Privacy policy
1. Who we are
modularCISO ("we", "us", "our") operates the website modularciso.com. We provide cybersecurity training and tools for security professionals.
For data protection inquiries, contact us at: privacy@modularciso.com
2. What data we collect
Account data (provided by you)
- Email address — Required for account creation, login, and password recovery
- Name — Required for personalization and community identity
- Company and role — Optional, used for content personalization
- Password — Stored as a PBKDF2-SHA256 hash with 100,000 iterations and a unique random salt. We never store your actual password. For transparency: 100,000 is the maximum iteration count the Cloudflare Workers runtime permits for PBKDF2 through the Web Crypto API, so this is a platform ceiling rather than a work factor we selected. Current OWASP guidance for PBKDF2-SHA256 is higher, and we would use a stronger setting — or a memory-hard algorithm such as Argon2id — where the runtime allows it.
OAuth data (if you use social login)
If you sign in with Google, GitHub, or LinkedIn, we receive your name, email address, and profile picture from the provider. We do not store access tokens or request ongoing access to your provider account.
Usage data (generated automatically)
- Learning progress — Which modules and lessons you've started, completed, and your quiz scores
- Session data — IP address, browser type, login times, and session identifiers for security monitoring
- Audit log — Records of login events, profile changes, and security-relevant actions. Retained for 12 months.
- Content attribution — A cryptographic representation of your unique user ID may be invisibly embedded into the curriculum text you view to deter unauthorized redistribution.
Page view counts
We count how often each lesson and tool page is opened, so we can see which material is actually read. Each record contains four things: the date, the page path, whether the reader was signed in, and a count. It contains no user ID, no IP address, no browser details, no session identifier and no cookie, and it is written server-side — there is no script in your browser doing it. Nothing in that data can be traced back to a person, including by us.
What we do NOT do
- No advertising trackers, ad identifiers, or marketing pixels
- No third-party analytics scripts running in your browser
- No selling, renting, or sharing of your data
- No tracking of your browsing outside this site
- No device fingerprinting
- No location data beyond the country implied by your IP address
The honest summary, in one paragraph
No advertising trackers and no third-party analytics. After you sign in we keep a session cookie, security logs that include your IP address and browser, per-lesson progress, and an invisible watermark tied to your account in the curriculum text. Separately we keep aggregate page counts that identify nobody. Cloudflare, which hosts the site, processes standard request data on our behalf as our infrastructure provider. One detail for anyone who reads our security headers: our Content Security Policy still permits Cloudflare's privacy-friendly analytics script (static.cloudflareinsights.com). It is not enabled — no such script is served on any page today — and the allowance exists only so we could turn it on without a policy change. If we ever do, this paragraph gets updated first. Our policy also still allows inline scripts ('unsafe-inline'), which weakens it: Cloudflare's bot-management platform injects an inline script carrying a token that changes on every request, so it cannot be allowlisted by hash or nonce, and removing the allowance would disable that protection. The reasoning is set out in full in our vulnerability disclosure policy. That is the complete list — if you find something on this site that contradicts it, please tell us, because that would be a bug in either the site or this page.
3. Why we process your data
- Account management — To create and maintain your account, authenticate you, and manage your account access level. (Legal basis: contract performance)
- Service delivery — To provide training content, track your progress, and save quiz results. (Legal basis: contract performance)
- Security & IP Protection — To protect your account from unauthorized access, detect abuse, embed attribution watermarks to prevent intellectual property theft, and maintain platform security. (Legal basis: legitimate interest)
- Communication — To send account verification emails, password reset links, and critical service notifications. (Legal basis: contract performance)
4. Who has access to your data
Infrastructure providers
- Cloudflare (USA, EU processing available) — Hosts our website, API, and database. Cloudflare processes data under their privacy policy and has a Data Processing Addendum (DPA) in place.
- Resend (USA) — Sends transactional emails (verification, password reset). Receives only your email address and name for this purpose.
We do not sell, rent, or share your personal data with any other third parties. We do not use your data for advertising or profiling purposes.
5. Where your data is stored
Your data is stored on Cloudflare's infrastructure with EU data processing configured. All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Password hashes use PBKDF2-SHA256 with 100,000 iterations — the platform maximum (see the note above).
6. How long we keep your data
- Account data — Retained while your account is active. Accounts inactive for 24 months are scheduled for deletion.
- Session data — Sessions expire after 30 days. Expired sessions are purged automatically.
- Audit logs — Retained for 12 months, then deleted.
- Login attempt records — Retained for 90 days for security purposes.
- After account deletion — All data is permanently purged within 30 days of deletion request (with a 7-day grace period to cancel).
7. Your rights under GDPR
As a data subject in the EU, you have the following rights:
- Right of access — Download all data we hold about you from your Privacy & Data page.
- Right to rectification — Update your profile information at any time from your Profile page.
- Right to erasure — Delete your account and all associated data from your Privacy & Data page.
- Right to data portability — Export your data in machine-readable JSON format.
- Right to restriction of processing — Contact us to restrict processing of your data.
- Right to object — Contact us to object to specific processing activities.
- Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, use the self-service tools in your account settings or email privacy@modularciso.com.
8. Cookies
We use a single cookie:
- session — A session identifier used to keep you logged in. HttpOnly, Secure, SameSite=Strict. Expires after 30 days. This is a strictly necessary functional cookie and does not require consent under GDPR.
We do not use analytics cookies, advertising cookies, or any third-party tracking cookies.
9. Children
modularCISO is not directed at individuals under 16 years of age. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it promptly.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to registered users and noted on this page with an updated "last updated" date. Continued use of the service after changes constitutes acceptance.
11. Contact
For privacy-related inquiries, data protection requests, or complaints:
Email: privacy@modularciso.com
If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).