt-in.
Data Storage & Security
As a cybersecurity professional, I implement multiple layers of security to protect your personal information. Your data is stored securely using enterprise-grade cloud infrastructure.
- Data Storage InfrastructureSupabase (PostgreSQL) in EU region for user data; Stripe for payment tokens (PCI DSS Level 1).
- Security MeasuresTLS in transit, AES-256 at rest, row-level security, least-privilege access, 2FA for admin accounts.
- Data Backup and RecoveryDaily encrypted backups with 30-day retention and tested recovery procedures.
- Third-Party SecurityVendors reviewed for SOC 2 / ISO 27001 attestation and GDPR-compliant data processing agreements.
Data Sharing & Disclosure
I do not sell, rent, or trade your personal information to third parties for their marketing purposes.
- General PrinciplesMinimum necessary, contract-bound processing only.
- Service ProvidersSupabase, Stripe, Resend, Sentry — all under DPAs.
- Legal RequirementsCourt order, regulator request, or safety of persons.
- Business TransfersMerger or acquisition with notice and equivalent protections.
- Consent-Based SharingOnly with your explicit opt-in.
- Aggregated and Anonymized DataNon-identifiable statistics for research and marketing.
Data Retention
I retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce my agreements.
- Account InformationActive account lifetime + 2 years.
- Assessment Data7 years for professional liability recordkeeping.
- Payment InformationHeld by Stripe per their retention schedule; I retain receipts for 10 years (CH tax law).
- Website Usage DataAggregated analytics up to 26 months.
- Communication RecordsSupport emails retained 3 years.
- Legal HoldExtended retention during active legal matters.
- Secure DeletionVerified erasure from primary and backup systems on request.
Your Rights & Choices
You have several rights regarding your personal information. As a sole proprietorship, I personally handle all privacy rights requests and am committed to responding promptly and thoroughly.
- Access RightsRequest a copy of the personal data I hold about you.
- Correction and Update RightsRequest correction of inaccurate or incomplete data.
- Deletion Rights (Right to be Forgotten)Request deletion subject to legal retention obligations.
- Data PortabilityReceive your data in a structured, machine-readable format.
- Objection and Restriction RightsObject to processing or request temporary restriction.
- Consent WithdrawalWithdraw marketing consent at any time.
- Cookie ControlsManage preferences via in-site cookie banner or browser settings.
- Complaint RightsLodge a complaint with your data protection authority.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or my data practices, please contact me directly.
- • Swiss Federal Data Protection Authority
- • European Data Protection Board
- • California Privacy Protection Agency
Terms of Service
By using CyberGapAudit you agree that the assessment outputs are advisory in nature and do not constitute formal compliance certification or legal advice. The platform is provided “as is” under Swiss law. Disputes are resolved by the competent Swiss courts.
Subscription terms, refunds, and cancellation policies are set by the operator (sole proprietor Devon Waller). Emailemail us for terms questions or to request the full Terms of Service document.