Privacy Policy

Version
2026-08-03
Effective
3 August 2026
Last updated
3 August 2026

This policy explains how Cyber Crisis Desk handles personal information when you visit our website, run an emergency check, or manage a cyber incident case with us. It is written in plain English and describes what the platform actually does.

See also our Terms of Service and Cookie Policy.

Who we are

Cyber Crisis Desk is a trading name and online service operated by Miro Global Services LTD, a company registered in England and Wales under company number 14466196, with its registered office at 7 The Colliery, Donnington Wood, Telford, England, TF2 7FQ.

Miro Global Services LTD is the controller for personal information it processes for its own purposes — for example running your account, delivering the incident workflow, taking payment, securing the platform and meeting legal obligations.

The precise controller or processor role can depend on the service and the context. Where you use the platform to store and analyse material about an incident affecting your organisation, you may be a controller of the personal information contained in that material, and we may act on your behalf in respect of it. If you need a specific written determination or a data processing agreement for your organisation, contact privacy@cybercrisisdesk.com.

Scope

This policy applies to:

  • visitors to the public website;
  • registered users and paying customers;
  • administrators and authorised representatives of an organisation;
  • people whose information appears inside incident evidence submitted to us;
  • people who contact support or submit a privacy request or complaint.

Information we collect

Based on how the platform works today, we may hold:

  • Account and identity information — email address, the name you provide, your user identifier and your role (client or administrator).
  • Authentication and security records — sign-in events handled by our authentication provider, password reset requests, and session records.
  • Emergency-triage responses — the answers you give in the emergency check, including incident type, timing and severity signals.
  • Incident case content — your description of what happened, the affected accounts, websites, devices, systems and organisation details you enter, and the case status history.
  • Uploaded evidence — files you choose to upload, such as emails, screenshots, logs, exports and documents, together with file names, sizes and types.
  • Technical indicators — IP addresses, domains, URLs and file hashes you submit for analysis, and the analysis results returned.
  • Recovery and action records — rescue plan steps, client actions, recovery tracks, evidence requests, monitoring checks and their outcomes, including any recovered amounts you record.
  • Messages and support communications — secure case messages between you and our team, and emails you send us.
  • Reports and case summaries — generated PDFs and their metadata, including closure summaries.
  • Billing and subscription metadata — plan, billing interval, subscription status, period dates, Stripe customer and subscription identifiers, Emergency Pass records, and entitlement usage counters.
  • Device, browser and application-log information — technical details recorded by our hosting and database providers when requests are served, and error reports raised by the application.
  • Consent and policy-acceptance records — your cookie preference record, and the version and timestamp of the Terms you accepted.

Card details. Payment card data is entered on Stripe-hosted checkout and billing pages and is processed by Stripe. Cyber Crisis Desk does not receive or store full card numbers, CVV codes or bank credentials; we receive payment and subscription status and identifiers from Stripe.

Sensitive information in evidence

Incident evidence can contain sensitive personal information, information about other people, or information about alleged criminal activity. To keep this proportionate:

  • upload only what is reasonably necessary to understand and respond to the incident;
  • never upload passwords, one-time codes, CVV numbers, private keys, seed phrases, recovery phrases or access tokens — no part of the service needs them;
  • make sure you have a lawful basis and the authority to provide information about other people;
  • we may restrict, quarantine or remove material that should not have been uploaded, and we may ask you to re-upload a redacted version instead.

We have not designed the platform as a repository for special-category data, and this policy does not assert a special-category processing condition. If your incident necessarily involves special-category or criminal-offence data, contact privacy@cybercrisisdesk.com before uploading so the position can be assessed properly.

How we obtain information

  • directly from you, when you register, run triage, message us or upload evidence;
  • from your use of the platform, including the case actions you complete;
  • from other authorised members or administrators of your organisation;
  • from the content of the evidence you submit;
  • from Stripe, which reports payment and subscription status back to us;
  • from technical and threat-intelligence services, when you ask for an indicator to be assessed;
  • automatically, through security and application logs and the storage technologies described in our Cookie Policy.

Purposes and lawful bases

PurposeInformation usedLawful basis
Creating, securing and administering your accountAccount, identity, authentication recordsPerformance of a contract
Delivering emergency triage, rescue plans and the incident workflowTriage responses, case content, actions, messagesPerformance of a contract; legitimate interests for non-registered triage use
Preserving and organising evidenceUploaded files and their metadataPerformance of a contract
Analysing technical indicatorsIP addresses, domains, URLs, file hashesPerformance of a contract
Producing reports, recovery packs and closure summariesCase content, findings, evidence referencesPerformance of a contract
Managing subscriptions, payments and entitlementsBilling metadata, Stripe identifiers, usage countersPerformance of a contract; legal obligation for accounting records
Responding to support requests, privacy requests and complaintsContact details, correspondence, request recordsLegal obligation; legitimate interests in running a support function
Preventing fraud and misuse of the platformAccount, security logs, billing signalsLegitimate interests in fraud prevention and protecting our service and users
Maintaining platform security and investigating incidents affecting usSecurity and application logs, audit trailsLegitimate interests in platform security; legal obligation to keep data secure
Improving reliability and usabilityError reports, aggregate operational dataLegitimate interests in service reliability
Sending service and transactional emailsEmail address, case and billing eventsPerformance of a contract
Establishing, exercising or defending legal claimsRelevant records for the disputeLegitimate interests in defending legal claims; legal obligation where applicable
Optional storage technologies (see Cookie Policy)Preference storageConsent, where consent is legally required

We do not rely on consent for processing that is necessary to provide the service you have asked for. We do not currently run a marketing programme; if we introduce marketing emails we will only send them where the law permits, and every message will include an unsubscribe option.

AI and automated processing

The platform includes optional AI-assisted drafting powered by OpenAI models. Where enabled by an administrator, it can draft a case summary, suggest which evidence may be missing, and propose findings for review.

  • AI requests are made server-side; your browser does not call the AI provider directly.
  • Before a request is sent, the case context passes through a redaction step that removes secret-like values (such as tokens, keys and password-like strings) and unnecessary personal detail while preserving the technical indicators needed for analysis. Redaction reduces risk but cannot guarantee that every sensitive string inside free-text or evidence is caught — this is why you should not upload secrets.
  • AI output is stored as a draft for review. It is not automatically published to you as a finding, and it does not by itself close a case, share a report or change your billing.
  • AI does not make legal, financial or similarly significant decisions about you, and it does not perform automated decision-making with legal effect.
  • Your initial Rescue Plan is generated by deterministic playbooks, not by AI.
  • AI text is decision support only. It is not legal, regulatory, insurance or forensic advice, and it should be verified before you rely on it or send it to a third party.

We do not claim that our AI provider retains nothing. The provider processes requests under its own terms and API data policies; we have not published a retention guarantee here because that would need to be confirmed against the live provider agreement and settings.

Technical and threat-intelligence providers

When an indicator is analysed, the relevant technical value — an IP address, domain, URL or file hash — may be sent to third-party services to retrieve reputation, hosting or network information. Only the indicator and the minimum context needed for the lookup is sent; your case narrative and evidence files are not.

These lookups can be enabled or disabled per provider by an administrator, so the exact set used on your case may vary. Submitted indicators may be retained by the provider and, for some services, may become visible in their public datasets.

Do not paste secrets inside URLs, query strings or indicator fields — assume anything submitted for a lookup may leave our platform.

Payments

  • Stripe processes subscription payments and one-time Emergency Pass payments.
  • Configured prices are charged in US dollars (USD).
  • Your bank or payment provider may convert the charge into your local currency and may apply its own currency-conversion or international-transaction fees. We do not control those fees.
  • We receive payment and subscription status, plan, period dates and Stripe identifiers from Stripe, and use them to set your entitlements.
  • Stripe may process billing, device and anti-fraud information under its own privacy terms.

Sharing and subprocessors

We do not sell personal information. We share it with the service providers below, with professional advisers where necessary, and with authorities where we are legally required to do so.

Providers verified from the current implementation and configuration. We do not publish secret account identifiers or private configuration.
ProviderPurposeInformationLocation relevance
SupabaseAuthentication, database, private file storageAccount, case, evidence, messages, billing metadata, logsMay involve processing outside the UK
StripePayments, subscriptions, customer billing portalEmail, billing and payment metadata, card data handled by StripeInternational transfer relevant
OpenAIAI-assisted drafting (where enabled)Redacted case context and technical indicatorsInternational transfer relevant
Resend (transactional email)Sending service and case notification emailsEmail address, minimal notification contentInternational transfer relevant
Lovable (hosting and deployment platform)Serving the application and its APIsRequest and application log dataMay involve processing outside the UK
Google (Google Ads measurement)Measuring whether our own adverts lead to enquiries, only where you accept the Marketing cookie categoryAdvert click and page-visit measurement data from public pages. No incident details, evidence, case content or account dataInternational transfer relevant
VirusTotal, AbuseIPDB, IPinfo, urlscan.ioIndicator reputation and hosting lookups (each can be disabled)The submitted indicator onlyInternational transfer relevant

Each provider publishes its own privacy information on its website. If you need our current subprocessor list in writing for a due-diligence review, contact privacy@cybercrisisdesk.com.

Notification emails are written to avoid incident detail: they tell you that something needs your attention and ask you to sign in, rather than reproducing evidence or findings.

International transfers

Cyber Crisis Desk is operated from the United Kingdom, and several of our providers operate internationally, including in the United States. This means personal information may be processed outside the UK.

Where that happens we rely on one or more of the following, depending on the provider:

  • UK adequacy regulations, where the destination is covered by them;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • the provider's contractual data-protection terms together with technical safeguards such as encryption in transit, access control and minimisation.

We are not naming a single mechanism per provider here, because the applicable mechanism depends on each provider's current contractual terms. If you need the specific mechanism relied on for a named provider, request it at privacy@cybercrisisdesk.com.

Security

Safeguards implemented in the platform include:

  • evidence held in private storage that is not publicly listable or publicly readable;
  • download access to evidence and reports through controlled, time-limited links;
  • database row-level security so users can reach only their own cases, evidence, messages and billing records;
  • role-based access separating client and administrator capabilities, with roles held in a dedicated table rather than on the user profile;
  • server-side guards that block clients from editing administrative fields even by calling the API directly;
  • encryption in transit (HTTPS/TLS) for traffic to the application and its providers;
  • secrets held in the server environment and never exposed to the browser;
  • case timelines and audit records for significant actions;
  • redaction before AI requests;
  • application and security logging and monitoring.

No online service can guarantee complete security. We do not promise that the platform is impenetrable, and you should keep your own credentials, devices and downloaded reports secure.

Retention

We keep information for as long as we need it for the purpose it was collected, and then for as long as we have a legal or legitimate reason to keep it. The platform does not currently run automatic deletion jobs, so the table below describes the real criteria we apply rather than fixed automated periods.

RecordsRetention criteria
Account and profile dataKept while your account exists; deleted or anonymised on verified account deletion request, subject to the exceptions below.
Active casesKept while the case is open and you continue to need it.
Closed casesKept so you retain access to your history and documentation, until you ask for deletion or the account is closed.
Uploaded evidenceKept with its case. You can ask us to delete specific items sooner; some material may be retained where needed for a dispute.
Reports, recovery packs and closure summariesKept with the case, so a shared document can be re-verified.
Case messagesKept with the case as part of its record.
Billing and accounting recordsKept for the period required by UK accounting and tax law (currently six years from the end of the relevant financial year).
Stripe customer and subscription identifiersKept while the billing relationship and its accounting record are needed.
Security and application logsKept for a limited operational period defined by our hosting and database providers' log settings, then rotated.
Webhook and audit recordsKept while needed to prove what happened to a payment or a case action.
Consent and Terms-acceptance recordsKept while your account exists and afterwards as evidence of the choice made.
Support and privacy complaint recordsKept for a period appropriate to the matter, and longer where a dispute or regulatory query is possible.
BackupsOverwritten on our providers' own backup cycles; a deleted item may persist in a backup until that cycle completes.

We may keep some records longer where necessary for legal obligations, accounting, fraud prevention, platform security, disputes, or the establishment, exercise or defence of legal claims.

Your rights

Under UK data protection law you may have the right to:

  • ask for access to the personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information where there is no continuing reason to keep it;
  • ask us to restrict processing in certain circumstances;
  • object to processing based on legitimate interests, and to object to direct marketing at any time;
  • receive information you provided to us in a portable format, where the right applies;
  • withdraw consent where we rely on consent, without affecting past processing;
  • ask about, and object to, decisions made solely by automated means with legal or similarly significant effect. We do not currently make such decisions.

These rights are not absolute; they can be limited — for example where we must keep records for accounting or to defend a legal claim, or where a request would reveal another person's information.

Send requests to privacy@cybercrisisdesk.com. We will normally act on a request from the email address on your account without asking for further identification. We will only ask for additional identity evidence where we have a genuine doubt about who is making the request.

How to make a data protection complaint

If you are unhappy with how we have handled your personal information, tell us. Send your complaint to privacy@cybercrisisdesk.com, describing what happened and what outcome you are looking for.

We will:

  • give you a clear way to submit a complaint, in writing, by email;
  • acknowledge receipt within 30 days;
  • investigate without undue delay;
  • ask you for clarification only where that is reasonably necessary;
  • keep you informed of progress where it is appropriate to do so;
  • tell you the outcome and our reasons.

Make a data protection complaint →

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint. You can do this at any time — you do not have to complete our internal process first, and you can contact the ICO instead of us or as well as us.

Children

Cyber Crisis Desk is intended for adults aged 18 or over, and for organisations acting through authorised adult representatives. It is not designed for children and we do not knowingly create accounts for them. If you believe a child has registered, contact privacy@cybercrisisdesk.com and we will act promptly.

Changes and contact

We may update this policy as the platform changes. The version identifier and last-updated date at the top of this page always reflect the current version. Where a change materially affects how we use your information, we will take reasonable steps to tell you — for example by email to your account address or by a notice in the application — before or when it takes effect.

Cyber Crisis Desk is operated by Miro Global Services LTD, registered in England and Wales under company number 14466196. Registered office: 7 The Colliery, Donnington Wood, Telford, England, TF2 7FQ.

Privacy contact: privacy@cybercrisisdesk.com
General and contractual support: support@cybercrisisdesk.com